Ransomware is one of the biggest trends in cybersecurity right now. The tactic, which generally involves encrypting or otherwise preventing access to devices or data until a ransom is paid, can be easy to execute and prove highly lucrative.
However, some companies have found that by taking preventative steps such as frequently backing up systems in multiple locations, they can mitigate the worst of the damage. Therefore, criminals have had to evolve their attacks in order to increase their chances of being paid. Frequently, this sees hackers turn to extortion tactics.
What is extortionware?
As a result of growing awareness of the threat, partly thanks to highly publicized incidents such as WannaCry and NotPetya, traditional ransomware techniques that aim to encrypt data are no longer the most popular form of attack. In fact, according to research by Venafi, only around one in six ransomware incidents (17%) now solely demand money in exchange for a decryption key.
Instead, it claims 83% of attacks now involve some form of extortion effort, where criminals threaten to do further harm to a business unless they receive a payment.
These types of attacks are often more highly targeted than relatively indiscriminate ransomware efforts, with hackers focusing their energies on businesses that contain highly sensitive or confidential data, or those that would be especially damaged by any interruption in service.