Ransomware’s New Pressure Model: Inside the Economics of Multi-Extortion

Author : Kaushal Patil | Published On : 05 Oct 2026

For years, the economics of ransomware appeared relatively straightforward: attackers encrypted critical systems, organizations lost access to data and operations, and a ransom demand created a price for restoring access.

That model has changed.

Modern ransomware operations increasingly create leverage from more than encryption. Attackers may steal sensitive information before deploying ransomware, threaten public disclosure, interfere with recovery infrastructure, contact customers or other stakeholders, or continue applying pressure even after an organization has restored its systems.

The result is multi-extortion: an attack model in which adversaries create several independent sources of pressure to increase the economic, operational, legal, and reputational cost of refusing their demands.

CISA and the FBI have long recognized the shift from encryption-only ransomware toward data exfiltration and disclosure threats, commonly described as double extortion. CISA also notes that some actors may use stolen data as the sole mechanism of extortion without deploying ransomware at all.

More recent incident-response evidence suggests that data theft has become deeply integrated into ransomware operations. Google Threat Intelligence Group reported in March 2026 that Mandiant observed confirmed or suspected data theft in approximately 77% of the ransomware intrusions it investigated in 2025, compared with approximately 57% in 2024. The figures represent Mandiant’s incident-response sample rather than the entire ransomware market, but the direction is significant.

For defenders, this changes a fundamental question.

The issue is no longer simply: How quickly can we restore our systems?

It is also: How much leverage does the attacker still possess after we restore them?

Why Backups Changed Ransomware Economics - but Did Not End the Problem

Reliable, isolated, tested backups remain one of the most important components of ransomware resilience.

If an organization can restore critical systems without obtaining an attacker’s decryptor, encryption becomes a less effective source of economic leverage. Better recovery capabilities can therefore weaken one part of the ransomware business model.

Threat actors have adapted.

Google Threat Intelligence Group says improved security, greater refusal to pay, and stronger recovery capabilities appear to be putting pressure on ransomware profitability. Its 2026 analysis suggests this may contribute to greater emphasis on data-theft extortion and other monetization methods.

This is an important distinction: better backups do not make ransomware irrelevant. They change which pressure points attackers need to exploit.

An organization may restore every encrypted server and still face difficult questions:

  • What information was stolen?

  • Does it include customer, employee, financial, legal, intellectual-property, or operational data?

  • Who must be notified?

  • Could stolen credentials enable another compromise?

  • Could leaked information expose customers or partners to additional attacks?

  • How long will business disruption continue despite technical restoration?

  • What claims is the attacker making, and which of them can actually be verified?

Recovery solves the availability problem.

It does not automatically solve the extortion problem.

What Is the Multi-Extortion Pressure Model?

Multi-extortion works by turning one security incident into several simultaneous business problems.

Instead of depending entirely on encrypted systems, attackers attempt to create multiple forms of leverage.

1. Operational Pressure: “Your Business Cannot Function Normally”

Encryption remains powerful because downtime has a measurable economic cost.

Production can stop. Employees can lose access to systems. Customer services can become unavailable. Transactions can be delayed. Incident-response costs begin accumulating immediately.

Attackers can strengthen this pressure by targeting technologies important to recovery itself. In Mandiant’s 2025 ransomware investigations, threat actors were observed targeting virtualization infrastructure in approximately 43% of ransomware intrusions analyzed, up from 29% in 2024. Mandiant also observed techniques intended to inhibit recovery, including attempts to interfere with backups and security controls.

The economic objective is clear: make every hour of resistance more expensive.

2. Data Pressure: “Restoring Systems Does Not Return What We Stole”

Data theft creates a different kind of leverage because restoration cannot retrieve information already copied by an attacker.

Mandiant reported that ransomware actors in its 2025 investigations targeted sensitive information including legal, human resources, accounting, and business-development data.

Once exfiltration occurs, the organization faces two parallel incidents: restoring its own environment and determining what an external party may now possess.

That distinction fundamentally changes response economics.

A technically successful restoration may reduce downtime while doing nothing to eliminate the consequences of compromised confidential information.

3. Disclosure Pressure: “The Incident May Become Someone Else’s Problem Too”

Stolen information gives attackers another mechanism: threatening publication or exposure.

