Skip to main content

Ransomware's New Tactic: Steal the Data, Then Threaten to Publish It

Modern ransomware gangs don't just lock files. They steal sensitive data first, then use the threat of publication to pressure victims into paying.

By Mittapalli Sriram
Published: Oct 05, 2026
4 mins read
👁️ 18 Unique Views
Ransomware's New Tactic: Steal the Data, Then Threaten to Publish It
The scale of inference: Optimized for multimodal workloads.
Premium Insight

Why It Matters

Ransomware can affect Indian businesses, hospitals and organisations that store sensitive customer, employee and medical data. Double extortion means restoring backups may not be enough if attackers have already copied the data. Strong authentication, offline or immutable backups and knowing what sensitive data an organisation holds are therefore important for reducing the impact of an attack.

On March 1, 2024, Change Healthcare, a US healthcare payments company, sent $22 million in Bitcoin to a ransomware gang. In return it was promised that the stolen patient data would be deleted. Within weeks, a different group was demanding money for the same data.

How theft and encryption work together

Classic ransomware did one thing: it locked your files and charged you for the key. Modern gangs do two. They copy your data out first, then lock the originals. Security agencies call this double extortion, and it gives the attacker two threats instead of one: pay or stay locked out, and pay or we publish.

The order matters. Attackers get in, usually through stolen logins or an unpatched system, and spend time quietly looking around. They find the valuable files, copy them to servers they control, and only then run the encryption. CISA's advisory on the Play ransomware group describes exactly this sequence: exfiltrate first, encrypt after. By the time a ransom note appears on a screen, the copy has often already left the building. Some gangs now skip encryption entirely and simply sell their silence.

Why backups only solve half of it

For years, the standard advice was to keep good backups, and that still works against encryption. You wipe the machines and restore. But a backup can't un-steal anything. The attackers still hold a copy, and the threat of publishing stays on the table whether or not your systems are running again.

This is why security teams now treat a ransomware incident as a data breach from the first hour. If customer records, medical files or employee details were on those machines, they may be in someone else's hands, and the organisation has to deal with that whether it pays or not.

What a payment actually buys

A ransom payment is a deal with a criminal, and nobody can enforce it. The Change Healthcare case shows how that goes wrong. The gang that took the money, ALPHV, also known as BlackCat, shut down without paying the affiliate who had carried out the attack. That affiliate kept the stolen data and took it to another group, RansomHub, which began its own extortion in April 2024. The money was gone and the data was still out there.

The FBI has warned of similar problems. It says paying doesn't guarantee your data comes back, that some victims never received a decryption key, and that others were asked for more money after paying. Still, the choice is rarely clean for a hospital or a small business that can't operate.

Sophos's 2025 survey found that 49% of organisations hit with encryption paid, while 97% eventually recovered their data. Recovery through backups was at its lowest rate in six years, which helps explain why so many feel cornered.

What to do before and after an attack

Before: keep backups offline or immutable, meaning they can't be altered or deleted, and test restoring from them. Both CISA and the FBI recommend this. Turn on multi-factor login, since stolen credentials are a common way in. Know what sensitive data you hold, because you can't protect or report what you haven't mapped.

After: call the authorities and follow a written response checklist, such as the one in CISA's #StopRansomware Guide, rather than improvising under pressure. Check whether a free decryption tool exists, since researchers have occasionally published them, as Bitdefender did for files encrypted by the REvil gang. Such a tool can't help with data that was already stolen, so assume that data is gone, tell the people affected, and plan for that. The ransom note is only part of the problem.

Found this analysis insightful?

Share with colleagues, engineers, and your network.

Link copied to clipboard!