Double extortion
Steal the data first, encrypt second, and charge for both: one price to decrypt, another not to publish. Increasingly the theft alone, with no encryption at all, because publication is the half that forces payment.
Why it matters to you
Backups answer encryption and answer nothing about publication. If the data left, the incident is a disclosure question from the first hour rather than a recovery one.
Where we meet it
The countdown and the sample appear on the leak site before most victims have finished scoping the incident, and what gets published is often narrower than what was claimed.
Connected terms
DLS / leak site
A ransomware group's "dedicated leak site": victim announcements, countdown timers and proof packs, published to convert embarrassment into payment.
Proof pack
The sample of stolen files a ransomware crew publishes or shows a victim to prove the breach is real: file trees, contracts, ID scans, released ahead of the full dump.
Ransomware-as-a-Service (RaaS)
Ransomware sold as a product: the operator builds the encryptor, the panel and the leak site, affiliates bring the victims, and the ransom splits between them. The reason a small crew can run an enterprise-grade extortion campaign.
Where this term stops being vocabulary
Dragnet is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.