The intended audience for that pressure may extend beyond the security team.

Executives may be concerned about operational and reputational consequences. Legal teams may need to assess contractual and regulatory obligations. Privacy teams may need to determine whether protected information was affected. Communications teams may need to prepare for external scrutiny. Customers and partners may need information.

A ransom negotiation can therefore become only one component of a much larger business-response process.

4. Recovery Pressure: “We Will Make Restoration Harder”

Attackers understand that recovery capacity affects negotiating leverage.

That makes backup infrastructure, virtualization platforms, identity systems, administrative accounts, security tooling, and recovery processes attractive targets.

A mature ransomware strategy should therefore treat recovery infrastructure as high-value security infrastructure, not merely an IT continuity function.

Organizations should assume that a capable attacker who understands the environment may also look for the systems designed to bring that environment back.

5. Uncertainty Pressure: “You Do Not Know Exactly What Happened”

One of the least discussed components of ransomware economics is uncertainty.

During the first hours of an incident, leadership may not know the complete intrusion timeline, the full scope of compromised identities, exactly what information was accessed, whether data was successfully exfiltrated, or whether the attacker still has persistence.

Attackers can exploit that information gap.

This makes forensic visibility economically important. Better telemetry does more than support technical investigation - it can improve decision quality when an adversary is attempting to monetize uncertainty.

Organizations should not automatically accept an attacker’s claims as fact. Threat actors may exaggerate, recycle, or fabricate claims; Google Threat Intelligence specifically cautions that some data-leak-site claims can be misleading.

The Real Cost of Ransomware Is Larger Than the Ransom

Focusing exclusively on the ransom demand can obscure the actual economics of an incident.

The FBI’s 2025 Internet Crime Report recorded more than 3,600 ransomware complaints and reported losses exceeding $32 million. Importantly, the FBI explicitly warns that its ransomware loss figures generally do not include many indirect costs such as lost business, lost time, wages, files or equipment, or third-party remediation services. The figures also cover only incidents and losses reported through the relevant channels.

For an affected organization, the real economic model can be much broader:

Ransomware impact = operational disruption + restoration + incident response + investigation + legal and regulatory response + stakeholder management + third-party consequences + security remediation + potential extortion payment.

Not every incident creates every cost, and the scale varies dramatically.

But this framework matters because it changes how ransomware readiness should be funded. A resilience program designed only around recovering encrypted files is addressing one component of a potentially much larger loss event.

Industry Spotlight: Manufacturing

Manufacturing illustrates why operational pressure can become particularly powerful.

The FBI reported Critical Manufacturing among the critical-infrastructure sectors most affected by the ten ransomware variants most frequently reported to it in 2025.

For a manufacturer, ransomware response can involve more than restoring corporate laptops. Dependencies may span enterprise IT, production scheduling, identity services, engineering environments, virtualization infrastructure, suppliers, logistics systems, and operational processes.

The central resilience question is therefore not simply:

“Do we have backups?”

It is:

“Can we safely continue or restore priority operations if several critical dependencies become unavailable simultaneously?”

That requires understanding operational dependencies before an incident occurs, defining restoration priorities, protecting recovery infrastructure, and testing scenarios in which attackers have also stolen sensitive business information.

Industry Spotlight: Government & Public Sector

Government organizations face another dimension of the pressure model: public-service continuity.

The FBI also identified Government Facilities among the critical sectors most affected by its ten most frequently reported ransomware variants in 2025.

For public-sector organizations, disruption may affect services that cannot simply be measured through conventional lost-revenue calculations. The consequences can include delayed public services, interrupted administrative functions, recovery costs, exposure of sensitive information, and intense public scrutiny.

This makes ransomware preparedness a governance issue as much as a cybersecurity issue.

Technical restoration, communications, legal review, leadership decisions, service-continuity planning, and evidence preservation need to operate as parts of the same response model.

How Should Organizations Prepare for Multi-Extortion?

The defensive model should match the attacker’s pressure model.

Instead of asking only how to prevent encryption, security leaders can organize ransomware resilience around six questions:

1. Can we contain the intrusion?

Segment critical environments, protect privileged identities, strengthen remote-access controls, monitor exposed services, and reduce opportunities for lateral movement.

