Skip to content

Extortion and threats · Also called data extortion, leak site extortion, extortion without encryption, exfiltration extortion, ShinyHunters-style extortion

Data theft extortion

Data theft extortion is an attack in which criminals copy a company's data, often after tricking staff by phone or bribing insiders, and then demand payment not to publish or sell it. Unlike classic ransomware, nothing may be encrypted, so the first sign can be the ransom email itself.

How it works

  1. Attackers get in through people rather than software flaws, for example by posing as IT support on the phone, sending callback phishing emails, or paying insiders.
  2. They copy data out, often with legitimate tools such as file transfer utilities or an authorised connected app, which traditional antivirus may not flag.
  3. They email or call the company demanding payment, often in bitcoin with a short deadline, and may phone employees to pressure them into negotiating.
  4. Some post stolen data on a leak site when the victim does not pay, although they do not always follow through.

Red flags

If you are targeted

Where to report, by country

Prevention

For individuals

For organisations

By the numbers

Figures are for the reporting category this scam falls under, not this scam alone.

Extortion losses reported to the FBI IC3 in 2025$122.5MUS, 2025, FBI IC3

Real cases

Delivered through: Voice phishing (vishing)

How official datasets classify it

FBI IC3
Extortion
MITRE ATT&CK
T1657

Questions

What is data theft extortion?
It is extortion based on stolen data rather than locked systems. The criminals copy company data and threaten to publish or sell it unless they are paid.
Should a company pay a data extortion demand?
The FBI does not support paying ransoms, and it warns that complying with extortion does not guarantee the data will stay private. Contain the incident, keep the evidence, and report it to law enforcement.

Related scams

Read more