From $10 to $30M: Operating in the Data-Extortion Aftermath

Diego Matos (Incident Response Leader for Latin America · IBM)

BSidesSF 2026 · Day 1 · AMC IMAX

Overview

In his compelling BSides SF talk, "From $10 to $30M: Operating in the Data-Extortion Aftermath," Diego Matos, IBM's Latin American Incident Response Leader, provides a critical examination of the evolving landscape of data extortion. Drawing on over 16 years of experience in both offensive and defensive security, Matos guides the audience through the historical progression of ransomware and extortion tactics, highlighting the increasing sophistication and professionalization of cybercriminal enterprises. The presentation culminates in a detailed case study of a real-world incident where a $10 credential purchase on the dark web escalated into a multi-million dollar data extortion attempt.

Watch on YouTube

Visual summary for From $10 to $30M: Operating in the Data-Extortion Aftermath by Diego Matos
Visual summary for From $10 to $30M: Operating in the Data-Extortion Aftermath by Diego Matos

Key moments

  1. 0:00 Speaker introduction and talk overview
  2. 2:00 First ransomware: Aid Trojan (1989) and its limitations
  3. 3:00 WannaCry and the impact of stronger encryption
  4. 4:00 Rise of professional ransomware operations and Conti group
  5. 6:00 Modern multi-extortion methods and MGM Resorts attack
  6. 7:00 Standard attack path from initial access to extortion
  7. 8:30 Billions in financial gains for cybercriminals from extortion

From $10 to $30M: Operating in the Data-Extortion Aftermath

Speakers: Diego Matos, Latin American Incident Response Leader, IBM

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=AM8lRCkbol0

Overview

In his compelling BSides SF talk, "From $10 to $30M: Operating in the Data-Extortion Aftermath," Diego Matos, IBM's Latin American Incident Response Leader, provides a critical examination of the evolving landscape of data extortion. Drawing on over 16 years of experience in both offensive and defensive security, Matos guides the audience through the historical progression of ransomware and extortion tactics, highlighting the increasing sophistication and professionalization of cybercriminal enterprises. The presentation culminates in a detailed case study of a real-world incident where a $10 credential purchase on the dark web escalated into a multi-million dollar data extortion attempt.

This talk is highly relevant for cybersecurity professionals, incident responders, C-suite executives, and anyone involved in organizational risk management. Matos underscores the shift from simple data encryption to multi-faceted extortion strategies, including data leakage, Distributed Denial of Service (DDoS) attacks, and direct harassment of stakeholders. The discussion emphasizes the profound financial, reputational, and operational impacts of these attacks, moving beyond mere technical remediation to encompass crisis management, legal considerations, and strategic communication in the face of relentless cyber threats. Understanding these dynamics is crucial for organizations to develop robust defense mechanisms and effective incident response playbooks in an era where data extortion is a primary concern.

Background

▶ Watch: Speaker introduction and talk overview (0:00)

The journey of cyber extortion began modestly in 1989 with the Aid Trojan, a rudimentary piece of malware that encrypted user data and demanded payment via a traceable postal mailbox in Panama. This early attempt, largely ineffective and unscalable, laid the groundwork for future, more sophisticated attacks. The landscape evolved significantly with the adoption of stronger encryption algorithms, such as RSA 2058, moving beyond simple encryption to initial forms of extortion where victims paid solely to decrypt their data. A pivotal moment in this phase was the WannaCry attack, which crippled the UK's National Health Service (NHS), forcing the cancellation of 90,000 appointments and impacting medical devices. This incident highlighted the real-world, life-threatening consequences of ransomware.

The third phase marked a profound professionalization of cybercriminal operations. Threat actors transitioned from individual hackers to highly structured organizations, often operating under a Ransomware-as-a-Service (RaaS) model. These groups developed internal structures mirroring legitimate businesses, complete with affiliates, negotiation teams, and 24/7 victim support. They offered encryption keys, promised data deletion, or provided "help" to avoid further business impacts. A prime example of this professionalization was the Conti group, infamous for its attack on Costa Rica's government, which led to a national emergency declaration. Leaks from Conti's internal operations, triggered by events related to the Russia-Ukraine conflict, revealed a sophisticated hierarchy, affiliate programs, and significant revenue, reaching $108 million in 2021.

