ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Managing cyber-extortion

Robert Boyce at Accenture describes a new model for understanding extortion groups

 

The landscape of cyber-extortion is becoming increasingly complex and dangerous. Recent reports indicate a significant rise in ransomware attacks, with new groups emerging. High-profile attacks, such as those on healthcare providers like Synnovis, have caused widespread disruption and highlighted the urgent need for effective strategies to combat these threats.

 

To assist organisations in deciding if and how they should interact with cyber criminals during an extortion attack, a new model has been developed by Accenture Cyber Intelligence (ACI) that assess the credibility and stability of ransomware and data extortion groups: Extortion Group Maturity Model (EGMM).

 

Increased complexity in the extortion ecosystem

Many extortion groups operate on a ransomware-as-a-service (RaaS) model, leasing or selling their malware to affiliates. Recently, two notorious RaaS groups, ALPHV-ng (a.k.a. BlackCat) and LockBit, faced law enforcement takedowns and accusations of defrauding their affiliates. This has led to speculation about the potential end of the RaaS model.

 

Recent events have increased the complexity of the extortion ecosystem, introducing new relationships between threat actors and a recruitment race among groups to hire malicious talent. 

 

These events have also introduced new extortion techniques targeting C-suites, an increased propensity for harassing victims, and a heightened focus on the theft and leaking of highly sensitive personally identifiable information, such as healthcare data.

 

Consequently, data extortion and ransomware are expected to remain major threats to enterprises throughout 2024 and 2025.

 

Extortion group maturity model

As mentioned, there is a new model that help to provide a snapshot of a group’s stability and predictability during a ransomware or data extortion event, and help organisations prime their situational awareness prior to an event and better understand their adversaries. 

 

The EGMM is an analytical tool that helps assess the credibility, stability, and anticipated behaviour of active ransomware and data extortion groups. When applied, the model can help decision-makers judge if and how they should interact with a malicious group.

 

The EGMM helps organisations assess a threat group’s predictability and stability based on 19 unique data points. The model then uses those data points to plot a group on a scatter graph along two axes: chaotic to stable, and predictable to unreliable. This approach effectively divides extortion groups into four categories—credible, reliable, volatile, and unreliable/unpredictable—each with individual risks and suggestions.

 

Figure 1. Key active ransomware and extortion groups on ACI’s EGMM


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543