Ransomware used to have a simple, if brutal, playbook: attackers encrypted files and demanded payment for the decryption key. Pay up, and the ordeal was over. That model has changed. Modern ransomware crews increasingly steal a copy of your data before they ever trigger the encryption routine, then threaten to publish it regardless of whether the ransom is paid. Security researchers call this double extortion, and it means recovery is no longer just about restoring files. It's about assuming your data has already left the building.

Why Modern Ransomware Steals Data Before Encrypting It

Encryption alone lost its leverage once organizations got serious about backups. If a victim can simply restore from an offline backup, paying a ransom for a decryption key stops making sense. Attackers adapted by adding a second pressure point: exfiltrating sensitive files first. Even a company with pristine backups now faces the threat of stolen customer records, financial documents, or health data being posted publicly or sold to other criminal groups.

This shift has been especially visible in healthcare and financial services, where the data itself, not just system uptime, is the real prize. Incidents involving ChipSoft's healthcare data exposure, the DentaQuest breach affecting millions of patients, and the McKesson breach tied to the ShinyHunters extortion group all illustrate how attackers now treat stolen records as a bargaining chip separate from the encryption itself. Paying to unlock files no longer guarantees the data won't surface later.

5 Forensic Steps to Take in the First Hour After an Attack

When ransomware is discovered, the first sixty minutes matter more than almost any other stage of the incident. Panic-driven actions, like immediately shutting down every machine, can destroy the evidence needed to understand what actually happened. Instead:

  1. Isolate, don't power off. Disconnect affected devices from the network (unplug ethernet, disable Wi-Fi) rather than shutting them down. Powering off can erase volatile memory that holds clues about how attackers got in and what they accessed.
  2. Preserve logs immediately. Firewall logs, VPN access logs, and endpoint detection records are often the first things attackers try to wipe. Export or back up these logs before doing anything else.
  3. Identify the entry point. Check for signs of phishing emails, exposed remote desktop ports, or compromised credentials. Knowing the initial access vector shapes every decision that follows.
  4. Determine what data was touched, not just encrypted. Look for unusual outbound data transfers in the hours or days before encryption began. Large file transfers to unfamiliar external IP addresses are a strong signal that exfiltration occurred.
  5. Engage a forensic specialist or incident response team early. Even for small businesses, a professional who can document the timeline properly is critical for legal, regulatory, and insurance purposes.

Acting methodically in this window doesn't just help containment. It determines whether you can later prove what was and wasn't stolen, which matters enormously for notification obligations and public statements.

How to Spot Which Type of Data Theft Occurred

Not every ransomware incident involves data theft, and not every data theft involves encryption. Distinguishing between them requires looking at specific evidence:

  • Encryption-only attacks leave files locked but show no signs of large outbound transfers in network logs. The ransom note typically references only decryption, not publication.
  • Double extortion attacks show both encrypted files and evidence of data staging, such as compressed archives created shortly before the attack, or unusual authentication from exfiltration tools. The ransom note usually threatens to leak data on a dedicated leak site.
  • Pure data theft (no encryption) is increasingly common on its own, particularly against cloud databases and SaaS platforms. Here, systems keep running normally, but attackers quietly copy records and later demand payment to prevent publication. The 700GB dark web leak affecting Bank of Baroda and the Veradigm breach claimed by the Gentlemen ransomware group both show how theft claims can emerge even when the operational disruption is minimal.

Distinguishing between these scenarios early helps organizations calibrate their response, from breach notification timelines to how they communicate with affected customers.

Defensive Layers That Reduce Exposure: Encryption, VPNs, and Monitoring

Given that double extortion ransomware assumes data will be exposed no matter what, the most effective defense is reducing what's exposable in the first place. Encrypting sensitive data at rest means that even if attackers exfiltrate files, the contents remain unreadable without separate keys. Using a VPN for remote access closes off one of the most common entry points, exposed remote desktop and VPN gateways with weak or reused credentials, which attackers routinely scan for and exploit. Continuous network monitoring that flags unusual outbound data volumes can also catch exfiltration in progress, before encryption even begins.

What This Means for You

If you run a small business or manage IT for one, the double extortion ransomware response can't start when the ransom note appears. It starts with basic hygiene: encrypted backups stored offline, monitored VPN access instead of exposed remote desktop ports, and a written incident plan that spells out who calls whom in the first hour. For consumers whose data sits with healthcare providers, banks, or benefits administrators, the practical takeaway is vigilance after a breach notification, since stolen data can surface even when a company insists a ransom situation was resolved.

Actionable Takeaways

  • Assume any ransomware incident may involve data theft, not just encryption, until forensic evidence proves otherwise.
  • In the first hour, isolate systems without powering them off, and preserve logs before they can be altered or deleted.
  • Encrypt sensitive data at rest so exfiltrated files are less valuable to attackers even if stolen.
  • Secure remote access with a properly configured VPN rather than exposed remote desktop protocols.
  • Watch for breach notifications from providers you use, and treat them seriously even if the organization claims the ransom situation is contained.

Double extortion has reshaped what it means to "recover" from ransomware. Paying doesn't guarantee your data stays private, and refusing to pay doesn't mean it disappears either. The organizations and individuals best positioned to weather these attacks are the ones who treated data protection as a daily habit long before an attacker ever got in.