The current, fourth phase, which closely resembles today's threat landscape, sees threat groups employing quadruple extortion tactics. Beyond encrypting data and threatening its exposure, they now leverage DDoS attacks against victim infrastructure and actively harass customers, partners, and employees to exert maximum pressure. The attack against MGM Resorts, which halted casino operations in Las Vegas, serves as a stark reminder of the operational disruption these advanced tactics can achieve. The typical attack path now involves:

  1. Initial Access: Exploiting vulnerabilities, stealing credentials, or purchasing them from dark web brokers.
  2. Internal Reconnaissance & Lateral Movement: Mapping the network and expanding access.
  3. Persistence: Establishing footholds for continued access.
  4. Exfiltration: Stealing sensitive data using legitimate tools like WinSCP to avoid detection.
  5. Detonation/Extortion: Either deploying ransomware to encrypt systems or proceeding directly to extortion based on the exfiltrated data.

This evolution has led to significant financial gains for cybercriminals, with annual figures ranging from $600 million to over $1 billion between 2020 and 2025. While there has been a recent stagnation in the total amount collected, attributed to improved cybersecurity controls and better organizational processes, the number of active threat groups has surged by 49% leading into 2025, resulting in a 50% increase in data leak events. Paradoxically, fewer companies are paying ransoms, but when they do, the payments are substantially higher, with a reported 400% increase in average ransom amounts observed leading into 2025. This fuels the sophisticated and ever-growing cybercrime ecosystem.

Key Findings

▶ Watch: WannaCry and the impact of stronger encryption (3:00)

Diego Matos's analysis reveals several critical findings about the contemporary data extortion landscape:

  • Professionalization of Cybercrime: Threat groups operate with highly structured hierarchies, often mirroring legitimate businesses, with executive, strategic, tactical, and operational levels. This includes roles for hiring insiders, developing tools, managing exfiltration, and money laundering. The leaked internal structures of groups like Conti and LockBit vividly illustrate this, showing affiliate programs, revenue splits (e.g., LockBit affiliates retaining 80% of successful ransoms), and even access fees for their panels ($777 for LockBit).
  • Escalating Extortion Tactics: The shift from single extortion (encryption) to quadruple extortion (encryption, data leakage, DDoS attacks, and harassment of stakeholders) significantly amplifies pressure on victims. Groups like LockBit are known for threatening DDoS attacks and direct outreach to customers and employees if negotiations falter.
  • Reduced Payment Rates, Increased Payment Amounts: While more companies are opting not to pay ransoms due to improved defenses and processes, those that do end up paying significantly more. Matos highlighted a staggering 400% increase in average ransom payments observed leading into 2025, indicating that successful attacks are yielding much larger payouts for criminals.
  • Surge in Threat Group Activity and Leak Events: Despite the stagnation in overall collected ransom amounts, the number of active threat groups globally increased by 49% leading into 2025. This proliferation led to a 50% increase in data leak events, demonstrating that while payment rates might be down, the volume of attacks and data exposure continues to rise.
  • Dark Web Credential Market as a Major Entry Point: A recurring theme is the ease and low cost of initial access through stolen credentials available on the dark web. The case study presented by Matos underscores this, with a $10 credential purchase initiating a multi-million dollar incident.
  • Varying Negotiation Playbooks: Different threat groups employ distinct negotiation strategies. Aira, for instance, offers post-incident reports and significant discounts (40-60%) to incentivize payment. LockBit is known for its aggressive stance, quickly escalating to DDoS if negotiations don't progress. KillNet focuses on rapid data leakage if demands are not met, or large discounts if they are.
  • Traceability of Cryptocurrency: Despite the perceived anonymity, law enforcement operations like CoronOS against LockBit demonstrate the ability to track cryptocurrency movements. Matos cited the example of Ian Condorf, a sanctioned individual linked to LockBit, whose crypto wallet alone moved 52 Bitcoins (approximately $4 million), indicating the vast sums handled by these networks.

