Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is double extortion?

Double extortion combines disruption or encryption with pressure based on claimed data theft, publication or misuse. The claim does not itself prove that data was exfiltrated or that the same actor performed both components.

Separate claim from possession

Assess encryption, collection, transfer, possession and publication independently. Archives, uploads, provider logs, communications, leak pages and recovered files can support different stages.

A supplied sample may prove possession of that item. Compare it with source hashes, metadata and content, and preserve the route by which it arrived. It may come from an earlier breach or another legitimate holder and does not establish possession of the wider claimed dataset.

Preserve publication and attribution evidence

Distinguish material advertised, partially displayed and made downloadable through leak sites, messages or sharing services. Group names, branding and notes can be copied or deceptive.

Where encryption and exfiltration evidence point to different actors or times, retain that distinction rather than forcing one group narrative.

Key takeaway

Prove disruption and data possession as separate extortion components, limiting any sample or publication finding to the content and actor links actually supported.

Reference: CIM-174Cyber Incidents & Offender Methods