Security Stop Press : Follow-On Extortion of Ransomware Victims

Published on

Getting hit by ransomware is bad enough. But imagine thinking it’s all over, only to get targeted again by a second scam. That’s exactly what’s happening to victims of Royal and Akira ransomware – cybercriminals are coming back for more.
According to security researchers at Arctic Wolf Labs, hackers are launching follow-on extortion attacks, pretending to offer help but actually trying to scam victims twice. If your organisation has been affected by ransomware, or if you just want to stay ahead of cyber threats, here’s what you need to know.
What’s Happening?
Who’s being targeted? Businesses and organisations that were already victims of Royal or Akira ransomware.
What’s the scam? Attackers claim they want to help the victim. They say they’ll hack into the original ransomware gang’s servers and delete the stolen data to protect the victim’s sensitive information.
What’s the real goal? It’s just another extortion attempt. These scammers aren’t helping at all – they’re simply trying to trick victims into paying more money, either for a fake data deletion service or as a second ransom payment.
When did this start? Arctic Wolf Labs has documented cases of these follow-on attacks since October 2023, meaning this scam has been running for months.
It’s a double hit – first, victims lose data and money to ransomware, then they’re tricked into paying again with false promises.
How Do These Attacks Work?
Cybercriminals behind this scam are smart. They know that after a ransomware attack, organisations are desperate to recover and secure their data. Here’s how they manipulate that fear:
1 They contact the victim, pretending to be security experts or “ethical hackers”.
2 They claim to have access to the ransomware group’s servers and offer to delete the victim’s stolen data.
3 They demand another payment, insisting it’s a “small price to pay” to permanently erase sensitive files.
4 They disappear after getting paid – without actually doing anything.
It’s all a lie. These scammers have no connection to the original ransomware gangs. They’re simply preying on victims who are already vulnerable.
How to Protect Yourself from Follow-On Attacks
If your organisation has been hit by ransomware, stay alert – cybercriminals may try to scam you again. Here’s how to avoid falling victim to follow-on extortion attempts:

  • Don’t Trust Unsolicited Offers of Help – If someone reaches out claiming they can delete stolen data, be suspicious. Cybercriminals don’t work like that.
  • Work with Trusted Security Experts – If you need help after a ransomware attack, hire a reputable cybersecurity firm, not someone who contacts you out of the blue.
  • Verify All Communications – If you receive messages or calls about your ransomware attack, check the source carefully. Scammers often pretend to be security professionals.
  • Never Pay a Second Ransom – Paying cybercriminals once is bad enough, but paying again doesn’t guarantee anything. Instead, focus on securing your systems to prevent further attacks.
  • Improve Your Cyber Defences – If your organisation has been attacked once, strengthen your security to avoid future breaches. This means patching vulnerabilities, using strong authentication, and backing up data securely.
    Why Does This Matter?
    The fact that cybercriminals are double-dipping shows how ruthless they are. Even when a ransomware gang has been paid off or disrupted, others are still looking to exploit victims further.
    It’s also a reminder that paying a ransom doesn’t solve the problem. Many organisations think that once they pay, their data is safe – but as this new scam proves, attackers can and will come back for more.
    Final Thoughts: Stay Alert, Stay Secure
    If your organisation has been hit by Royal or Akira ransomware, or any other cyberattack, be on high alert for follow-on scams. Cybercriminals are always looking for new ways to squeeze more money out of their victims.
    Don’t trust random offers of help.
    Work with real cybersecurity professionals.
    Focus on long-term protection, not quick fixes.
    Ransomware attacks are tough to deal with, but falling for a second scam only makes things worse. Stay cautious, stay informed, and keep your business one step ahead of cybercriminals.
    Have you heard of similar scams before? Let us know – the more we share, the safer we all are!