Blindfy — Digital Protection

Ransomware: re-extortion and the attack that doesn't encrypt

The new trend that skips encryption — it only steals and threatens to leak — and the advance of the Babuk group in Brazil.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

The company suffers an incident. Systems keep running — nothing was encrypted. Days later, an email arrives with samples of internal data and a 72-hour deadline to pay, under threat of publication. Paying doesn't end the case: months later, a new group appears with the same data and a new demand.

How the scam works

Modern groups have partly abandoned encryption (slow and easy to mitigate with backups) and adopted pure exfiltration: they break in, copy sensitive data and threaten to leak it. After payment, they frequently resell the data to other groups — the re-extortion. Babuk and its offshoots lead operations on Brazilian territory.

Common mistake

Betting on backup as the only antidote. Backup restores operations, it doesn't prevent leaks. And paying the ransom doesn't prevent re-extortion.

Impact

LGPD fines, class actions by data subjects, loss of contracts with confidentiality clauses, intellectual property exposure and permanent reputational damage. The total cost reaches multiples of the ransom amount.

What works

Blindfy structures a re-extortion response plan (with legal, regulatory and PR escalation), monitors the dark web and Telegram to warn of imminent leaks and works on damage containment via takedown of leak pages and mirror sites.

Protection checklist

  • Classify data by sensitivity and segregate access
  • Implement DLP (Data Loss Prevention) on network egress
  • Monitor the dark web and Telegram channels for early alerts
  • Keep a response plan with a clear legal-regulatory flow
  • Train leadership for crisis communication under extortion
  • Strengthen contractual customer notification clauses
  • Test the response with quarterly tabletop simulations

Editorial sources

Paying doesn't close the case — it only funds the next one. Real defense starts at exfiltration detection, not at backup.

← All risk analyses · Blindfy initial assessment