RepublicCyberIntel

Beyond file-locking: triple extortion, affiliate speed, and who gets hit

20 September 2026

Three stacked layers of extortion

From locks to layers

Early ransomware asked one question: pay for the key? Then came double extortion (Maze, 2019): pay, or stolen data gets published. Now industry tracking describes triple and multi-extortion: encryption, plus public leaks, plus DDoS attacks, plus direct harassment of customers and partners — each layer an independent reason to pay. The target is no longer your files; it is your relationships.

Affiliate speed: breakout in minutes

Ransomware-as-a-service industrialised the crime: developers lease the toolkit, affiliates bring access, profits split automatically. Modular playbooks compress every phase — initial access to domain-wide encryption now routinely unfolds far faster than defenders' shift rotations. The practical consequence: prevention (patching, MFA, backups) beats response, because response no longer gets a head start.

Sector focus: why hospitals and factories

Manufacturing, healthcare, and wholesale supply chains top victim lists for one reason: downtime intolerance. A factory line halted or an ER diverted creates life-safety pressure to pay quickly. Attackers follow the willingness to pay, not the prestige of the logo.

What still stops it (unchanged since our ransomware guide)

  1. Offline 3-2-1 backups — the only defence that survives all three extortion layers (leaks still hurt, but operations continue and payment pressure collapses).
  2. Patch + MFA on remote access — the two doors affiliates actually walk through.
  3. Incident rehearsal — know who disconnects what, who calls whom, and where the clean backups are, before the ransom note.

For individuals the translation is simpler: the same backup habit, the same suspicion of attachments (scan them), the same quarterly breach re-check. The gangs are faster; the fundamentals haven't moved.