The pace of change in the modern world is mind-bending. We have AI, robotics, space technology, bio technology, and frontier AI technologies reshaping society in real time.
Beneath the surface, data is the bedrock underlying everything we see happening. Massive troves of valuable data that bad actors would love to weaponize.
More and more, ransomware operators are changing their ways to adapt to the strengthened resilience and hardened security posture of modern organizations. Specifically, starting around the early 2020s, there’s been a continual rise in the number of double extortion and multi-extortion ransomware attacks.
This piece sets out to explore this troubling trend and shares best practices and recommendations to enhance your ransomware protection.
What Happens During a Double Extortion Attack?
With traditional ransom attacks, bad actors infiltrate networks to deploy ransomware designed to encrypt data and / or critical IT systems to effectively block the victim organization from accessing them. Once locked, the threat actors demand that victims pay a hefty ransom, often in the millions of dollars, in exchange for a decryption key.
While this approach was highly effective during the ransomware boom of the early 2010s, as organizations have matured and adapted over the past decade, the overall success rate is dwindling. Better cyber hygiene and disaster preparedness empower victim organizations with the savvy to circumvent total disaster by keeping up-to-date backups of mission-critical data and infrastructure.
Beginning sometime around 2019 to 2020, security researchers started to notice a new trend that saw sophisticated ransomware groups like Maze copy data to their own servers before deploying ransomware against the victim. They’d then make a threat to leak the stolen data if the ransom wasn’t paid.
The novelty of this approach led to a flurry of media buzz, which inadvertently became a flywheel prompting other ransomware groups to copy the technique. This ushered in an era some have dubbed “ransomware 2.0.”
DarkSide vs Brenntag
In addition to Maze, other cyber gangs like DarkSide also became infamous for their double extortion attacks in the early 2020s. One notable example is the 2021 attack targeting the North American branch of Brenntag, a German-owned chemical powerhouse.
Around early May that year, DarkSide gained initial access into the company’s internal network, likely via compromised credentials. Just days later, Brenntag’s security team uncovered the intrusion, but not before the criminals were able to steal and encrypt roughly 150GB of sensitive data.
Shortly thereafter, DarkSide published proof in the form of information snippets and screenshots of the stolen data to the dark web. In their post, they also demanded a 133 Bitcoin ransom (at the time equal to roughly $7.5 million USD) to both decrypt and not leak Brenntag's data. After some negotiation, the company was able to lower the ransom price down to $4.4 million, which was subsequently paid in full.
Anubis vs Coca-Cola
More recently, in July of 2026, a gang called Anubis hit Fairlife, the dairy products subsidiary of Coca-Cola, with a nasty attack. The group, which operates a popular ransomware-as-a-service platform, claimed to have exfiltrated 1TB of company data before encrypting critical systems. Their actions forced Fairlife to suspend production across the US for 11 days.
On the 20th, Anubis acknowledged that they were behind the attack and threatened to leak the stolen data if their demands weren’t met within a week. According to reports, Coca-Cola neglected to interact with Anubis, opting not to pay the undisclosed ransom amount.
One week later, on the 27th of July, Anubis indeed published a cache of the stolen data, but apparently not the full 1TB they claimed to possess.
Multi-Extortion Ransomware
More conniving groups like to up the ante by stacking on additional layers of pressure, a tactic researchers call multi-extortion ransomware.
Sometimes this added leverage comes in the form of ceaseless DDoS attacks following data exfiltration and encryption. It’s a cruel tactic that forces victim organizations to the negotiation table by leaving them little room to breathe.
Other times, attackers go directly after partners, vendors, and even customers, patients, or clients of their target. A textbook example is when Quanta Computer refused to pay REvil’s ransom demands, then the group retaliated by leaking stolen product schematics from Apple, one of Quanta’s most high-profile clients.
Building a Strong Double Extortion Ransomware Defense
Now that we’ve covered what double extortion attacks are and seen how they play out in the real world, let’s discuss how to defend against them.
Strengthen Identity and Access Management
Google’s threat intelligence group published an in-depth blog post in March 2026 highlighting the various tactics and techniques ransomware gangs rely on to exploit target organizations. Research finds that compromised credentials rank as a leading method for threat actors to gain initial entry.
One of the most effective strategies to stop this is strengthening your identity and access management (IAM). Security Scorecard says, “IAM is no longer limited to managing usernames and passwords. It now orchestrates identity governance across human users, workloads, and APIs … Today’s IAM systems must deliver layered, adaptive protection.”
In practice, this means using phishing-resistant MFA, strict zero-trust and least privilege enforcement, regular access management reviews, and proactive identity threat detection and response to create what Security Scorecard calls a “comprehensive identity lifecycle.”
Maintain Secure, Isolated, and Immutable Backups
Data encryption alone stopped being enough leverage for ransomware attackers the moment businesses collectively got serious about backups. That said, there are still plenty of organizations, especially resource-strapped SMBs, who don’t have a reliable backup strategy.
If you’re not sure whether your organization could fully restore its critical systems if disaster suddenly struck, that uncertainty is your answer.
If you’d rather not be seen as low-hanging fruit ripe for exploitation, a great place to start is this CISA backup guide. It’s chock-full of insights, recommendations, and best practices to help businesses with ransomware protection through strategic backup planning.
Keep Systems Patched and Manage Vulnerabilities
Unpatched systems rank alongside compromised credentials as one of the most reliable points of initial entry. For example, file-transfer software in particular routinely proves to be a lucrative target for a ransomware group called Clop.
Security Scorecard, again, offers sound advice saying “Not all vulnerabilities deserve equal attention. Effective vulnerability management strategies must combine CVSS score context, asset exposure, real-world threat intelligence, and third-party visibility.”
Essentially, the best advice boils down to common sense. That being, prioritize patch management for internet-facing systems first and everything else afterward.
Deploy Advanced Endpoint and Network Detection Tools
Speed to detection is a defining challenge of double extortion attacks. When a potential ransomware outbreak is discovered in terms of hours, not days of dwell time, its spread and lethality plummets.
The answer is moving beyond basic AV and firewalls toward layered, correlated detection. We’re talking EDR and XDR across all endpoints to catch credential misuse and lateral movement, coupled with network detection and response tuned specifically to catch data exfiltration signatures.
The initial rollout and upkeep of said solutions require real time and effort. The payoff, however, is measured in terms of reliable safety and greater peace of mind across the entire organization.
Industry Insights
Explore trends, insights, and guidance from technology leaders.


