Ransomware used to have a simple playbook: lock up a victim's files, demand payment, and wait. If the target had solid backups, they could often restore their systems and walk away without paying. That safety net has largely disappeared. In 2025, ransomware operators have shifted to what's known as double extortion, a tactic that combines file encryption with the threat of publicly leaking stolen data, even if the victim never touches the ransom demand.

This shift matters far beyond IT departments. It changes what "being prepared" for a ransomware attack actually means, for businesses and individuals alike.

What Double Extortion Means and Why Backups No Longer Save You

Traditional ransomware defense strategy has always centered on backups: if your files are encrypted, restore from a clean copy and move on. That advice hasn't gone away, but it's no longer sufficient on its own.

Double-extortion ransomware adds a second layer of pressure. Before encrypting a victim's systems, attackers first quietly copy sensitive files off the network. Then, even if the victim recovers everything from backups without paying a cent, the attackers still hold a copy of that stolen data. Their new leverage isn't "pay us or lose your files," it's "pay us or we publish your customer records, financial documents, or internal communications online."

This flips the entire calculus of ransomware response. A company with immaculate backups and a fast recovery process can still be extorted, because the threat has moved from availability (can you access your data) to confidentiality (can you keep your data private). For organizations handling sensitive personal information, that distinction can be the difference between a contained IT incident and a full-blown reputational and legal crisis.

Which Sectors and Data Types Are Being Targeted

Ransomware groups tend to gravitate toward organizations that hold data valuable enough to make leak threats credible and painful. Sectors that manage large volumes of sensitive personal information, financial records, or operational data are consistently attractive targets, precisely because the threat of exposure carries real consequences: regulatory penalties, lawsuits, and loss of customer trust.

Healthcare has been a particularly visible example of what's at stake when double extortion succeeds. Patient records combine some of the most sensitive data types that exist, medical histories, insurance details, Social Security numbers, all in one place. That's part of why a healthcare-focused breach affecting tens of millions of patients became such a stark case study in what happens when stolen data ends up in criminal hands rather than just encrypted on a server.

The broader pattern for 2025 isn't a shrinking pool of ransomware operators going after fewer, bigger targets. It's the opposite: a more fragmented and competitive criminal ecosystem, with multiple groups running double-extortion campaigns simultaneously across different industries. That diversification is explored in more depth in coverage of how ransomware gangs are multiplying heading into 2026, with no sign of the overall trend slowing down.

Where Encryption and VPNs Fit Into a Layered Defense

No single tool stops double extortion, but a layered approach reduces both the odds of a breach and the damage if one occurs.

Encrypting sensitive data at rest, meaning while it sits on servers or devices, means that even if attackers exfiltrate files, what they steal may be unreadable without the right keys. This doesn't prevent a breach, but it can neutralize the leak threat that gives double extortion its teeth.

Encrypting data in transit matters just as much. A VPN creates an encrypted tunnel for data moving between devices and networks, which helps prevent attackers from intercepting credentials or files as they travel across less secure connections, such as public Wi-Fi or remote access setups. For remote and hybrid workforces, this closes off one of the common entry points ransomware groups use to gain initial access before deploying encryption payloads.

Neither encryption nor VPN use replaces endpoint security, network segmentation, or employee training around phishing, which remains a top delivery method for ransomware. But together, these layers shrink the attack surface and limit what criminals can actually do with data they manage to steal.

What This Means For You

If you run a business, the takeaway is straightforward: backup strategy alone is no longer a complete ransomware defense plan. You also need to think about what happens if your data is stolen, not just encrypted. That means encrypting sensitive files at rest, securing remote access with VPNs, limiting who can access sensitive data in the first place, and having an incident response plan that accounts for public leak threats, not just system downtime.

If you're an individual, the risk is more indirect but still real. Your personal data, healthcare records, financial details, login credentials, may sit inside systems run by companies or providers that become double-extortion targets. Using strong, unique passwords, enabling multi-factor authentication, and being cautious about which organizations you share sensitive information with all reduce your exposure when a breach does happen elsewhere.

Actionable Takeaways

  • Treat backups as recovery insurance, not a complete ransomware defense; they don't stop data leak threats.
  • Encrypt sensitive data both at rest and in transit, and use a VPN for remote access to reduce interception risk.
  • Assume any organization holding your personal data could become a target, and monitor accounts for unusual activity after any reported breach.
  • Businesses should build incident response plans that explicitly address data leak scenarios, not just system restoration.

Double-extortion ransomware in 2025 reflects a broader truth about modern cyber threats: attackers adapt faster than static defenses can keep up. Staying informed about how these tactics evolve, and layering encryption, access controls, and secure connections accordingly, remains the most practical way to reduce risk in an environment where backups alone are no longer enough.