PlaybookCONSTRUCTEDMembers
Data theft extortion response plan: verify the claim, find the way out, own the notification
An extortion demand with nothing encrypted, or your name on a leak site. Three questions run in parallel with three owners: is the claim real, what left and how, and what you are obliged to say and to whom. A plan for answering each one on evidence rather than on the attacker's framing.
version 1.0checked 2026-09-26windows · linux · cloud · network6 min read
T1657T1567.002T1048T1041T1190T1530T1560.001T1074
what it covers
- What this plan is for
- Phase 1: verify the claim
- Phase 2: find the way out
- Phase 3: decide what must be said
- Phase 4: the demand
- Phase 5: communicate
- Review
sources
- CISA and MS-ISAC: #StopRansomware Guide
- CISA AA23-158A: CL0P ransomware gang exploits CVE-2023-34362 MOVEit vulnerability
- NCSC: Ransomware, extortion and the cyber crime ecosystem
- GDPR Article 33: Notification of a personal data breach to the supervisory authority
- US Treasury OFAC: Updated advisory on potential sanctions risks for facilitating ransomware payments
- NIST SP 800-61 Revision 3