Threats & Social EngineeringBeginnerThreat1 validated evidence record

Data Extortion

Also known as: Extortion without encryption, Data-theft extortion

30 sec

Theft of sensitive information followed by threats to publish, sell, misuse, or otherwise weaponize the data unless the victim pays or complies with the attacker’s demands.

Know

What is Data Extortion?

Data extortion separates extortion from ransomware encryption. Attackers may steal data from SaaS, cloud, endpoints, databases, or third-party systems and then threaten public release, regulatory harm, customer notification, operational disruption, or sale of the information. Some incidents combine encryption and theft; others skip encryption entirely.

Why it matters

Unit 42’s 2026 incident-response reporting describes a shift away from encryption toward data theft and extortion. SaaS-focused groups have shown that large-scale extortion can occur without deploying ransomware to endpoints at all.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationMeasured outcome

Identity weaknesses played a material role in nearly 90% of Unit 42 investigations

2026-02-17Palo Alto Networks Unit 42Cross-sector

Unit 42's 2026 Global Incident Response Report says identity was involved in nearly 90% of investigated incidents and that 65% of initial access was driven by identity-based techniques, including phishing, credential misuse, and permission abuse.

Why this is evidence

This frontline incident-response data validates identity as a primary modern attack surface rather than a supporting control category.

See the source — Palo Alto Networks Unit 42: 2026 Global Incident Response Report

Understand the mechanics

How it works

  1. 1

    Gain access through identity, vulnerability, third party, or malware.

  2. 2

    Locate high-value data.

  3. 3

    Exfiltrate enough information to create leverage.

  4. 4

    Contact the victim with proof and demands.

  5. 5

    Threaten disclosure, sale, regulatory exposure, or customer impact.

Practice

What to watch for

  • Large data exports
  • Unusual SaaS API or download volume
  • Archive creation
  • Unexpected cloud storage transfers
  • Extortion contact containing samples of stolen data

Perform

What to do

  1. 1

    Contain the access path and stop further exfiltration.

  2. 2

    Determine exactly what data was accessed and what evidence supports that conclusion.

  3. 3

    Engage incident response, legal, privacy, executive, and law-enforcement processes as appropriate.

  4. 4

    Do not assume restoring backups solves a data-theft incident.

How to reduce the risk

  • Identity security
  • Data access governance
  • DLP
  • Egress monitoring
  • Segmentation
  • Least privilege
  • SaaS audit logging
  • Incident and crisis exercises

Business impact

  • Regulatory exposure
  • Customer notification
  • Reputational damage
  • Financial loss
  • Legal costs
  • Loss of intellectual property

What different roles should do

Executive

  • Plan for extortion where systems remain operational but sensitive data is stolen

Security

  • Measure data access and exfiltration, not only malware and encryption

Framework & standards context

  • MITRE ATT&CK Exfiltration
  • NIST CSF Respond / Recover

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02