An extortion demand, and nothing is encrypted

Data theft extortion without encryption is routine now: Cl0p ran a whole campaign this way through MOVEit Transfer. The claim may be true, exaggerated, recycled from an old breach or invented, and the first hour is about finding out which without replying.

Trigger. A message to staff, executives or a public address claiming to hold your data and demanding payment, often with a sample or a file listing, while every system is running normally.

The first 90 minutes1 of 5 expire
045 min90
  1. 01

    Preserve the message and the sample with full headers

    by 10 minexpires

    Export the original with headers, links and attachments into evidence storage, hashed. If it links to a leak site or a file host, record the address and a screenshot, and open it only from an isolated analysis machine.

  2. 02

    Date and source the sample

    by 30 min

    Which system does the data come from, and what is the newest record in it? A newest record from two years ago points to an old breach or a supplier; one from last week points to live access. File names, column layouts and export formats usually identify the system.