Beyond file-locking: triple extortion, affiliate speed, and who gets hit
20 September 2026
From locks to layers
Early ransomware asked one question: pay for the key? Then came double extortion (Maze, 2019): pay, or stolen data gets published. Now industry tracking describes triple and multi-extortion: encryption, plus public leaks, plus DDoS attacks, plus direct harassment of customers and partners — each layer an independent reason to pay. The target is no longer your files; it is your relationships.
Affiliate speed: breakout in minutes
Ransomware-as-a-service industrialised the crime: developers lease the toolkit, affiliates bring access, profits split automatically. Modular playbooks compress every phase — initial access to domain-wide encryption now routinely unfolds far faster than defenders' shift rotations. The practical consequence: prevention (patching, MFA, backups) beats response, because response no longer gets a head start.
Sector focus: why hospitals and factories
Manufacturing, healthcare, and wholesale supply chains top victim lists for one reason: downtime intolerance. A factory line halted or an ER diverted creates life-safety pressure to pay quickly. Attackers follow the willingness to pay, not the prestige of the logo.
What still stops it (unchanged since our ransomware guide)
- Offline 3-2-1 backups — the only defence that survives all three extortion layers (leaks still hurt, but operations continue and payment pressure collapses).
- Patch + MFA on remote access — the two doors affiliates actually walk through.
- Incident rehearsal — know who disconnects what, who calls whom, and where the clean backups are, before the ransom note.
For individuals the translation is simpler: the same backup habit, the same suspicion of attachments (scan them), the same quarterly breach re-check. The gangs are faster; the fundamentals haven't moved.