Call our IT experts today on 01254 877009
info@use-it.co.ukLancs BB1 4LA
Getting hit by ransomware is bad enough. But imagine thinking it’s all over, only to get targeted again by a second scam. That’s exactly what’s happening to victims of Royal and Akira ransomware – cybercriminals are coming back for more.
According to security researchers at Arctic Wolf Labs, hackers are launching follow-on extortion attacks, pretending to offer help but actually trying to scam victims twice. If your organisation has been affected by ransomware, or if you just want to stay ahead of cyber threats, here’s what you need to know.
What’s Happening?
Who’s being targeted? Businesses and organisations that were already victims of Royal or Akira ransomware.
What’s the scam? Attackers claim they want to help the victim. They say they’ll hack into the original ransomware gang’s servers and delete the stolen data to protect the victim’s sensitive information.
What’s the real goal? It’s just another extortion attempt. These scammers aren’t helping at all – they’re simply trying to trick victims into paying more money, either for a fake data deletion service or as a second ransom payment.
When did this start? Arctic Wolf Labs has documented cases of these follow-on attacks since October 2023, meaning this scam has been running for months.
It’s a double hit – first, victims lose data and money to ransomware, then they’re tricked into paying again with false promises.
How Do These Attacks Work?
Cybercriminals behind this scam are smart. They know that after a ransomware attack, organisations are desperate to recover and secure their data. Here’s how they manipulate that fear:
1 They contact the victim, pretending to be security experts or “ethical hackers”.
2 They claim to have access to the ransomware group’s servers and offer to delete the victim’s stolen data.
3 They demand another payment, insisting it’s a “small price to pay” to permanently erase sensitive files.
4 They disappear after getting paid – without actually doing anything.
It’s all a lie. These scammers have no connection to the original ransomware gangs. They’re simply preying on victims who are already vulnerable.
How to Protect Yourself from Follow-On Attacks
If your organisation has been hit by ransomware, stay alert – cybercriminals may try to scam you again. Here’s how to avoid falling victim to follow-on extortion attempts: