Threats may involve publishing stolen data, disrupting services, destroying information, exposing private material, or continuing an intrusion. The demand and threatened harm — not one particular tool — define the pattern.
Cyber extortion also includes data-theft-only demands, distributed denial-of-service (DDoS) extortion, and threats based on compromised accounts. Actors may exaggerate or fabricate access, but both genuine compromise and false claims require validation.
Key points
AssessmentPreserve the demand and communication metadata, validate claimed access or theft without relying on attacker-provided links, establish affected systems and people, and distinguish observed facts from unverified claims.
Response prioritiesProtect safety and essential services, contain and investigate compromise, preserve evidence, prepare trustworthy communications, and coordinate authorized leadership, counsel, law enforcement, regulators, insurers, and responders as applicable.
RecoveryRevoke attacker access, protect exposed identities and data, restore services from verified sources, monitor for disclosure or renewed access, and correct the entry path and control failures.
Important limitationAn extortion claim does not prove that the actor retains access, stole data, or can carry out the threat. Absence of encryption does not make a claim false, and paying or engaging cannot guarantee recovery, deletion, silence, or an end to targeting.