Stolen Data, No Locked Files: Preparing for Data Extortion
Your systems can stay online while stolen information becomes an extortion demand. A useful readiness plan needs to cover who can reach sensitive data, how you would notice it leaving, and who takes charge when a threat arrives.
BlackSight Team
Offensive security & threat analysis
Updated
Data theft can create a crisis without an outage
Data extortion means threatening to expose stolen information to pressure a victim into paying. Encryption may be part of an incident, but it is not required. In their November 2024 advisory, the FBI, CISA, and ASD's ACSC described BianLian's move to extortion based entirely on stolen data. Working applications therefore cannot tell you whether confidential records have stayed private. Read the joint BianLian advisory.
The issue remains relevant in 2026. Mandiant's June reporting described UNC3753 targeting professional, legal, and financial services organizations. Attackers used phone conversations and support pretexts to obtain remote access, then pursued sensitive documents for extortion. That report concerns a specific observed campaign; it is not evidence that every suspicious support call belongs to the same group. See Mandiant's campaign analysis.
Separate restoring systems from protecting information
The StopRansomware Guide addresses both recovery and data-extortion risk. Backups remain essential, but restoring a server cannot recover a copy already held elsewhere. Restrict access to sensitive repositories, protect backup administration, and retain evidence that can help establish what happened. Review remote access tools and unnecessary permissions as part of that work.
For a useful planning exercise, consider a consulting business whose project archive contains contracts, employee records, and old credentials. Ask the archive owner to distinguish what current staff need from what accumulated over time. Then ask the security team what evidence would distinguish an ordinary project download from a compromised account collecting many clients' files. Those are two different responsibilities, and both need an owner.
Rehearse the decisions before a demand arrives
Our suggested tabletop exercise starts with a fictional message claiming possession of sample documents. The aim is to find unanswered operational questions, without introducing malware or exposing real records:
- Who receives the report, and who can activate the incident process outside office hours?
- Who can validate the sample against internal records without distributing it further?
- Which logs show account access, file retrieval, and transfers, and how long are they retained?
- Who can restrict affected access while keeping essential services available?
- Who owns staff, client, and external communications as facts become available?
During an actual incident, preserve the demand and available evidence, involve the designated response team, and assess the extent of access before declaring the environment clear. The official response guidance provides a structured starting point for containment, investigation, and recovery.
What an assessment should demonstrate
A focused manual penetration test can use agreed sample records and controlled transfers to test an access path and the associated alert. We recommend recording the starting privileges, the boundary crossed, the evidence generated, and the response taken. That produces specific work for system owners and defenders, rather than an assumption that successful backup restoration resolves every form of extortion exposure.
Common questions
Can data extortion happen without ransomware?
Yes. An attacker can steal information and threaten to publish it without encrypting systems. The absence of locked files does not rule out a serious data breach.
Do backups protect against data extortion?
Backups help restore availability. They cannot retrieve copies already stolen by an attacker, so access controls, monitoring, and an incident response process are also needed.
How can a pentest assess extortion exposure?
An authorized assessment can test access to agreed sample data, network boundaries, and detection using controlled transfers. It should use defined targets and stop conditions rather than moving real sensitive records unnecessarily.