PlaybookCONSTRUCTEDMembers

Data theft extortion response plan: verify the claim, find the way out, own the notification

An extortion demand with nothing encrypted, or your name on a leak site. Three questions run in parallel with three owners: is the claim real, what left and how, and what you are obliged to say and to whom. A plan for answering each one on evidence rather than on the attacker's framing.

version 1.0checked 2026-09-26windows · linux · cloud · network6 min read

T1657T1567.002T1048T1041T1190T1530T1560.001T1074

what it covers

  1. What this plan is for
  2. Phase 1: verify the claim
  3. Phase 2: find the way out
  4. Phase 3: decide what must be said
  5. Phase 4: the demand
  6. Phase 5: communicate
  7. Review

sources

  1. CISA and MS-ISAC: #StopRansomware Guide · primary
  2. CISA AA23-158A: CL0P ransomware gang exploits CVE-2023-34362 MOVEit vulnerability
  3. NCSC: Ransomware, extortion and the cyber crime ecosystem
  4. GDPR Article 33: Notification of a personal data breach to the supervisory authority
  5. US Treasury OFAC: Updated advisory on potential sanctions risks for facilitating ransomware payments
  6. NIST SP 800-61 Revision 3

Tags: extortion · data-theft · exfiltration · leak-site · notification · legal · incident-response · T1657 · T1567 · cisa