Double extortion
A ransomware tactic where the attacker steals your data before encrypting it, then threatens to publish it if you refuse to pay.
Single extortion was simple: encrypt, demand payment for the key, and a good backup beat it. Crews adapted. Now the data is exfiltrated first, so a clean restore solves the availability problem but does nothing about the copy sitting on a leak site.
For a regulated business the second half is usually the more expensive one. Publication turns an IT incident into a reportable breach with notification duties, regulator attention, and potential litigation. Preventing exfiltration means egress monitoring and least privilege, not just better backups.
Where this comes up
Double extortion sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.