What is Cyber Extortion? Types, Examples, and Prevention

Cyber extortion is an attack where criminals demand payment under threat of leaking data or disrupting systems. Its types, real examples, and how to prevent it.
Published on
Wednesday, September 16, 2026
Updated on
September 16, 2026

Cyber extortion is a financially motivated attack in which criminals demand payment, almost always in cryptocurrency, under threat of harm. That harm usually means leaking stolen data, locking systems with ransomware, or knocking services offline. It has become the dominant profit model for organized cybercrime.

The scale is hard to overstate. Ransomware and extortion appeared in 44% of all data breaches in 2024, up from 32% a year earlier, according to the Verizon Data Breach Investigations Report.

What is Cyber Extortion?

Cyber extortion is a form of digital coercion. An attacker takes control of something an organization cannot afford to lose, then demands money to release it or keep it quiet. The leverage is what makes each case work: stolen data, locked systems, or the power to disrupt operations on demand.

What sets cyber extortion apart from plain theft or vandalism is the deal. The attacker holds the victim hostage and offers terms, typically a payment against a deadline. Victims range from hospitals, pipelines, and banks down to individuals, and the driver is almost always money rather than espionage.

How Does Cyber Extortion Work?

A cyber extortion attack unfolds in stages. Attackers first gain a foothold, often by buying stolen credentials from an initial access broker or exploiting an unpatched system. They then build leverage, stealing sensitive data, encrypting files, or positioning to disrupt a service.

how does cyber extortion happen

With leverage in hand, the attacker issues a ransom demand and a deadline, usually payable in cryptocurrency, to stay anonymous. Much of this runs on a ransomware-as-a-service model, where a core group rents its malware and leak infrastructure to affiliates in exchange for a share of the proceeds.

Types of Cyber Extortion

Cyber extortion takes several forms, defined by the leverage the attacker holds.

types of cyber extortion

Ransomware

Ransomware encrypts an organization's files and demands payment for the decryption key. It remains the most common form of cyber extortion and the one that shuts down operations fastest.

Data-theft extortion

Data-theft extortion, sometimes called exfiltration extortion, skips encryption entirely. Attackers steal sensitive files and threaten to publish or sell them unless paid, a model that has grown as encryption-based attacks draw more scrutiny.

DDoS extortion

DDoS extortion, or ransom DDoS, threatens to flood a target with traffic until its services collapse. Attackers often launch a short demonstration attack, then demand payment to call off a larger one.

Sextortion

Sextortion targets individuals rather than systems. The attacker claims to hold compromising images or webcam footage, real or fabricated, and demands payment to keep it private.

Single, Double, and Triple Extortion

Extortion tactics have escalated over time, stacking more pressure on each victim.

Model What the Attacker Adds Pressure on the Victim
Single Extortion Encrypts files and demands a decryption key Loss of access to data and systems
Double Extortion Steals data before encrypting, then threatens to leak it Breach disclosure and regulatory fallout on top of downtime
Triple Extortion Adds DDoS attacks or direct threats to customers and partners Public pressure and third-party harm force a faster payment

The double-extortion model, pioneered by the Maze group in 2019, is now standard, because stolen data gives attackers leverage even against victims who restore cleanly from backups.

Cyber Extortion vs Ransomware

Cyber extortion and ransomware are often used interchangeably, but one contains the other. Ransomware is a single method of cyber extortion, which encrypts files. Cyber extortion is the wider category, spanning data-theft extortion, DDoS extortion, and sextortion.

The distinction matters in practice. Many modern campaigns skip ransomware altogether, stealing data and threatening to leak it without ever encrypting a file. Treating every extortion attack as a ransomware problem leaves the data-theft variants unaddressed.

Notable Cyber Extortion Attacks

Three cases show how far cyber extortion reaches and how its methods differ.

notable cyber extortion attacks

Colonial Pipeline (2021). The DarkSide group encrypted the systems of the largest US fuel pipeline and stole roughly 100 gigabytes of data. Colonial paid $4.4 million and remains shut down for six days, triggering fuel shortages across the East Coast.

Cl0p and MOVEit (2023). The Cl0p group exploited a single flaw in the MOVEit file-transfer tool to steal data from more than 2,000 organizations. It never deployed ransomware, relying entirely on the threat of leaking the files, the clearest example of encryption-free extortion at scale.

