Kicking You While You’re Down: Ransomware Attacks Begin to Adopt a “Triple Extortion” Model

Stu Sjouwerman | May 14, 2021

Ransomware Attacks Triple Extortion MethodNew tactics spotted by security researchers at CheckPoint indicate a growing pattern by ransomware gangs to use additional extortion actions to increase revenues and ensure payment.

It’s bad enough that you’ve been hit by ransomware. Your operations are down, data and systems are inaccessible, and the pressure’s on to either pay the ransom or recover the impacted environment quickly. The bad guys are keenly aware of how their victims are preparing themselves for an attack and have been looking for ways to increase their chances of getting a payout for their efforts.

It started with Maze ransomware a year and change ago with exfiltrating data and threatening to publish it if the ransom was not paid. Now 70% of all ransomware attacks include this.

Apparently, that’s not good enough for the bad guys.

According to new data from CheckPoint, more ransomware gangs are taking an additional third step as part of the attack in an effort to maximize their potential revenues, dubbed triple threat extortion. In some cases the triple threat involves calling victims and contractors to make sure the ransomware attack can’t be kept quiet. CheckPoint also mentions extortion of a therapy clinic’s customers that had been hit by ransomware by threatening customers to pay small sums or have their session notes published.

And this is just the beginning. As the bad guys continue to innovate, you should expect new and creative ways for them to look beyond the now two-pronged approach of encryption and extortion to also include some additional third factor. This factor either increases the chances you’ll pay a ransom or creates a new source of revenue for the bad guys.

Phishing remains a top initial attack vector for ransomware attacks, so putting Security Awareness Training in place to educate your users around the current email-based threats will help to reduce the attack surface and minimize the risk of successful attack.

Topics: Ransomware

Test Your Network’s Defenses with our Free Ransomware Simulator

When employees bypass guidance and fall for social engineering, your network security is the last line of defense. Run our 100% harmless RanSim tool on Windows 10+ workstations to safely simulate 25 ransomware and cryptomining infection scenarios, pinpoint technical vulnerabilities, and get your results in minutes.

Launch Your Free Ransomware Simulation

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.