"What's happened to my data?"
Irrespective of whether the ransom is paid, a ransomware attack means organisations have lost control of their information.

Andriy Onufriyenko via Getty Images
Ransomware has been around for some time now, and continues to impact organisations in the UK and around the world. However, in recent years criminals have not only been encrypting victims’ computers and networks, but they have also been stealing data.
Headlines will often report on the initial damage and disruption caused to organisations. However, this is often only the beginning of the incident. Even after systems and accesses have been restored, organisations – knowing that a criminal has been inside their network – will often ask ‘What’s happened to my data?'
No longer 'just encryption’
Most, if not all, ransomware incidents will involve the theft of data from a victim’s network. When a cyber criminal deploys ransomware, it should be assumed that data has been stolen. In the ‘least-worse case’ scenario, only system data (that is, data involved in the operation of a victim’s IT processes) will be stolen. In the worst case, extremely sensitive personal information (such as medical or legal details) is exfiltrated.
To pressure victims into paying the ransom, cyber criminals want organisations to believe that data will be leaked if the ransom is not paid. If the demand is ignored, it’s highly likely that criminals will publish some (or all) of the data on a data leak site (DLS) on the dark web.
Similarly, victims are more likely to pay the ransom if they believe that doing so will allow them to decrypt the data, but will also ensure that the data will not be leaked.
However, in the recent law enforcement action against LockBit Infrastructure, the National Crime Agency (NCA) revealed that data from victims who had paid the ransom was still on LockBit’s systems. This highlights how a victim can never be sure that all their data has been deleted, even if they pay the ransom (as my colleague Toby explains in his blog 'The rise of ransomware').
The truth data is out there
When an organisation’s network is compromised, data can be published very quickly. Once on the DLS, the data can almost certainly be used by criminals, likely leading to an increased risk of fraud or financial loss. Once stolen as part of a ransomware attack, the victim no longer has control of the data. Risks to the data include being sold on to another criminal group or state actor.
Criminals will ‘market’ the data available on the DLS in a variety of ways. They might provide the data in full, or alternatively:
- provide data for a limited time period
- leak small samples to encourage criminals to purchase the full set
- provide a file or folder trees to show the type of information available
Don’t encrypt the data, just steal it
More recently, some groups conduct ‘data theft and extortion only’, without deploying ransomware and encrypting victims’ systems. Accordingly, cyber criminals will now use whichever approach they believe most likely to yield payment; for example, deploying ransomware attacks to disrupt logistics companies that need the data to function, but favouring extortion-only attacks against healthcare services (where patient privacy is paramount). Extortion-only attacks are highly likely becoming a favoured tactic of some cyber criminals.
However, it is likely that encryption of systems, combined with threats of data publication, will remain a core tactic to increase pressure on victims to pay a ransom.
These tactics , whether it’s ransomware encryption or extortion-only, show how cyber criminals will adopt whatever technology (or business model) allows them to best exploit their victims. This means (as explained in a recent white paper from the NCSC), that the ransomware threat will continue to adapt and evolve as threat actors seek to maximise profits. So it’s crucial that organisations of all sizes take steps to defend themselves from these kinds of cyber attacks. The following NCSC publications will help you do this, and to recover from the impact of ransomware (and extortion-only) attacks.
- NCSC guide to ransomware
An area of the NCSC’s website dedicated to ransomware. - What to do when cyber attacks disrupt your organisation
How to recover from disruption, get ready for future incidents and make them less likely. - Incident management
How to effectively detect, respond to and resolve cyber incidents. - Why more transparency around cyber attacks is a good thing for everyone
Joint blog from the NCSC and the Information Commissioner’s Office (ICO).


