🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
The double-extortion playbook has changed — here's what's new
SCAN
Threat Intelligence

The double-extortion playbook has changed — here's what's new

ERD Research TeamJul 1, 20265 min read

Key takeaways

  • Attackers increasingly steal data days before encrypting anything, so encryption-stage detection catches the attack too late to prevent the breach.
  • Outbound data-transfer monitoring is now as important as endpoint detection for limiting blast radius.
  • Good backups no longer end the negotiation — a separate demand tied to stolen data remains, and your IR plan should address it explicitly.

Exfiltration moved to the front

Through the first half of 2026, the majority of enterprise ransomware incidents we've tracked followed an exfiltration-first sequence: attackers spend days quietly copying data out of the environment before triggering encryption, rather than encrypting immediately on gaining privileged access. The stolen data — not the locked files — has become the primary source of leverage.

Why it breaks encryption-stage detection

Detection strategies built solely around encryption-stage indicators — mass file renames, shadow-copy deletion — now catch the attack too late to prevent data theft, even if they still prevent downtime. By the time those signatures fire, the breach has already happened. Outbound data-transfer monitoring has become as important as endpoint detection for limiting the blast radius of a modern incident.

Backups don't end the negotiation anymore

This also changes the negotiation calculus. Many affected organizations restore from backup without paying for decryption, but still face a separate extortion demand tied purely to the stolen data — a scenario your incident response plan and legal counsel should address explicitly, not assume away. 'We have good backups' is a strong position against downtime and a weak one against a data-leak threat.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy