When ransomware victims become extortion targets
HuFiCon Management Memo:
Journey with the CISO
A mountain climb to cyber security resilience. Find out how to get to the summit of cyber security resilience in Inge van der Beijl's management memo, from her presentation at the Human Firewall Conference (HuFiCon) on the 14.11.2024.
The climb will take you from the base camp of foundational security to the high-camp of a security conscious culture, all the way to the summit consisting of strategic security integration.
Inge van der Beijl
Director Innovation

Prepare to protect people, not just systems, from cyberattacks
A company was hacked and your personal data was stolen. Unfortunately, it’s a scenario that’s all too familiar and not very surprising. Usually, you will receive a standard notification from the company about the data theft, as required by law. But what if you are also personally contacted by the hackers themselves? And, they demand that you pay up or risk having your sensitive data exposed. This is a shocking and very real incident that happened recently in the Netherlands.
In this case, the threat actor claims to have stolen data from grocery delivery company Flink and contacted the customers and employees whose data was stolen. According to a report by NOS, individuals were told to pay approximately €10–€15 in cryptocurrency or risk having their personal data published. Northwave’s Pim Takkenberg was interviewed by NOS and advised those customers and employees not to pay. He warns that the data theft victims have no way of knowing whether payment would actually result in their data being deleted. He also highlighted what makes the incident particularly notable: while threat actors have previously targeted organisations connected to an initial victim, directly approaching individual consumers in this way is a new development. However, this strategy already seems to be picking up steam. A little more than week later, ASOS customers received an in-app push notification that actually came from a ransomware gang.
The aggressive tactics used in these incidents are connected to a broader ransomware trend. Cybercriminals are looking for additional ways to exploit stolen data and put more pressure on targets. As such, preparing for an attack means considering not only what threat actors might do to your systems and data, but also what they might do to the people behind that data.
Cyber extortion is looking for new pressure points
Northwave has been tracking this shift closely. Traditional ransomware relied heavily on encryption. Attackers locked critical files and systems and demanded payment for their recovery. However, organisations have become better at defending against this form of extortion. Stronger backup and recovery capabilities, improved detection and greater employee awareness mean that many organisations can now restore operations without purchasing a decryptor.
These smart defensive measures are a threat to the ransomware business model. Now, we are seeing a decrease in the number of reported ransomware payments. In 2023, 63% of ransomware cases handled by Northwave’s CERT involved payment. By 2024, that number dropped to 50%.

Threat actors have responded by finding other forms of leverage.
Data theft became an important part of the ransomware business model, resulting in double extortion: encrypting systems while also threatening to publish stolen information. Other attacks have abandoned encryption altogether and focused solely on exfiltrating valuable data. Stolen information can subsequently expose organisations to reputational and legal consequences, while potentially enabling further crimes such as identity theft and fraud.
The report, Inside the Ransomware Ecosystem 2025, published by Northwave and Marsh, also highlights the growth of triple and quadruple extortion tactics that add layers of pressure following cyberattacks. One of these is target chasing, in which threat actors directly contact executives, employees, business partners or other stakeholders to create psychological pressure and internal confusion.
In the recent Flink incident, it’s clear how this principle can potentially be extended. Rather than using customers simply as leverage against an organisation, threat actors can use stolen contact information to approach the individuals themselves with separate demands. As a result, customers and employees are no longer only stakeholders who need to be informed about an incident. They may become direct targets of the threat actor.
Furthermore, we’ve observed in the past few years that new ransomware gangs tend to be less experienced and less reliable than their predecessors. As we reported after last year’s cyberattack on the Clinical Diagnostics medical lab in the Netherlands, this can result in unpredictable interactions with threat actors who “break their own rules”.

Prepare to protect people, not just systems
Northwave’s Director of Innovation and Cyber Psychologist Inge van der Beijl addressed the societal toll of cybercrime following the cyberattack on Odido in early 2026. When organisations are the victims of a cyberattack, they must carefully weigh the potential impact a data theft could have on so-called “indirect victims”. Therefore, when personal data has been stolen, organisations should consider a critical question as part of their incident response: Could the threat actor use this information to contact or further victimise our employees, customers or partners?
If the answer is yes, communication is an important part of the defence.
Our cyber crisis and incident communication research emphasises that transparency should primarily help affected people understand the potential impact of the incident and what they should do next. At the same time, organisations should only communicate verified information and avoid disclosing details that could assist the attacker. In practice, organisations facing data extortion should consider several measures:
- Warn affected people about the possibility of direct contact.
If there is a credible risk that attackers may approach customers or employees, tell them what they might encounter and through which channels. This can reduce the element of surprise that gives the extortion tactic much of its power. - Give clear instructions on what to do.
Employees and customers should know how to report suspicious communication and where they can obtain reliable information. Our ransomware communication experts advise organisations to immediately update internal protocols when threat actors begin “chasing” their employees and instruct employees not to engage directly. - Address the risks that matter to the individual.
Generic statements about an ongoing investigation are unlikely to answer the questions people have when their own information may be involved. Clearly explain the confirmed details regarding the types of data that are affected, what the breach could mean for them, and which practical precautions they can take. - Create a reliable source of information.
Threat actors benefit from confusion. Establish clear channels where customers and employees can verify communications, ask questions and report suspicious approaches. Monitor these channels closely so messaging can be refined as new concerns and tactics emerge. - Prepare these processes before an incident occurs.
The first hours of a ransomware attack are not the time to decide who owns customer communication, how employees should report attacker contact or which channels will remain available. Crisis communication plans should anticipate these scenarios, with roles, escalation paths, target audiences and key messages established and exercised in advance.

Extortion tactics will continue to evolve. Preparation needs to evolve with them.
The incidents involving Flink and ASOS reveal how cybercriminals continue to search for additional leverage when established extortion tactics become less effective. For organisations, this means ransomware resilience cannot end with backups, recovery and technical incident response. It must also account for how stolen information can be weaponised against customers, employees and other stakeholders. When those people become the next targets of an attack, timely and carefully considered communication can help take some of that leverage away from the threat actor.
Our free guide, Managing Communications During Cyber Crises and Incidents, provides practical advice for preparing communication strategies before an incident and managing them throughout response and recovery. If you’d like support with developing and practising your cyber crisis and incident response plans, get in touch with Northwave’s cyber crisis readiness team today.
We are here for you
Need help with your cyber security or wondering how secure your business really is?
Get in touch and we will help you find the best solution.
