Incorporating Hargreaves Perkins Insurance Brokers
British Insurance Brokers' Association | Member

When Stolen Data Is Used for Cyber Extortion

A business restores its systems from clean backups and expects the worst of a cyber incident to be over. Then another message arrives.

The attackers claim they copied company data before the systems were encrypted. Unless payment is made, they threaten to publish or release that information.

At that point, restoring the network has solved only part of the problem.

Cyber extortion can involve more than preventing access to systems. Attackers may also use stolen information as leverage, placing pressure on directors even when the business has a viable route to technical recovery.

That distinction matters when reviewing cyber insurance. A business may need help with forensic investigation, specialist advice, communications, operational disruption and the extortion threat itself, depending on the incident and the policy wording.

Encryption and data theft create different problems

Ransomware is often associated with systems becoming unavailable because files or servers have been encrypted.

That remains a serious operational problem. Staff may lose access to production systems, customer records, finance software or shared files. Orders may be delayed and normal trading can quickly become difficult.

But an attacker may also copy information before encrypting the network.

That creates a separate exposure.

A business might be able to restore its systems from backups while still facing uncertainty over:

  • What information was taken
  • Whether the attackers genuinely hold it
  • Whether it has already been shared
  • Who could be affected
  • What the attackers intend to do with it
  • How the business should respond to the threat

Technical recovery and resolution of the extortion demand therefore do not necessarily happen at the same time.

A stolen-data extortion incident in practice

Consider a fictional Lancashire manufacturer supplying components to the construction sector.

The business employs 80 people and relies on a central production planning system. Its network also contains customer contact information, technical drawings and supplier records.

A member of the accounts team receives what appears to be a genuine email from a regular supplier. An attachment is opened and malicious software gains access to the network.

Over the weekend, attackers move through the systems. Files are copied and several key servers are encrypted.

On Monday morning, staff cannot access production schedules, invoices or stock information. A message demands a cryptocurrency payment within 72 hours and states that stolen information will be published if the business refuses.

The attackers also contact a director directly.

The immediate pressure is obvious. Production has been disrupted and the company needs to understand whether its systems can be restored.

But there is now a second problem.

Even if the encrypted systems can be recovered, the business still needs to establish what information may have left the network.

Establish whether data was actually taken

An extortion message may claim that large amounts of sensitive information have been copied.

That claim should not simply be accepted at face value.

A forensic investigation can help establish, as far as reasonably possible:

  • How the attackers entered the environment
  • Which accounts or systems they accessed
  • How long they had access
  • Whether files appear to have been copied
  • Which data may have been involved
  • Whether encryption was the only activity detected
  • Whether other systems remain compromised

This evidence can significantly affect the response.

An incident involving encrypted systems but no apparent data removal may present a different risk from one where customer records, confidential documents or commercially sensitive information appear to have been copied.

The business should therefore avoid making major decisions based only on the attacker’s claims.

The type of stolen information matters

Not all data creates the same exposure.

In the fictional manufacturer example, the affected systems contain customer contact details, technical drawings and supplier records.

Each type of information can create different concerns.

Customer information

If personal or customer information may have been accessed, the business may need specialist advice on what has been affected and what further steps are appropriate.

The position should be established carefully rather than communicating more widely than the known facts support.

Technical and commercial information

Technical drawings, specifications and other commercially sensitive records may create concerns around confidentiality, customer relationships or intellectual property.

The impact will depend on the nature of the files and who they relate to.

Supplier records

Supplier information may contain contact details, commercial correspondence or other records that require careful review.

The key point is that the response should be based on what the investigation identifies rather than treating all stolen files as one type of exposure.

Backups can restore systems but cannot retrieve stolen data

Reliable backups can make a major difference during a cyber incident.

If clean copies of systems and data remain available, the business may be able to restore operations without depending on a decryption tool supplied by the attacker.

But backups do not solve every part of a data-extortion event.

