How Do Ransomware Extortion and Defense Work?

TL;DR
Ransomware defense requires rapid detection, coordinated investigation and remediation, and preparation for pressures beyond file encryption. Attackers may steal data, disrupt operations, contact customers, approach media, and alert regulators to increase leverage, while observed dwell times can be as short as one to three days. Payment recovery is possible through law enforcement, but the presenters say it occurs infrequently.
Transcript
Th- thank you guys for, for, for joining, um, and the, you know, thank you again for, for being on time. Um, I'm David Wong. I'm a VP at Mandiant. Um, I run our consulting practice in New York. Um, I've been with the company for, for about nine years, and our team is the team that you'll hear about in the news that responds to incidents. So when, w... Read More
Key Insights
- Ransomware appeared in just under 25% of the Mandiant investigations discussed, but its destructive character creates unusually high stakes for victims and responders. Its operational consequences make it feel more prevalent to incident response teams than the percentage alone might suggest.
- Multifaceted extortion is broader than encrypting files and selling a decryption tool. Attackers may also steal information, threaten publication, disrupt infrastructure, contact customers, approach the media, or communicate with regulators to increase pressure on the victim.
- Attacker leverage is created by inflicting or threatening several forms of pain at once. The payment offer is then framed as a way to relieve as much of that combined operational, reputational, and regulatory pressure as possible.
- Ransomware dwell time can be extremely short. The presenters cite earlier 2021 data near five days and describe more recent cases in which reconnaissance and data theft contributed to timelines as short as one, two, or three days.
- The ransomware ecosystem showed no single dominant malware family in the presenters’ year-to-date sample. LockBit was encountered frequently, while BlackCat was notable for its ransomware capabilities and techniques that included targeting virtual infrastructure.
- Ransomware revenue can finance further attacks. The presenters describe threat actors buying access and exploits, including an example of spending $200,000 on an exploit, using it against 100 companies, and generating tens of millions of dollars.
- Published ransomware payment totals are likely incomplete because FBI figures rely heavily on voluntary reporting and cryptocurrency analysis may not capture every transaction. Even with those limitations, the cited figures included a 69% year-over-year increase and $600 million tracked by Chainalysis.
- Law enforcement recovery of ransom payments is possible but uncommon. In the cited 2021 Colonial Pipeline case, investigators traced individuals, Bitcoin wallets, and exchanges, enabling recovery of about 40% of the payment and its return to the company.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is multifaceted extortion in a ransomware attack?
Multifaceted extortion combines ransomware encryption with additional pressure tactics. Attackers may steal data and threaten to publish it, disrupt infrastructure to impede operations and recovery, contact the victim’s customers, seek media attention, or approach regulators with jurisdiction over the organization. Their objective is to create several sources of leverage and then offer to reduce the resulting harm if the victim pays.
Q: How should incident response and ransomware remediation teams work together?
Incident response investigators should determine how the intrusion occurred, what happened inside the environment, and what actions the attacker performed. Remediation specialists should work alongside them to contain malicious activity, eradicate the attacker, and improve the organization’s security posture. The presenters describe these functions operating in tandem, allowing investigation and defensive recovery to progress together during a high-impact intrusion.
Q: How quickly can ransomware attackers move through a network?
Ransomware attackers may progress from reconnaissance to data theft and disruptive action within only a few days. The presenters cite 2021 data showing a dwell time around five days, then describe more recent cases with dwell times as short as one, two, or three days. This accelerated pace creates a serious challenge for organizations trying to detect and stop activity before extortion begins.
Q: Why can ransomware cause severe harm even when it is not the majority of incidents?
Ransomware appeared in just under 25% of the cases investigated in the cited Mandiant reporting, but the presenters emphasize its destructive nature and potential operational impact. These incidents create high stakes for victims and employees, while response teams face intense pressure and little rest. Encryption, disruption, theft, and external pressure can also compound the damage within one intrusion.
Q: What tactics do ransomware attackers use besides encrypting data?
Attackers can steal sensitive data and threaten its publication, interfere with infrastructure, and make it harder for an organization to restore operations independently. They may also contact customers directly, antagonize those customers, approach journalists to increase public scrutiny, or notify relevant regulators. These tactics are intended to intensify pressure and make a ransom payment appear more attractive to the victim.
Q: Why might reported ransomware payment totals underestimate the problem?
The presenters caution that available totals probably do not capture every ransomware payment. FBI figures depend substantially on voluntary reporting, so incidents that victims do not report may be absent. Chainalysis derived its cited $600 million figure by examining Bitcoin wallets and payments, but that method may also miss activity. The presenters therefore treat exact totals as incomplete while emphasizing the substantial scale.
Q: Can law enforcement recover a ransomware payment?
Law enforcement can sometimes trace and recover part of a ransomware payment, but the presenters say this does not happen often. They cite the 2021 Colonial Pipeline case, in which law enforcement traced individuals, Bitcoin wallets, and the exchanges being used. Those efforts recovered about 40% of the payment, which was returned to the company, making it a notable but uncommon outcome.
Q: How do ransomware groups finance and scale their attacks?
Ransomware groups can use their earnings to buy access to victim environments and purchase exploits. The presenters describe a case in which threat actors spent $200,000 on an exploit, subsequently used it to compromise 100 companies, and made tens of millions of dollars. The example shows how ransom revenue can support reusable capabilities that expand the reach and profitability of later attacks.
Summary & Key Takeaways
-
Mandiant’s incident response teams divide responsibilities between investigation and remediation. Investigators determine what happened and what attackers did, while remediation specialists contain malicious activity, eradicate attackers, and improve the victim’s security posture. The teams work together during intrusions, reflecting the need to coordinate evidence gathering, containment, recovery, and longer-term defensive improvement.
-
Ransomware represented just under 25% of the cases covered by Mandiant’s cited reporting, yet its destructive nature makes the incidents especially demanding. No single malware family dominated the presenters’ year-to-date data, although LockBit appeared frequently and BlackCat had notable capabilities, including techniques for targeting virtual infrastructure and placing operational systems at risk.
-
Modern extortion can combine encryption, data theft, infrastructure disruption, customer harassment, media pressure, and contact with regulators. These tactics increase leverage by making independent recovery harder and threatening several kinds of harm simultaneously. The presenters recommend learning from incident outcomes, preparing defenses beforehand, and recognizing that attackers may move within only a few days.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator