# Double and triple extortion tactics cornering financial services organisations 
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-06-29
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Ransomware Attacks in Financial Services: Double and Triple
Meta Description: Learn about the alarming surge in ransomware attacks in the financial services industry and how to defend against double and triple extortion tactics with these
URL: https://financedigest.com/double-and-triple-extortion-tactics-cornering-financial-services-organisationshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/finance-1736815613793-compressed.jpg)

![Ian Wood, Senior Director and Head of Technology, UK&I at Veritas Technologies](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/lan-wood-450x672-1736815613617-compressed.jpg)

_By_ **_Ian Wood,_** _Senior Director and Head of Technology, UK&I at Veritas Technologies_

Ransomware continues to keep those in the [financial services](https://www.financedigest.com/trends-in-the-financial-service-landscape-and-the-impact-on-fraud.html "Trends in the financial service landscape and the impact on fraud") industry up at night – and not without good cause. [There was an alarming 105% surge in ransomware attacks last year](https://www.sonicwall.com/2022-cyber-threat-report/?elqCampaignId=13998&sfc=7013h000000MiQZAA0&gclid=CjwKCAiAgbiQBhAHEiwAuQ6BkmbfNdHZWbIdJBPGBn4ut4T3yR5wDxM6JrGQbSMPEUk4O5ClyAmcVxoC7MsQAvD_BwE) and a according to our research, companies in the financial services space are more likely to be struggling to keep pace with their security than those from most other sectors, with nearly half (48%) stating that their data security is lagging behind their digital transformation deployments. To add to their anxiety, malicious actors continue to ramp up the threat, by adding multiple layers to their attacks, including double and triple layers of extortion.

**A two-pipe problem**

Double extortion, also named pay-now-or-get-breached, is where criminals not only [hold systems hostage by encrypting their data](https://www.financedigest.com/sterling-holds-firm-after-uk-jobs-data-muddies-rate-outlook.html "Sterling holds firm after UK jobs data muddies rate outlook"), but also threaten to leak sensitive information online. This ensures that [businesses still face](https://www.financedigest.com/overcoming-challenges-faced-by-women-in-business.html "Overcoming challenges faced by women in business") jeopardy, even if they are confident in their ability to restore their data from backups.

The [double extortion tactic has been used widely by Maze operators](https://www.financedigest.com/taylor-wimpey-espana-celebrates-double-operating-profit-for-2016-as-spanish-market-continues-to-soar.html "Taylor Wimpey España celebrates double operating profit for 2016 as Spanish market continues to soar"), however, due to its success, we are seeing its proliferation in many other attacks. According to research, double extortion [ransomware attacks increased by almost 500% in 2021, with the number of attacks rising nearly 200% quarter over quarter](https://ciphertrace.com/ciphertrace-report-double-extortion-ransomware-jumped-by-nearly-500-last-year/).

[Allied Universal’s Systems](https://www.infosecurity-magazine.com/next-gen-infosec/ransomware-gamechanging-blackmail/) is cited as the first major breach in which double extortion was deployed. However, the [Colonial Pipeline attack in May 2021](https://www.zdnet.com/article/colonial-pipeline-ransomware-attack-everything-you-need-to-know/), is by far the highest-profile case of double extortion. Here, the hacking group DarkSide stole 100 GB of data, forcing its victim to pay a $5 million ransom, to unlock its [data and avoid](https://www.financedigest.com/the-race-to-avoid-data-dinosaur-extinction.html "THE RACE TO AVOID DATA DINOSAUR EXTINCTION") a massive leak.

**Bad-things-come-in-threes**

Triple extortion, as you might imagine, involves the [attackers finding a third pressure point](https://www.financedigest.com/new-intelligence-points-to-pro-ukraine-group-in-nord-stream-attack-nyt.html "New intelligence points to pro-Ukraine group in Nord Stream attack -NYT") for their victims. This might, for example, be by threatening to tell major [customers or partners that the company](https://www.financedigest.com/disconnected-customers-are-one-of-the-biggest-problems-facing-financial-companies.html "Disconnected customers are one of the biggest problems facing financial companies") has been breached, by threating to share details of the leak to the press, or by launching a DDoS attack to distract and overstretch the IT team.

The first widely published [ransomware attack](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") using triple extortion was in late 2020. [Vastaamo](https://www.theguardian.com/world/2020/oct/26/tens-of-thousands-psychotherapy-records-hacked-in-finland), a healthcare company from Finland, was put under increased pressure following a ransomware attack as calls from patients flooded in to its support service and the police.