2. Can we detect data theft before encryption?

Monitor unusual access to sensitive repositories, unexpected compression and staging activity, suspicious outbound transfers, and misuse of legitimate synchronization or transfer utilities. Mandiant observed tools such as Rclone frequently in ransomware incidents involving suspected or confirmed data theft in 2025.

3. Can we recover independently?

Maintain isolated and protected backups, define restoration priorities, and test recovery under realistic incident conditions rather than assuming a successful backup job equals recoverability.

4. Can we establish the facts quickly?

Preserve useful endpoint, identity, network, cloud, and data-access telemetry so responders can distinguish verified compromise from attacker claims.

5. Can leadership make decisions under pressure?

Predefine decision authority across security, IT, legal, privacy, communications, executive leadership, insurance, and other relevant stakeholders. Payment, reporting, notification, and legal obligations can vary by jurisdiction and circumstances and should be assessed with appropriate counsel and authorities.

6. Can we operate while recovery continues?

Identify minimum viable business processes and the dependencies required to sustain them. Business continuity should account for simultaneous technology disruption, investigation, data exposure, and stakeholder communications.

This produces a more useful ransomware resilience cycle:

Contain → Verify → Protect Data → Restore → Operate → Communicate → Remediate → Learn

The objective is not merely to recover systems faster.

It is to systematically remove the attacker’s sources of leverage.

Why the Economics May Keep Changing

The ransomware ecosystem is itself under economic pressure.

Google Threat Intelligence Group reported record numbers of victim posts on data-leak sites during 2025 while simultaneously observing indicators that ransomware profitability may be declining. It cautions that leak-site counts are imperfect because they can include data-theft-only incidents, exaggerated claims, and victims who refused negotiations.

That combination is important.

When one monetization technique becomes less reliable, financially motivated adversaries have incentives to search for others.

Encryption does not need to disappear for ransomware economics to evolve. Attackers simply need enough alternative leverage - stolen information, disruption, recovery interference, disclosure threats, or other monetization opportunities - to make compromise economically valuable.

For defenders, that means resilience cannot be built around yesterday’s ransom note.

FAQ

What is multi-extortion ransomware?

Multi-extortion ransomware is an extortion model in which attackers use multiple forms of leverage rather than relying solely on file encryption. These can include operational disruption, data theft, threatened disclosure, interference with recovery, and other pressure tactics.

Is double extortion the same as multi-extortion?

Double extortion generally refers to combining encryption with data theft and a threat to disclose stolen information. Multi-extortion is a broader conceptual description for incidents where attackers create several simultaneous pressure mechanisms.

Do backups still protect against ransomware?

Yes. Secure, isolated, tested backups remain critical because they can significantly reduce an attacker’s leverage over system availability. However, backups cannot erase data already stolen by an attacker or independently resolve legal, privacy, operational, or reputational consequences.

Should organizations trust ransomware attackers who claim they stole data?

No claim should automatically be treated as verified. Organizations should use forensic evidence, telemetry, incident-response investigation, and other available evidence to establish what was accessed or exfiltrated. Attackers can exaggerate or fabricate claims.

What is the most important change in ransomware response strategy?

Organizations should prepare to manage multiple sources of attacker leverage simultaneously. Recovery remains essential, but modern ransomware resilience also requires data protection, forensic visibility, business continuity, governance, communications, and well-rehearsed decision processes.

Final Thoughts

Ransomware is no longer best understood as malware that encrypts files and demands money for a key.

It is increasingly an economic pressure operation.

Encryption is one mechanism. Data theft is another. Operational disruption, disclosure threats, attacks on recovery capacity, and uncertainty can create additional leverage.

That changes the goal of ransomware defense.

The strongest response strategy is not simply the one that restores servers fastest. It is the one that gives an attacker progressively fewer ways to influence the organization’s decisions.

Backups reduce dependency on decryption. Data controls reduce the value of theft. Segmentation limits disruption. Telemetry reduces uncertainty. Tested continuity plans reduce the cost of downtime. Defined governance reduces decision paralysis.

Taken together, those capabilities attack the economics of extortion itself.

And that may be the more durable measure of ransomware resilience: not whether an organization can survive encryption, but whether it can continue making evidence-based decisions when an attacker attempts to turn every available consequence into leverage.

Know More