These findings collectively paint a picture of a dynamic, highly organized, and financially motivated cybercrime landscape that demands sophisticated and multi-faceted defensive strategies.

Technical Deep Dive

▶ Watch: Rise of professional ransomware operations and Conti group (4:00)

The technical underpinnings of modern data extortion attacks have evolved significantly since the early days of simple encryption. The core technical progression can be observed across several domains:

1. Encryption Strength: Early malware like the Aid Trojan used basic encryption, but modern ransomware employs robust algorithms such as RSA 2058, making decryption without the key practically impossible. This strong encryption forms the foundation of the initial extortion vector.

2. Initial Access & Tooling:

  • Credential Theft/Purchase: The most common initial access vector involves stolen credentials. These are often purchased for minimal amounts ($10 in the case study) on dark web marketplaces from brokers.
  • Info Stealers: Tools like Hakon are frequently used to harvest credentials, browser data, and other sensitive information from compromised systems, providing attackers with the keys to penetrate corporate networks.
  • Vulnerability Exploitation: Attackers also exploit known vulnerabilities in public-facing services (e.g., unpatched VPNs, web applications) to gain an initial foothold.

3. Internal Operations (MITRE ATT&CK Alignment):

  • Reconnaissance & Lateral Movement: Once inside, attackers perform extensive internal reconnaissance to map the network, identify critical assets, and locate valuable data. They then use various techniques for lateral movement, often leveraging legitimate administrative tools or stolen privileged credentials to spread across the environment.
  • Persistence: Establishing persistence ensures continued access even if initial entry points are remediated. This can involve creating new user accounts, installing backdoors, or modifying system configurations.
  • Data Exfiltration: This is a crucial technical step in data extortion. Attackers prioritize stealth, often using common, legitimate tools already present on victim networks, such as WinSCP (for SCP/SFTP transfers), cloud synchronization tools, or even custom scripts. This minimizes alerts to security teams compared to deploying novel, identifiable malware. The case study involved the exfiltration of 4 terabytes of data.

4. Extortion Modalities (Quadruple Extortion):

  • Data Encryption: The classic ransomware attack, rendering systems and data inaccessible.
  • Data Leakage: Threatening to publish sensitive exfiltrated data on leak sites, breach forums, or directly to competitors/media. This can include intellectual property, customer data, financial records, or internal communications.
  • Distributed Denial of Service (DDoS): Threatening to launch DDoS attacks against the victim's public-facing infrastructure, disrupting operations and causing further reputational damage. LockBit is a notable group employing this tactic.
  • Harassment of Stakeholders: Directly contacting customers, partners, and employees to inform them of the breach, creating internal and external pressure on the victim organization.

5. Negotiation Playbooks:

  • Dynamic Pricing: Ransom demands are not static. Actors often start with a high figure and threaten to increase it daily if negotiations are delayed, as seen in the $10M to $30M case.
  • Incentives and Threats: Groups like Aira might offer "post-incident reports" detailing how they breached the network, along with significant discounts (40-60%) to encourage payment. Conversely, groups like LockBit and KillNet escalate quickly with DDoS attacks or immediate data leaks if demands are not met or negotiations stall.
  • Cryptocurrency Transactions: Payments are almost exclusively demanded in cryptocurrency (e.g., Bitcoin, Monero) to complicate tracing. However, law enforcement efforts, such as Operation CoronOS against LockBit, have demonstrated the ability to track these transactions, leading to arrests and sanctions against individuals like Ian Condorf, whose wallets were found to have moved substantial amounts (e.g., 52 Bitcoins from one specific wallet).

The "aha moment" in incident response, as described by Matos, often comes from unexpected clues, such as an attacker mistakenly leaking their own script containing an API key, which can rapidly accelerate containment efforts by revealing the attack's specific path and tools. This highlights the importance of thorough forensic analysis even when initial indicators are present.

Demo / Proof of Concept

▶ Watch: Standard attack path from initial access to extortion (7:00)

While the talk did not feature a live technical demonstration, Diego Matos presented a compelling real-world case study that served as a powerful "proof of concept" for the entire data extortion lifecycle and its aftermath. This incident, which IBM's global incident response team managed, perfectly illustrated the escalating nature of these attacks and the complexities of responding to them.

The incident began with the discovery of information leaked on breach forums, accompanied by a direct message from the threat actor to the victim company's VP of IT. The actor claimed to have "dumped" sensitive data and provided a password-protected URL as proof, threatening to release the password and expose the entire dataset if a negotiation wasn't initiated. To validate their claims, the actor shared a sample of the exfiltrated data, which allowed the incident response team to begin tracing the source.

Critically, the threat actor made a significant mistake: they inadvertently leaked the script they used for the attack, which contained a specific API key. This accidental disclosure provided the incident response team with an immediate "aha moment," accelerating their investigation and containment efforts. The investigation quickly revealed that the initial access was gained through a privileged credential purchased on the dark web for a mere $10. This credential was compromised via an info stealer called Hakon, which enabled the attacker to establish a foothold and execute their full attack flow.

The attacker successfully exfiltrated a massive 4 terabytes of data. During negotiations, the actor initially claimed to have 2.5 terabytes and falsely asserted they had an "insider" within the company, offering to expose this alleged insider if paid. They adopted an aggressive negotiation posture, threatening to increase the ransom demand daily, escalating from an initial undisclosed amount to $30 million if the company did not engage quickly. Despite multiple extortion attempts, the company ultimately chose not to pay the ransom, which reportedly "pissed off" the threat actor.

This case study underscored the severe impacts of such incidents, including significant reputational damage and the immense challenge of managing crisis communications both internally and externally. It demonstrated that initial access can be incredibly cheap, but the resulting fallout can be astronomically expensive, requiring a comprehensive and professional incident response effort encompassing technical, legal, and communication strategies.

Defensive Implications

▶ Watch: Billions in financial gains for cybercriminals from extortion (8:30)

Responding to and mitigating data extortion attacks requires a multi-layered and coordinated strategy, extending far beyond purely technical controls. Diego Matos outlined several critical defensive implications for organizations:

  1. Proactive Threat Intelligence & Dark Web Monitoring: Organizations must actively monitor dark web marketplaces for compromised credentials related to their domain. The $10 credential example highlights how cheap and accessible initial access can be. Implementing strong password policies, multi-factor authentication (MFA), and regular credential hygiene are paramount.
  2. Robust Incident Response Plan & Crisis Management Team: A well-defined incident response plan is crucial. This includes establishing a dedicated crisis management team comprising executives, legal counsel, communications experts, and technical responders. This team needs clear playbooks for different extortion scenarios and defined escalation procedures.
  3. Legal Counsel & Law Enforcement Engagement: Immediately involve legal counsel to navigate regulatory requirements (e.g., GDPR, CCPA) and potential liabilities. Engaging law enforcement (e.g., FBI, local police) is highly recommended, as they can provide resources, track threat actors, and potentially lead to asset recovery or arrests. Matos emphasized that dealing with criminals can have legal ramifications, making professional guidance essential.
  4. Cyber Insurance Activation: Activate cyber insurance policies early in the incident. These policies can cover costs associated with incident response, legal fees, public relations, and sometimes even ransom payments (though paying ransom has its own complexities and ethical considerations).
  5. Professional Negotiation Strategy: If direct communication with threat actors is deemed necessary, it must be handled by specialized, professional negotiators. These communications are often monitored and can be leaked to the media, impacting public perception. The goal is to gather intelligence, buy time, and manage the situation without over-communicating or making commitments that cannot be kept.
  6. Comprehensive Communication Strategy: Develop pre-approved statements and a clear communication plan for internal employees, external stakeholders, customers, and the media. Over-communication or miscommunication can exacerbate reputational damage and legal exposure. Ensure employees are aware of policies regarding discussing the incident publicly.
  7. Technical Preparedness & Forensics:
  • Advanced Threat Detection: Implement EDR/XDR, SIEM, and network monitoring to detect early indicators of compromise (IOCs), lateral movement, and data exfiltration attempts.
  • Proactive Hunting: Regularly hunt for threats within the environment, leveraging frameworks like MITRE ATT&CK to identify attacker tactics, techniques, and procedures (TTPs).
  • Robust Backups & Recovery: While not a complete solution against quadruple extortion, immutable, offline backups remain critical for data recovery after encryption.
  • Containment & Eradication: Rapidly isolate compromised systems and eradicate the threat to prevent further spread and exfiltration.
  1. Understanding Business Impact: Beyond technical damage, assess the full scope of financial impacts, including reputational damage, stock market value loss, regulatory fines, and the cost of improving security posture. Review contracts with clients and partners to understand potential liabilities arising from data exposure.
  2. Continuous Improvement: Post-incident, conduct thorough lessons learned exercises to identify gaps in security controls, processes, and response capabilities, and implement necessary improvements to increase organizational maturity.

Matos stressed that organizations must abandon the mindset that backups alone are sufficient. The modern threat landscape demands a holistic approach that anticipates multi-faceted extortion and integrates technical, legal, and business continuity strategies.

Key Takeaways

  • Ransomware has Evolved into Multi-Layered Data Extortion: Beyond just encrypting data, modern threat groups employ "quadruple extortion" tactics, including data leakage, DDoS attacks, and direct harassment of customers and employees, significantly increasing pressure on victims.
  • Cybercrime is a Professionalized, Structured Enterprise: Threat actors operate with sophisticated internal structures, often mirroring legitimate businesses, with affiliate programs, specialized roles for negotiation, tool development, and money laundering, making them highly efficient and persistent.
  • Initial Access is Cheap, Consequences are Costly: Credential theft and purchases on the dark web (e.g., a $10 credential) are common entry points, leading to multi-million dollar extortion demands, massive data exfiltration (e.g., 4 terabytes), and severe financial and reputational damage.
  • Comprehensive Incident Response Requires a Holistic Approach: Effective response demands a coordinated effort involving a crisis management team, legal counsel, law enforcement, cyber insurance, and professional negotiators, extending beyond purely technical remediation to include strategic communication and risk assessment.
  • Proactive Defenses and Preparedness are Paramount: Organizations must implement robust security controls (MFA, EDR, threat hunting), monitor for dark web compromises, and develop detailed incident response playbooks for various extortion scenarios, rather than relying solely on backups.
  • Payment Decisions are Complex and Nuanced: While fewer companies are paying ransoms, those that do face significantly higher demands. The decision to pay involves substantial legal, ethical, and financial considerations that must be carefully weighed by executive and legal teams.

About the Speaker(s)

Diego Matos is the Latin American Incident Response Leader for IBM, where he is part of a global team specializing in incident response, crisis management, and proactive security services. With over 16 years of experience, Diego brings a unique perspective, having worked extensively in both defensive and offensive cybersecurity roles. His background includes serving as the EMEA head of penetration testing and red teaming for a UK-based company. Witnessing the devastating impact of the WannaCry attack on UK hospitals was a pivotal moment that influenced his shift towards defensive security. Diego's expertise covers the full spectrum of incident response, from technical analysis to crisis communication and strategic planning in the aftermath of major cyberattacks.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent war-story talk with a genuinely useful case study anchoring it — the $10 credential-to-$30M demand arc is clean and the accidental API key leak detail adds credibility. But the surrounding material is mostly well-packaged industry knowledge rather than new insight, and the threat landscape framing (RaaS, quadruple extortion, Conti, LockBit) has been rehashed at every mid-tier con for two years running.

Heather Calloway (CISO) — SOLID

A practitioner-grade walk through the extortion lifecycle with a real case study that grounds the narrative. Useful for IR teams and security managers, but it stops short of the governance and organizational accountability questions that would make it matter to executives and boards.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026