Ransomware can cause chaos on its own. However, when mixing this with a DDoS attack and a mob of frustrated customers, businesses see their ability to cope [reduced significantly](https://www.financedigest.com/white-bullets-collaboration-with-polands-sygnal-association-significantly-reduces-ad-funded-piracy-in-key-european-market.html "White Bullet’s collaboration with Poland’s Sygnał Association significantly reduces ad-funded piracy in key European market"). [Ultimately hackers want to push companies](https://www.financedigest.com/ultimate-growth-for-sme-finance-company.html "Ultimate growth for SME finance company"), who could potentially have avoided paying, into submission.

**Five steps to** [fighting back](https://www.financedigest.com/2016-the-fight-back-of-the-established-brand.html "2016 – THE FIGHT BACK OF THE ESTABLISHED BRAND")

So, what can you do to [protect your business](https://www.financedigest.com/the-best-ways-to-protect-your-business-from-cyber-threats-in-2021.html "The best ways to protect your business from cyber threats in 2021")? There are five key steps:

1. Implement a comprehensive and robust [data protection and recovery solution – encrypting data and locking it away from victims is the first thing that ransomware hackers](https://www.financedigest.com/frances-thales-says-hackers-claim-to-have-stolen-data.html "France’s Thales says hackers claim to have stolen data") will try to do.
2. Encrypt your own data – exfiltration attacks only work if the hackers can read the information that they’ve stolen.
3. Follow a zero trust methodology for data [access – business can limit what data is locked, blocked or stolen by ensuring that people and applications only have access to the data they need](https://www.financedigest.com/what-needs-to-happen-to-improve-the-landscape-for-smes-trying-to-access-finance-options-in-the-uk.html "What needs to happen to improve the landscape for SMEs trying to access finance options in the UK").
4. Monitor data in real time – [businesses need to react rapidly to threats and stop them in their tracks](https://www.financedigest.com/5-fx-metrics-your-business-should-be-tracking.html "5 FX METRICS YOUR BUSINESS SHOULD BE TRACKING"), this requires immediate alerts when anomalies are detected.
5. Understand your [data – most ransomware attacks rely on the victim assuming that the attacker has hold of something valuable, yet only 15% of the data that businesses](https://www.financedigest.com/three-ways-data-unlocks-business-value-for-financial-organisations.html "Three Ways Data Unlocks Business Value for Financial Organisations ") store is valuable to them. Knowing if the [data that has been breached is worth paying for should be a key](https://www.financedigest.com/sterling-edges-lower-ahead-of-key-data.html "Sterling edges lower ahead of key data") factor when deciding what to do.

**Augmentation and Autonomy**

The challenge of triple extortion is that it requires vigilance on three fronts and IT departments at [financial services](https://www.financedigest.com/how-crowdsourcing-can-help-drive-the-benefits-of-advanced-analytics-in-financial-services.html "HOW CROWDSOURCING CAN HELP DRIVE THE BENEFITS OF ADVANCED ANALYTICS IN FINANCIAL SERVICES") companies can end up feeling like the boy with his finger in the dyke. As more threats arise, they have to pull their finger out of one leak to use it to plug another and, soon, they’re overwhelmed.

As hackers increasingly [try to break](https://www.financedigest.com/eu-meets-to-try-to-break-gas-price-cap-impasse.html "EU meets to try to break gas price cap impasse") the IT team by stretching them too thinly, FSIs need to recognise that the solution to their problems can’t rely on people alone, since they aren’t infinitely scalable. Rather, their skills [need to be augmented with technology that can harness AI and machine learning to autonomously fight back](https://www.financedigest.com/if-the-nation-backs-fintech-we-need-to-address-a-few-things.html "If the nation backs FinTech, we need to address a few things").

Rather than relying on their existing team alone to implement the five-step plan, [organisations can empower their protection](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") solutions to autonomously assist them in the process.

Triple extortion is another example of hackers [moving the goalposts and hoping that they can score before their victims have noticed the change](https://www.financedigest.com/easycat-moves-to-public-beta-changing-the-way-businesses-market-their-products-and-do-business-one-catalog-at-a-time.html "EasyCat moves to public beta – changing the way businesses market their products and do business one catalog at a time"). Companies in the [financial services](https://www.financedigest.com/as-hackers-declare-cyberwarfare-financial-services-cannot-afford-to-be-complacent.html "As hackers declare cyberwarfare, financial services cannot afford to be complacent") space can outsmart their would-be attackers not by simply moving their defenders into new formations, but by flooding the pitch with bots that will assist them.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

