Ransomware Double Extortion Has Stopped Working

Double extortion ransomware was the dominant pattern from 2020 to 2024. The attacker encrypted the data and exfiltrated a copy, the victim paid the ransom to get both the decryption key and the non disclosure. By 2026 the pattern has…

Dark cinematic editorial image for Ransomware Double Extortion Has Stopped Working - abstract cyan and electric blue digital composition in deep black, hacker aesthetic, no text no logos

4 MIN READ

Three Change Healthcare style breaches later, the SEC cyber disclosure rule, and HHS OCR penalties that run into eight figures, double extortion is the pattern that stopped working. The attacker still exfiltrates the data. The threat of non disclosure stopped carrying weight somewhere around 2024, and the playbook that ran from 2020 to 2024 has been running out of room ever since.

Change Healthcare paid the ransom in 2024, the parent company UnitedHealth Group disclosed a $872 million impact in the same earnings cycle. Ascension Health paid in 2025. Okta’s 2026 support breach did not pay, and the stolen session token data showed up on a well known leak forum within 48 hours. The defenders learned. The backups matured. The regulators got teeth. The non disclosure threat used to be the criminal’s upper hand. The non disclosure threat became the criminal’s bluff.

Why the pattern worked between 2020 and 2024

Three pillars, all gone now. Data sensitivity to start with. The records being exfiltrated during that period (medical records at Change Healthcare, financial records at T-Mobile, customer PII at Colonial Pipeline, Kronos) were sensitive enough that the threat of public disclosure carried weight. The CISO who paid was paying to keep the data off the front page. Backup immaturity next. The typical company in 2020 was running daily backups to tape, restoring from those backups took 72 hours at best, and the immutable backup market (Veeam, Cohesity, Rubrik, AWS S3 Object Lock) was still the exception rather than the default. Regulatory gap to round it out. GDPR was three years old, breach notification laws in the US were a patchwork, and the average time to disclose a breach was still measured in weeks. The non disclosure threat worked because the disclosure was the threat, and the threat was avoidable. All three of those pillars have since been knocked over.

Why it stopped working in 2025 and 2026

Backup maturity, the first collapse. Immutable backup is now the default in the mid market. Veeam, Cohesity, and Rubrik together cover most of the Fortune 500 and a growing share of the mid market. Restoring from immutable backup within 24 hours has become achievable for most security orgs. The backup lead who can restore in a day no longer needs the decryption key, which means the encryption half of the double extortion play no longer has a buyer. Disclosure maturity, the second collapse. The SEC cyber disclosure rule (effective December 2023) requires public companies to disclose material cyber incidents within four business days. HHS OCR has been issuing HIPAA penalties that run into eight figures since 2024, including the $4.75 million Anthem settlement in 2025. Disclosure happens in hours now, not weeks. The threat of non disclosure carries no weight when the disclosure is happening anyway, and the regulator is fining the delay. Regulator involvement, the third collapse. State attorneys general have been running coordinated breach actions since 2024, and the GDPR fines from European regulators have been climbing each year. That angle on the regulatory front has been running reduced for two years running.

What the defender does in 2026

Three priorities, in this order. The backup lead goes first: invest in immutable storage (Veeam, Cohesity, Rubrik, AWS S3 Object Lock, Azure Blob Immutable Storage) and exercise the restore on a quarterly cadence, because the security org that can restore in a day no longer needs the decryption key. The comms lead takes the second piece, working with outside counsel: pre written disclosure templates, the regulator contact list on file, the customer notification path rehearsed, the legal hold process documented, so disclosure happens in hours rather than weeks. The general counsel and the compliance lead close out the list: regulatory readiness, evidence of the prior breach notifications, pre cleared response templates for HHS OCR, the SEC, the state AGs, the GDPR supervisory authorities. The security lead with the immutable backup, the breach notification program, and the regulatory readiness does not pay the double extortion ransom in 2026.

A single torn legal contract on a dark wood lawyer desk, one page crumpled, brass desk lamp casting long shadows
Double extortion in 2026: the backup matured, the breach notification matured, the regulator matured. The pattern has run out of ways to make the data valuable.

The bottom line

Immutable backup, fast breach notification, regulatory readiness. The security org with all three does not pay the double extortion ransom in 2026.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading