Skip to content

Extortion following a data breach

In plain terms

A message announces that your data was stolen from a service you genuinely use, and demands payment to avoid publishing it. The breach itself did happen — that's what makes the threat credible.

Definition

Extortion following a data breach exploits a real compromise that happened at a third party: the perpetrator threatens to publish or resell information about a person or organization unless a payment is made.

How it works

This form of blackmail differs from fake hacking blackmail in one decisive way: something actually exists. A database was compromised at a provider, a retailer, an institution, and the data is circulating. The perpetrator pulls genuine details from it — a case number, an address, a purchase history — and cites them to establish credibility within a few lines. The threat is therefore not unverifiable, which makes it more effective. It remains without a real resolution: the data is already out of anyone's control, often held by several parties, and paying doesn't get any verifiable deletion. When aimed at an organization, this form of blackmail comes with a public deadline and the threat of notifying the people affected, to add reputational pressure.

Warning signs

  • A message citing accurate information from a service you use
  • A reference to a real data breach, sometimes already made public
  • A short deadline paired with a threat of publication or resale
  • Payment demanded in cryptocurrency, with no verifiable commitment in return
  • A threat to contact your customers, people close to you, or your employer

How to verify

Check whether the breach actually happened with the service concerned: organizations are required to notify affected individuals, and a real incident usually leaves a trace. This tells you what genuinely leaked — useful information for protecting yourself — without giving any credibility to the payment demand.

What to do

Don't pay: no deletion can be verified, and the data is frequently held by several parties. Act on what you still control: change the affected passwords, enable two-factor authentication, and watch for the phishing attempts that will follow, since stolen data is first used to make them credible.

If it already happened

File a police report and preserve the message along with the details cited. Report the incident to the service where the breach originated: it has notification obligations, and your report may concern other people too. For an organization, the incident falls under a data-protection-authority notification procedure, and the blackmail attempt doesn't exempt anyone from it. If health or identity data is involved, stay alert to any procedures opened under your name.

Frequently asked questions

Would paying prevent the publication?
There's no way to verify that, and that's the central issue: a copied piece of data can't be un-copied. The same batches often circulate among several parties, and a payment mainly identifies someone willing to pay.
How can I know what actually leaked?
Ask the service concerned, which is required to inform affected people about the nature of the data involved. That's the only reliable source — not the blackmail message, whose description is meant to frighten, not to inform.

Official sources

Also known as: post-breach extortion, data blackmail, ransom without encryption.

This article is part of the Blackmail, harassment and personal harm family. Last updated: 2026-09-02.