Double extortion ransomware was the dominant pattern from 2020 to 2024. The attacker encrypted the data and exfiltrated a copy, the victim paid the ransom to get both the decryption key and the non disclosure. The pattern worked because the data exfiltration gave the attacker the upper hand even after the backup was restored. By 2026 the pattern has stopped working, for three reasons that have less to do with the attacker and more to do with the defender.
The 2024 Change Healthcare breach paid the ransom. The 2025 Ascension Health breach paid the ransom. The 2026 Okta support breach did not pay the ransom, and the leaked data showed up on the dark web within 48 hours anyway. The pattern is no longer working because the defenders have learned, the backups have matured, and the regulatory environment has made the non disclosure threat less credible. The 2026 state of double extortion is the state of a pattern that has run out of ways to make the data valuable to the attacker.
Why double extortion worked
Three things made double extortion work between 2020 and 2024. The first was the data sensitivity, because the data the attackers were exfiltrating (medical records, financial records, customer PII) was sensitive enough that the non disclosure threat was credible. The second was the backup immaturity, because the typical enterprise in 2020 did not have an immutable backup, did not have a tested restore, did not have the operational maturity to restore from backup within the 72 hour window. The third was the regulatory gap, because the typical enterprise in 2020 did not have a working breach notification program, and the disclosure to the regulator and to the customers happened weeks after the breach. All three of those things have changed.
Why it stopped working
Three things have changed since 2024. Backup maturity: the immutable backup now serves as the default in the mid market, the tested restore now serves as the default in the mid market, and the operational maturity to restore within 24 hours has become achievable. The victim who can restore within 24 hours does not need the decryption key. Breach notification maturity: the typical enterprise in 2026 has a working breach notification program, the disclosure happens within hours not weeks, and the data exfiltration no longer gives the attacker the same upper hand because the disclosure is happening anyway. Regulator involvement: the regulators in 2026 treat the breach notification as a separate compliance event from the breach itself, and the fines for late notification now run high enough to make the attacker threat less effective. The pattern has run out of ways to make the data valuable to the attacker.
What this means for the defender
Three moves if you are defending against ransomware in 2026. Invest in the immutable backup, because the backup removes the encryption threat. The enterprise that can restore within 24 hours does not pay the encryption ransom. Invest in the breach notification program, because the program removes the data exfiltration threat. The enterprise that discloses within hours removes the threat of the non disclosure. Invest in the regulatory readiness, because the regulatory readiness removes the secondary threat. The enterprise that can demonstrate a working compliance program pays smaller fines and the attacker angle on the regulatory front runs reduced. The defender who has all three is the defender who does not pay the double extortion ransom.

The bottom line
Double extortion stopped working because the backup matured, the breach notification matured, and the regulator matured. The attacker upper hand on the data exfiltration dropped from significant to marginal. The defender who has the immutable backup, the breach notification program, and the regulatory readiness does not pay the double extortion ransom in 2026.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



