Double Extortion Ransomware: Why Restoring Backups Is Not Enough

For years, the standard advice about ransomware was simple: keep good backups and you can restore without paying. That advice is still valuable, but it is no longer complete. Many ransomware groups now steal data before they encrypt anything, then threaten to publish it if the victim does not pay. This is commonly called double extortion.

For healthcare organizations, the shift changes the nature of an incident. Restoring from backup solves the availability problem. It does nothing about the fact that information has already left your network.

How double extortion works

A typical attack proceeds through stages:

Entry. The attackers gain access, often through stolen credentials, a phishing email or an unpatched internet-facing system.

Exploration. They move through the network, learn where data lives and obtain higher privileges.

Theft. They copy files, often to servers they control. This can take days or weeks and may be quiet.

Destruction of defenses. They disable security tools and try to delete or encrypt backups.

Encryption. They lock systems, usually timed for a weekend or holiday.

Extortion. They demand payment for a decryption tool and, separately, for a promise not to leak or sell the stolen data.

Some groups now skip encryption and focus on theft and extortion alone.

Why backups are not enough

Backups address only one of two harms

Encryption denies you access to your data. Theft exposes it. A restore brings your systems back, but the criminals still hold copies of what they took. The pressure to pay then centers on privacy rather than operations.

Stolen data can harm residents and families

Records may include names, dates of birth, Social Security numbers, diagnoses, insurance information and financial details. Leaked information creates risks of identity theft and fraud and can be deeply distressing for residents and families.

The attackers may still be inside

If you restore without finding and closing how they got in, they may return. A rushed rebuild without investigation risks reinfection.

Payment does not guarantee deletion

Even if an organization pays, there is no reliable way to verify that stolen data will be destroyed.

What it means for notification duties

Under the HIPAA Breach Notification Rule, an impermissible acquisition, access, use or disclosure of unsecured protected health information is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. With data theft, that probability is typically not low.

Practical implications:

Investigate what was taken. Forensic analysis of logs and network traffic helps determine which systems and records were accessed or copied.

Notification clocks apply. Notice to affected individuals is required without unreasonable delay and within 60 days of discovery, and breaches affecting 500 or more people also require notice to HHS and, in certain cases, the media. Smaller breaches are reported to HHS annually.

State laws may differ. Some states have shorter deadlines or additional requirements.

Encryption of data at rest may provide a safe harbor in some circumstances, but only if the stolen data was truly unreadable to the attacker. If attackers obtained access through authorized accounts, encrypted data may still have been viewable.

Counsel should lead. Engage legal counsel early so investigation and communication decisions are made with privilege and care.

This is general information, not legal advice.

Strengthening your defenses against both threats

Reduce the chance of entry

Enforce multi-factor authentication, especially for email and remote access

Patch internet-facing systems promptly

Train staff to recognize phishing

Limit administrative privileges

Make theft harder

Segment the network so one compromised machine cannot reach everything

Restrict who can access sensitive file shares

Monitor for unusual large data transfers

Limit unnecessary storage of old data, because data you no longer keep cannot be stolen

Detect earlier

Use endpoint detection and response with someone watching alerts

Retain logs long enough to investigate

Alert on new administrator accounts and disabled security tools

Protect backups

Keep at least one copy offline or immutable, isolate backup credentials from the main directory, and test restores regularly.

Prepare to respond

Maintain an incident response plan with contact details stored offline

Know your insurer's notice requirements and approved vendors

Draft notification templates in advance

Practice with a tabletop exercise

Where UnityCare IT fits

UnityCare IT helps healthcare organizations build layered defenses and response plans that assume both outcomes, locked systems and stolen data. Good backups remain essential. They are just one part of a larger answer.

Related service

Microsoft 365, cloud storage and tested backups with access controls built in.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172