← All threats
CRITICAL
Ransomware Extortion Post
Victim posted on a ransomware leak site after refusing or delaying ransom payment. Indicates an initial-access + privilege-escalation + data-exfiltration chain succeeded — full ransomware playbook applies for prevention.
Victim posted on a ransomware leak site after refusing or delaying ransom payment. Indicates an initial-access + privilege-escalation + data-exfiltration chain succeeded — full ransomware playbook applies for prevention.
MITRE ATT&CK
Tactics, Techniques & Procedures
TA0006 Credential Access
tactic
TA0040 Impact
tactic
TA0001 Initial Access
tactic
TA0008 Lateral Movement
tactic
Defensive mapping
Mapped controls
The audit will verify each of these controls is in place and effective.
| Control | Confidence | Why it matters |
|---|---|---|
| MFA for remote access suggested | 75% | Recommended control for ransomware |
| Immutable backups suggested | 75% | Recommended control for ransomware |
| EDR on every endpoint suggested | 75% | Recommended control for ransomware |
| Network segmentation between user and server tiers suggested | 75% | Recommended control for ransomware |
| Privileged access management (PAM) suggested | 75% | Recommended control for ransomware |
| Incident response playbook suggested | 75% | Recommended control for ransomware |