Extortion without encryption: Unit 42 on the new extortion economy
Palo Alto Unit 42 has published an analysis of a clear shift in the extortion market: more actors now steal data and demand payment without encrypting anything. Unit 42 identifies four drivers. Better backup and recovery makes rebuilding machines routine. Mature endpoint tooling disrupts attacks automatically. Exfiltration has become faster. And regulation itself has become the lever: fines, class actions and lasting reputational damage weigh more heavily than a few hours of downtime.
What this means for your organisation
Continuity plans built around getting systems back up no longer address the problem. When the attacker encrypts nothing, there is nothing to restore; the pressure comes from data about customers, employees and contracts being exposed. For Norwegian organisations this makes extortion a privacy and board matter, with GDPR and NIS2 notification duties forming part of the incident itself. The ability to detect large-scale data extraction now matters more than the ability to restore from backup.
Berigo recommends
- Extend your incident plan with a scenario where data is stolen but nothing is encrypted, and exercise it with the management team.
- Establish monitoring of abnormal outbound data volumes, not just malware on endpoints.
- Decide in advance who authorises notification to the data protection authority, customers and regulators, and within what deadlines.
- Map where your most sensitive datasets actually live, and reduce the number of places they can be pulled from.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch