
Companies that fall victim to ransomware are starting to realize that these attacks are also data, putting the company, its customers, and its employees at risk. More and more victim companies are starting to notify employees and customers about data stolen during ransomware attacks.
This tactic (stealing data before encrypting systems) has been used for several months by ransomware gangs targeting corporate networks. Hackers steal victims' data and threaten to publish it on special sites (leak sites), in case the victims do not want to pay the ransom.
These sites have been created by the hackers for this exact purpose.
This tactic is now used by almost all ransomware gangs: Maze, REvil, Netwalker, DoppelPaymer, CLOP, RagnarLocker, Nephilim, Ako and others.
Ransomware attacks are data breaches
The data stolen in these attacks can cause a big problem for a company, as it usually includes financial data, trade secrets, unpublished reports, and emails.
It can, however, be a huge problem for employees, as many of their personal details, such as social security numbers, passports, medical records, warning letters, bank accounts, salary information, and more can also be exposed.
Unfortunately, many companies choose to disclose ransomware attacks without reporting that personal data has been stolen. Often, employees of the victim companies themselves are unaware of what exactly has happened, nor that data .
In fact, many employees, in such cases, try to learn from external sources about the ransomware attack and the possible data breach, as the company does not give them details or, even worse, denies any breach.
Companies should report data breaches to their employees, as attackers can use their stolen personal information to commit fraud. If an employee doesn't know what happened, they have no way to protect themselves.

Ransomware victims are beginning to issue notifications of data breaches
The good news is that companies are finally starting to issue data breach notifications after a ransomware attack.
Additionally, most offer free credit monitoring to and identity theft protection services affected customers and employees, so they can be notified if their data is being used publicly or for fraud.
Several companies have reported data breaches following ransomware attacks. These companies should be commended for following privacy laws but also doing what is right for their employees. On the other hand, victims who continue to hide ransomware attacks should be punished because they are putting many people (customers and employees) at risk.