Once information has been copied outside the organisation, restoring the original files does not remove the attacker’s copy.

That means a company can be technically recovering while the extortion threat remains active.

For this reason, cyber resilience should not be judged only by whether a backup exists.

The business also needs to consider:

  • How quickly backups can be restored
  • Which systems need to return first
  • Whether restored systems are safe to reconnect
  • What information may have left the network
  • How the extortion threat will be managed alongside recovery

This is one reason ransomware cover should be considered in terms of the wider response rather than only the cost of recovering encrypted files.

Paying does not guarantee stolen data disappears

A demand for payment can place directors under intense pressure.

The attackers may give a short deadline and claim that refusal will result in sensitive information being published.

It can be tempting to treat payment as a way of making the problem disappear.

The position is rarely that simple.

Even if payment is made:

  • There may be no guarantee every copy of the information is deleted
  • The attackers may not honour their promise
  • The data may already have been shared
  • Further demands could follow
  • Payment may not resolve the technical recovery
  • Legal, sanctions or regulatory considerations may still need to be assessed

A business should therefore avoid negotiating, promising payment or transferring money without involving its insurer and appropriately qualified advisers.

Whether the policy responds to an extortion demand, specialist negotiation costs or any payment will depend on the wording, limits, circumstances and advice received at the time.

Specialist advice matters before engaging with attackers

Cyber extortion combines technical, legal, commercial and insurance issues.

That makes early specialist involvement particularly important.

Depending on the policy and incident, the response may involve:

  • A cyber incident manager
  • Forensic IT investigators
  • Legal advisers
  • Specialist communications support
  • Extortion or negotiation specialists
  • The business’s own IT provider

These roles are different but connected.

The forensic team may be trying to establish whether data has been taken.

Legal advisers may be considering the implications of the findings.

Communications specialists may be helping the business explain the situation accurately to customers, suppliers or employees where necessary.

The incident manager may be coordinating priorities while directors continue making operational decisions.

The value of this support is not simply technical expertise. It gives the business a structured way to make decisions while facts are still emerging.

Operational recovery and incident resolution are not the same thing

A business may reach the point where staff can work again before the cyber incident is fully resolved.

For the fictional manufacturer, restoring the production planning system may allow output to resume.

Invoices may once again be raised and stock information accessed.

That is operational recovery.

But the company may still be dealing with:

  • Ongoing forensic investigation
  • An extortion demand
  • Uncertainty over stolen information
  • Customer questions
  • Legal advice
  • Insurance documentation
  • Communications with affected parties
  • Additional recovery costs

This distinction matters when reviewing how much support a cyber policy provides.

Getting a server back online does not necessarily mean the business has reached the end of the loss.

Cyber insurance may respond across several sections

A single data-extortion incident can create several different types of cost.

Depending on the policy, cyber insurance may be designed to help with areas such as:

  • Forensic investigation
  • Incident response
  • Specialist legal support
  • Extortion response
  • Data and system restoration
  • Communications support
  • Certain notification-related costs
  • Business interruption
  • Additional costs incurred during recovery

The precise scope depends on the wording, limits, exclusions and conditions.

This is why the headline policy limit does not necessarily tell a business how much protection it has for a particular cyber-extortion event.

Different parts of the claim may fall under separate sections.

Check cyber extortion sub-limits before a claim

Cyber policies can contain different limits for different types of loss.

For example, incident response, extortion costs and cyber business interruption may not all share the same available limit.

There may also be:

  • Policy excesses
  • Waiting periods
  • Separate extortion sub-limits
  • Conditions around specialist providers
  • Requirements for insurer approval
  • Notification timescales
  • Different limits for communications or legal costs

These details are much easier to review at renewal than during a live extortion incident.

Businesses should also understand whether they are expected to use insurer-approved response providers before incurring major specialist costs.

Acting quickly matters, but so does following the policy process.

Keep communications factual while the position is being investigated

Cyber extortion can create pressure to communicate before the facts are clear.

