Leakware, also called doxware, is extortion malware or an attack tactic in which criminals steal sensitive data and threaten to publish it unless a demand is met. The pressure comes from possible disclosure rather than only from loss of access to encrypted files.
Leakware and ransomware
Traditional ransomware encrypts data to interrupt access. Leakware focuses on confidentiality and may not encrypt anything. Many modern attacks combine both methods: criminals exfiltrate files, encrypt systems, and threaten a public leak. This is commonly called double extortion.
A payment does not prove that stolen copies were deleted, and it does not prevent later demands or publication.
How an attack develops
- Attackers gain access through phishing, stolen credentials, an exposed remote service, or an unpatched application.
- They locate file shares, cloud storage, mailboxes, backups, and other valuable records.
- Data is collected and transferred to infrastructure controlled by the attackers.
- The victim receives a demand containing samples or other evidence of theft.
Warning signs
- Large or unusual outbound transfers, especially from file servers.
- Unexpected archive, synchronization, or command-line tools.
- New sign-ins, mailbox rules, cloud tokens, or administrator accounts.
- An extortion message linking to a sample or a countdown page.
What to do after a leakware claim
- Activate the incident-response plan and isolate affected systems without destroying logs.
- Reset exposed credentials and revoke sessions from a known-clean device.
- Preserve the demand, email headers, logs, and samples. Do not download files from a leak site onto a production device.
- Determine what data left the environment, which people are affected, and whether persistence remains.
- Involve legal counsel, the insurer, law enforcement, and regulators as required for the organization and jurisdiction.
- Communicate verified facts to affected people; do not repeat the attacker's unverified claims.
Prevention centers on phishing-resistant MFA, least privilege, rapid patching of public services, egress monitoring, segmented backups, and a current inventory of sensitive data. General recovery guidance is available in Ransomware.