Data extortion is a tactic in which attackers steal sensitive files and threaten to publish, sell, or leak them unless the target pays or agrees to other demands. The goal is leverage: even if systems are restored from backups, the attacker can still pressure the victim by threatening exposure of confidential information, customer records, financial data, or internal strategy documents.
This matters because the harm is not limited to encryption or downtime. Exposure can trigger reputational damage, fraud, competitive loss, legal obligations, and follow-on phishing or impersonation. In real attacks, extortion crews often stage stolen data on leak sites, divide it into valuable categories, and use that public listing as proof of access. Defenders reduce risk by limiting data egress, monitoring unusual outbound transfers, segmenting sensitive assets, and preserving logs and endpoint telemetry for fast validation and containment.


