Ransomware: re-extortion and the attack that doesn't encrypt
The new trend that skips encryption — it only steals and threatens to leak — and the advance of the Babuk group in Brazil.
Audience: Companies and Operations · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
The company suffers an incident. Systems keep running — nothing was encrypted. Days later, an email arrives with samples of internal data and a 72-hour deadline to pay, under threat of publication. Paying doesn't end the case: months later, a new group appears with the same data and a new demand.
How the scam works
Modern groups have partly abandoned encryption (slow and easy to mitigate with backups) and adopted pure exfiltration: they break in, copy sensitive data and threaten to leak it. After payment, they frequently resell the data to other groups — the re-extortion. Babuk and its offshoots lead operations on Brazilian territory.
Common mistake
Betting on backup as the only antidote. Backup restores operations, it doesn't prevent leaks. And paying the ransom doesn't prevent re-extortion.
Impact
LGPD fines, class actions by data subjects, loss of contracts with confidentiality clauses, intellectual property exposure and permanent reputational damage. The total cost reaches multiples of the ransom amount.
What works
Blindfy structures a re-extortion response plan (with legal, regulatory and PR escalation), monitors the dark web and Telegram to warn of imminent leaks and works on damage containment via takedown of leak pages and mirror sites.
Protection checklist
- Classify data by sensitivity and segregate access
- Implement DLP (Data Loss Prevention) on network egress
- Monitor the dark web and Telegram channels for early alerts
- Keep a response plan with a clear legal-regulatory flow
- Train leadership for crisis communication under extortion
- Strengthen contractual customer notification clauses
- Test the response with quarterly tabletop simulations
Editorial sources
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
Paying doesn't close the case — it only funds the next one. Real defense starts at exfiltration detection, not at backup.