An extortion demand, and nothing is encrypted
Data theft extortion without encryption is routine now: Cl0p ran a whole campaign this way through MOVEit Transfer. The claim may be true, exaggerated, recycled from an old breach or invented, and the first hour is about finding out which without replying.
045 min90
- 01
Preserve the message and the sample with full headers
by 10 minexpiresExport the original with headers, links and attachments into evidence storage, hashed. If it links to a leak site or a file host, record the address and a screenshot, and open it only from an isolated analysis machine.
- 02
Date and source the sample
by 30 minWhich system does the data come from, and what is the newest record in it? A newest record from two years ago points to an old breach or a supplier; one from last week points to live access. File names, column layouts and export formats usually identify the system.