Extortion and threats · Also called data extortion, leak site extortion, extortion without encryption, exfiltration extortion, ShinyHunters-style extortion
Data theft extortion
Data theft extortion is an attack in which criminals copy a company's data, often after tricking staff by phone or bribing insiders, and then demand payment not to publish or sell it. Unlike classic ransomware, nothing may be encrypted, so the first sign can be the ransom email itself.
How it works
- Attackers get in through people rather than software flaws, for example by posing as IT support on the phone, sending callback phishing emails, or paying insiders.
- They copy data out, often with legitimate tools such as file transfer utilities or an authorised connected app, which traditional antivirus may not flag.
- They email or call the company demanding payment, often in bitcoin with a short deadline, and may phone employees to pressure them into negotiating.
- Some post stolen data on a leak site when the victim does not pay, although they do not always follow through.
Red flags
- An email, voicemail, or call from an unnamed group claims to have stolen your company's data.
- The demand is for bitcoin within a short deadline, such as 72 hours.
- Employees receive calls pressing them to start ransom negotiations.
- Monitoring shows unexplained large data downloads, or file transfer tools such as WinSCP or Rclone connecting to outside addresses.
If you are targeted
- Stop: do not pay or negotiate on the attacker's deadline. The FBI does not support paying ransoms, and complying with extortion does not guarantee the data will not be shared.
- Contain the problem: take affected systems offline and reset or revoke every credential that may have been exposed.
- Keep the ransom note, phone numbers, voicemails, cryptocurrency wallet details, and the original phishing email or call-back message for investigators.
- Report it to the FBI at ic3.gov using the words "data breach", or to your national cyber agency; our Report a scam page lists where.
Prevention
For individuals
- If someone calls saying they are from IT, hang up and call the help desk back on the number you already know.
- Never install remote access software, approve an app, or enter a code because a caller asked.
- Do not engage with anyone who contacts you about stolen company data; pass it straight to your security team.
For organisations
- Tell staff how and when IT will contact them and prove who it is, so impostors stand out.
- Apply least privilege to bulk data export tools and API access, and monitor for large downloads and exfiltration tools.
- Require phishing-resistant MFA, and restrict who can authorise new connected apps.
- Create an incident continuity plan in advance, as the FBI advises for ransomware, including who contacts law enforcement.
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Extortion losses reported to the FBI IC3 in 2025 | $122.5M | US, 2025, FBI IC3 |
Real cases
2025-08 · US · Disclosed
Salesloft Drift OAuth tokens used to take Salesforce data, 20252025-09 · US · Charged · $115M ransom
Scattered Spider: Thalha Jubair charged in New Jersey, 20252025-06 · US · Disclosed
Google Salesforce instance hit by UNC6040 vishing campaign, 20252025-05 · US · Disclosed · $180M estimate
Coinbase support staff bribed to leak customer data, 20252025-04 · GB · Disclosed · £80M impact
Co-op and Harrods cyber attacks, 20252023-09 · US · Disclosed
Caesars loyalty database taken after IT vendor social engineering, 20232023-09 · US · Disclosed · $100M impact
MGM Resorts cyberattack after a reported help desk call, 2023
Delivered through: Voice phishing (vishing)
How official datasets classify it
- FBI IC3
- Extortion
- MITRE ATT&CK
- T1657
Questions
- What is data theft extortion?
- It is extortion based on stolen data rather than locked systems. The criminals copy company data and threaten to publish or sell it unless they are paid.
- Should a company pay a data extortion demand?
- The FBI does not support paying ransoms, and it warns that complying with extortion does not guarantee the data will stay private. Contain the incident, keep the evidence, and report it to law enforcement.
Related scams
- Vishing into a malicious OAuth connected app
- Callback phishing (fake subscription renewal)
- Insider bribery and recruitment
- North Korean fake IT workers