No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Why Cyber Extortion Attacks No Longer Require Ransomware

September 15, 2023
in Protection
0
informa



44CON 2023 – London – Cyber attackers are becoming less reliant on ransomware to get victims to pay — instead using social engineering skills to extort money, according to a top official from the UK’s National Cybersecurity Centre (NCSC).

Speaking at 44CON in London, NCSC’s operations director Paul Chichester said ransomware remains a major concern for the agency and for businesses as the number of ransomware incidents continue to increase. But a lot of attackers often do not use the encryption malware anymore: They just steal data, put it on a leak site, and solicit for a payment in exchange for taking it down.

“We’ve seen criminals move from only encrypting data, to double extortion — encrypting it and threatening to leak it, to now, on some occasions, simply threatening to leak the data. It feels like they are keen to be as efficient as possible, or perhaps making it less painful for the victim, because generally people still pay to avoid their data being leaked,” he said.

Double extortion is where the attacker steals data and demands a payment from an organization to have it returned, and also often deploys ransomware to encrypt networks and desktops as well. However, attackers increasingly are moving away from using encryption malware, and toward pure data-theft extortion tactics.

Addressing a cyber extortion attack is more than just having backups to restore their systems and data. Organizations also should consider best practices on passwords and multifactor authentication, ensure efficient patch management, and provide security training for employees, experts say.

Who Is Paying Ransom?

NCSC’s Chichester said the UK has a policy that recommends organizations do not pay ransom because the payments fuel the criminal ecosystem. Even so, some companies do pay in order to reassure their customers that their data is safe, he noted.

Sharing a story about a company that was attacked, Chichester said the attacker set the ransom payment to be a lower amount than a GDPR fine, so that it would appear that the company was paying less with the ransom rate than a regulatory fine and therefore saving money.

“That’s not true by the way: You still have to pay a GDPR fine for a data breach, but that’s the way that actors are socially engineering a victim,” he explained.

Chichester said he has empathy for companies that are hit, as he has seen incidents where everything is encrypted and the victim is locked down and they feel they have no choice but to pay the ransom.

Fines for GDPR violations have ranged from £20 million, or $24 million, to $425 million. The UK Information Commissioner’s Office in its guidance on penalties states that the maximum fine is £17.5 million, or four percent of the total annual worldwide turnover in the preceding financial year — whichever is higher.

Ransomware payments, meanwhile, have been reported as reaching up to eight figures, while the average payment by UK organizations in 2023 was $2.1 million.

Chichester praised collaboration with the UK industry sector, especially when organizations alert the NCSC to a ransomware attack. That way, the agency is able to study the malware and work with threat intelligence providers and research communities to help the victim — and sometimes act as a broker between the victim and the attacker.

“I’d much rather stop an incident than actually be responding to one,” he says. “But we respond to and work closely with all of those organizations [that are hit].”

Editorial Team

Editorial Team

Related Posts

Why Online Fitness Advice Can Seem so Contradictory
Protection

Why Online Fitness Advice Can Seem so Contradictory

April 30, 2026
15 of the Most Common Beginner DIY Mistakes (and How to Avoid Them)
Protection

15 of the Most Common Beginner DIY Mistakes (and How to Avoid Them)

April 29, 2026
This Acer Predator Helios Neo 16 Gaming Laptop Is $560 Off
Protection

This Acer Predator Helios Neo 16 Gaming Laptop Is $560 Off

April 29, 2026
These New AI Editing Tools May Be Added to the Photos App in iOS 27
Protection

These New AI Editing Tools May Be Added to the Photos App in iOS 27

April 29, 2026
Why I Never Wear a Smart Ring During My Workouts
Protection

Why I Never Wear a Smart Ring During My Workouts

April 29, 2026
Google Translate Now Helps You Practice Your Pronunciation
Protection

Google Translate Now Helps You Practice Your Pronunciation

April 29, 2026
Load More
Next Post
Adobe Had ‘Blowout’ Quarter With AI. Why the Stock Is Falling.

Adobe Had ‘Blowout’ Quarter With AI. Why the Stock Is Falling.

Popular News

  • The key global oil contract tops $115 as Strait of Hormuz impasse continues

    The key global oil contract tops $115 as Strait of Hormuz impasse continues

    0 shares
    Share 0 Tweet 0
  • Meta shares look ‘iffy’ into earnings. How to trade it

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • 7 Wearable Makeup Trends That’ll Be Everywhere In 2025

    0 shares
    Share 0 Tweet 0
  • AIM Summit London Edition 2026 

    0 shares
    Share 0 Tweet 0

Latest News

Why Online Fitness Advice Can Seem so Contradictory

Why Online Fitness Advice Can Seem so Contradictory

April 30, 2026
0

Learning about exercise can be overwhelming. One YouTube channel tells you what to do, and you think, OK, I’ve got...

Cointelegraph

US Seized $500M in Iranian Crypto Assets, Treasury Secretary Says

April 30, 2026
0

The United States has seized nearly $500 million in Iranian cryptocurrency assets as part of a sweeping economic pressure campaign...

Exclusive-Apollo, Blackstone and KKR vie for Shell stake in LNG Canada, sources say

Exclusive-Apollo, Blackstone and KKR vie for Shell stake in LNG Canada, sources say

April 30, 2026
0

Exclusive-Apollo, Blackstone and KKR vie for Shell stake in LNG Canada, sources say

CVC sees Q1 growth spike on private wealth expansion

CVC sees Q1 growth spike on private wealth expansion

April 30, 2026
0

CVC Capital Partners has reported strong growth within its private wealth channel in the first quarter of 2026, driven in...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.