# What is Cyber Extortion?

> Cyber extortion is coercion carried out through or against digital systems in which an actor demands money, access, services, or another benefit and threatens cyber-enabled harm if the demand is refused.

- Canonical URL: https://yellowcube.eu/glossary/cyber-extortion/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Threats may involve publishing stolen data, disrupting services, destroying information, exposing private material, or continuing an intrusion. The demand and threatened harm — not one particular tool — define the pattern.

Cyber extortion also includes data-theft-only demands, distributed denial-of-service (DDoS) extortion, and threats based on compromised accounts. Actors may exaggerate or fabricate access, but both genuine compromise and false claims require validation.

### Key points

- **Assessment:** Preserve the demand and communication metadata, validate claimed access or theft without relying on attacker-provided links, establish affected systems and people, and distinguish observed facts from unverified claims.
- **Response priorities:** Protect safety and essential services, contain and investigate compromise, preserve evidence, prepare trustworthy communications, and coordinate authorized leadership, counsel, law enforcement, regulators, insurers, and responders as applicable.
- **Recovery:** Revoke attacker access, protect exposed identities and data, restore services from verified sources, monitor for disclosure or renewed access, and correct the entry path and control failures.
- **Important limitation:** An extortion claim does not prove that the actor retains access, stole data, or can carry out the threat. Absence of encryption does not make a claim false, and paying or engaging cannot guarantee recovery, deletion, silence, or an end to targeting.

### Related terms

[Ransomware](<https://yellowcube.eu/glossary/ransomware/>) · [Data exfiltration](<https://yellowcube.eu/glossary/data-exfiltration/>) · [Distributed denial-of-service (DDoS) attack](<https://yellowcube.eu/glossary/distributed-denial-of-service-attack/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Cyber insurance](<https://yellowcube.eu/glossary/cyber-insurance/>)

### Sources

[CISA: StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide) · [FBI Internet Crime Complaint Center: 2025 Annual Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf) · [Europol: Internet Organised Crime Threat Assessment](https://www.europol.europa.eu/publications-events/main-reports/iocta-report)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