Customers may be asking why orders are delayed. Employees may want to know what has happened. Suppliers may hear about the disruption.

If stolen data is suspected, the pressure increases.

The business should avoid speculation.

A measured approach is generally better.

Communications should reflect:

  • What is known
  • What is still being investigated
  • What practical action is being taken
  • Who genuinely needs information at that stage

Sending broad messages too early may create unnecessary concern if later investigation shows the incident was narrower than first thought.

Equally, communications should not be delayed without good reason where action is required.

Specialist support can help a business make those decisions based on evidence rather than pressure from the attacker.

Business interruption may continue after systems return

The financial impact of the incident may extend beyond the period when systems are unavailable.

In the manufacturer example, production is reduced while key systems are restored. Once normal access returns, the business may still face:

  • A production backlog
  • Overtime costs
  • Additional IT expenditure
  • Delayed customer orders
  • Extra management time
  • Reduced turnover during the outage

Where business interruption cover applies, the financial loss will need to be assessed in accordance with the policy.

This should not be confused with the extortion demand itself.

A single attack can create both an extortion exposure and a loss of trading, with different sections of the policy potentially becoming relevant.

Prepare for stolen-data extortion before an incident

A business cannot predict exactly how an attacker will behave.

It can, however, make the response easier by understanding its own exposure before anything happens.

Useful preparation includes identifying:

  • The information that would create the greatest concern if stolen
  • Where sensitive data is stored
  • Which systems the business cannot operate without
  • Whether backups are separate and tested
  • Who can make urgent decisions
  • How the insurer and broker can be contacted if normal systems are unavailable
  • Which incident-response providers are available through the policy
  • The limits and conditions applying to cyber extortion cover

Key contact details should also be available away from the network.

If the company’s normal email system is inaccessible, staff still need to know how to contact the right people.

Review whether the policy reflects the real extortion exposure

Cyber extortion is no longer only about deciding whether encrypted files can be recovered.

A business may restore its systems and still face pressure because customer records, confidential files or commercially sensitive information are being used as leverage.

That creates a more complicated incident.

Technical recovery, legal considerations, communications and the insurance response may all need to progress together.

The purpose of cyber insurance is not to remove every difficult decision. It is to provide access to financial protection and specialist support when the business is dealing with circumstances it may never have encountered before.

An experienced broker can help review whether the structure of the cover reflects that reality, including incident-response support, extortion limits, business interruption and the approvals required when specialist costs arise.

If attackers claim to hold stolen data, the business needs more than a working backup. It needs a clear route to specialist advice, evidence-led decision-making and insurance that has been considered before the pressure of a live incident begins.

FAQs About Cyber Extortion and Stolen Data

Can cyber extortion happen without ransomware encrypting a company’s systems?

Yes. Attackers may steal information and demand payment in return for not publishing, selling or otherwise disclosing it, even where the business’s systems remain operational. The insurance response will depend on the circumstances and policy wording.

Should a business preserve messages sent by cyber extortionists?

Yes. Messages, emails and other evidence relating to the demand may assist forensic investigators and specialist advisers. They should be preserved carefully and not altered or deleted while the incident is being assessed.

Can commercially sensitive data create an extortion exposure even if no personal data is involved?

Yes. Technical information, contracts, pricing details, intellectual property and confidential business records can all be valuable to attackers. The consequences may be commercial rather than privacy-related, depending on what has been taken.

Can a business appoint its own cyber response specialists after an extortion incident?

That depends on the policy. Some insurers require approved or panel specialists to be used, while others may permit different providers with prior agreement. Businesses should check the policy process before committing to significant external costs where possible.

Does cyber extortion insurance always reimburse the amount demanded by an attacker?

No. Cover for an extortion payment is policy-dependent and may be subject to separate limits, conditions, approvals and legal considerations. Cyber extortion cover should not be treated as an automatic promise that any demand will be paid.

Scroll to Top
Broker Banner