Ransomware gangs are increasingly failing to keep their promises to victims that they will delete stolen data after paying the ransom. In 2019, the Maze ransomware gang began using the double extortion method. This is a tactic in which attackers steal unencrypted files and then threaten victims with leaking them if they don’t pay the required ransom.
Now, however, hackers are not only blackmailing victims into encrypting their files, but are also threatening to publish their data, causing a data breach. This tactic was quickly adopted by other ransomware gangs, who began creating data leak sites where they publish the files they steal from their victims.
Additionally, most ransomware gangs require a victim to pay a ransom to both receive a decryptor for their encrypted files and receive assurances from the attackers that their stolen data will be deleted. Some ransomware gangs, such as AKO/Ranzy, demand two ransom payments, one to provide a decryptor and one to not share the stolen data.
The Coveware Q3 2020 ransomware report released yesterday states that some ransomware gangs are not keeping their promise to delete stolen data after the ransom is paid.
As the report states, some gangs leak stolen data after paying the ransom, using fake data as proof of the supposed deletion, while they may blackmail the victim again, using the same data they were paid for so that they would not publish it. The following cases are mentioned as an example:
- Netwalker: The ransomware gang leaked the data it stole from companies, despite the fact that the latter paid the ransom demanded of them to avoid this.
- Sodinokibi: The hackers have once again blackmailed their victims, threatening to leak the data they had supposedly deleted previously, after receiving the ransom.
- Mespinoza: Gang members published the data they stole from companies, despite receiving the ransom they demanded from their victims.

The Sekhmet gangs and Egregor are also among those who do not keep their promise to delete stolen data.

