Cyber extortion has evolved. It’s no longer just about locked systems.
For years, ransomware followed a familiar script: attackers encrypted systems, disrupted operations and demanded payment for a decryption key.
Today, the playbook has changed.
As organisations have strengthened their backup and recovery capabilities, cyber criminals have increasingly shifted towards data extortion. Rather than simply locking systems, attackers steal data and use public "naming and shaming" tactics to pressure organisations into paying. Data leak sites, public disclosures and direct contact with customers have become common tools in the cyber criminal arsenal.
A recent example is the alleged ASOS breach, where attackers reportedly used the retailer's customer notification channel to send messages threatening to leak data unless the company engaged with them. The aim appeared to be not only to communicate with the organisation, but also to create public pressure by involving customers before the facts had been fully established.
This creates a significant challenge for organisations. In some cases, attackers may contact customers, journalists or even seek to attract regulatory attention before the organisation has completed its investigation. Businesses can therefore find themselves managing reputational and regulatory fallout while still trying to establish what happened, what data is affected and whether notification obligations have been triggered.
As a result, cyber incident response is no longer solely a technical exercise.
Alongside containment and recovery, organisations need to consider:
- Whether a personal data breach has occurred
- Whether regulators need to be notified
- Whether affected individuals need to be informed
- How communications with customers, suppliers and employees should be managed
- How to respond if attackers attempt to control the narrative publicly
The most effective responses bring together technical, legal and communications expertise from the outset.
That's why we developed BreachReddi. By combining cyber, legal and crisis management support, we help organisations prepare for and respond to cyber incidents in a coordinated and practical way, ensuring that technical response, regulatory compliance and stakeholder communications are managed together. Find out more here.
In an era where attackers increasingly weaponise publicity as much as technology, preparation is about more than restoring systems. It's about being ready to manage the wider consequences of a breach before someone else tells your story for you.
Don’t wait for a cyber incident to test your response. Talk to our BreachReddi team about how you can prepare for a breach by contacting our team below.