Change Healthcare (2024). The ALPHV group crippled a company that processes a third of US medical claims. UnitedHealth paid a reported $22 million, yet a second group re-extorted the same stolen data soon after, proving that payment guarantees nothing.

How Cyber Extortion Is Evolving

The extortion landscape shifts constantly as law enforcement disrupts it. In 2024, Operation Cronos seized LockBit's infrastructure, and ALPHV vanished in an exit scam after the Change Healthcare payment. Rather than ending the threat, these takedowns splintered it, scattering affiliates to new and rebranded groups and pushing the number of active extortion operations to a record 85 by late 2025.

The tactics are shifting alongside the actors. As more victims restore from backups and refuse to pay for decryption, groups increasingly skip encryption and extort on stolen data alone. Cl0p's 2025 campaigns, run purely on data theft, point to where the model is heading.

How to Prevent Cyber Extortion

No single control stops cyber extortion, but layered defenses cut the risk sharply.

how to prevent cyber extortion

Two measures blunt most attacks. Offline, tested backups let an organization restore encrypted systems without paying, and prompt patching closes the unpatched vulnerabilities that attackers exploit for entry.

Access hardening limits the damage. Phishing-resistant multi-factor authentication stops stolen credentials from working, network segmentation keeps an intrusion from spreading, and endpoint detection flags mass encryption or file transfers early.

Visibility closes the gap. Continuous dark web monitoring surfaces stolen credentials and leaked data before attackers weaponize them, and a tested incident response plan turns a crisis into a procedure.

How to Respond to Cyber Extortion

A cyber extortion incident calls for a calm, practiced response, not a rushed payment.

The first hours matter. Isolate affected systems to stop the spread, preserve logs and ransom notes as evidence, and bring in incident response specialists and legal counsel before communicating with the attacker.

Reporting comes next. The FBI and CISA urge victims to report every incident to law enforcement through IC3, whether or not they pay. Both agencies discourage paying, because payment never guarantees recovery and funds further attacks, and 64% of victims declined to pay in 2024. CISA's StopRansomware guidance sets out the full response checklist.

How CloudSEK Helps Against Cyber Extortion

Cyber extortion now hinges on stolen data and leaked credentials, which is where early detection changes the outcome. Most double-extortion victims learn their data is gone only when it surfaces on a leak site, long after the attacker took it.

CloudSEK XVigil monitors the dark web and ransomware leak sites for an organization's data, credentials, and brand, flagging exposure before or as an extortion attempt unfolds. CloudSEK Threat Intelligence adds context on the specific groups targeting a sector, so teams act on a named threat rather than a generic warning.

Frequently Asked Questions

Is cyber extortion illegal?

Yes, cyber extortion is a serious crime under computer fraud and extortion laws worldwide. Demanding payment under threat carries heavy penalties, and paying certain sanctioned groups can itself break the law.

How much does a cyber extortion attack cost?

The average extortion or ransomware breach cost $5.08 million in 2025, according to IBM. The median ransom demand was far lower, around $115,000, but recovery and downtime drive the real total.

What is a data leak site?

A data leak site is a dark web page where extortion groups publish or threaten to publish stolen data to pressure victims into paying. Most double-extortion gangs run one to name and shame non-payers.

What is the difference between cyber extortion and blackmail?

Blackmail threatens to reveal private information, while cyber extortion is broader, covering threats to data, systems, and service availability. All blackmail is a form of extortion, but not all extortion is blackmail.

Does cyber insurance cover cyber extortion?

Many cyber insurance policies cover extortion, including ransom payments, negotiation, and recovery costs, though coverage and conditions vary. Some policies exclude payments to sanctioned threat groups.

Are small businesses targets of cyber extortion?

Yes, small and medium businesses are frequent targets; ransomware appeared in 88% of their breaches in 2024, versus 39% at large firms. Attackers see weaker defenses and quicker payouts.

Related Posts
What is Pastebin? Uses, Risks, and How It Works
Pastebin is a free site for sharing plain text and code via a link. How Pastebin works, its legitimate uses, security risks, and how attackers abuse it.
What is Personally Identifiable Information (PII)?
Personally identifiable information (PII) is any data that identifies a specific person. PII types, examples, exposure risks, and the laws that govern it.
What Is the National Vulnerability Database (NVD)?
The National Vulnerability Database (NVD) is NIST's public repository of CVE data with severity scores. How the NVD works and its 2026 triage shift.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.