Scenario library / Extortion
Data Extortion with a Leak Site Countdown: a tabletop exercise scenario
An actor publishes a sample of regulated customer records and sets a seven-day countdown. Nothing is encrypted and operations are unaffected.
75–90 min · Executive + comms + legal

What this is modelled on
Modelled on extortion campaigns that skip encryption entirely: data is stolen, a sample is published, a countdown starts, and the pressure is reputational rather than operational.
Why it matters
With no outage, the temptation is to treat it as a communications problem. Regulatory clocks, negotiation posture and customer trust all move faster than forensic certainty.
Exercise objectives
- Test regulatory assessment and notification timing
- Rehearse public messaging with unverified scope
- Set a negotiation and engagement posture in advance
- Confirm board reporting cadence during a countdown
Decision points tested
- Public statement now or hold pending scoping
- Whether to engage the actor at all, and through whom
- Notification to regulators with incomplete facts
- Support offering for affected individuals
Sample inject timeline
- T+0
Sample posted
A leak site names the organisation with 300 records visible.
- T+20
Scope unclear
Forensics cannot yet confirm the full dataset or the exfiltration route.
- T+40
Media enquiry
A trade publication requests comment within two hours.
- T+65
Customer escalation
Two major customers invoke contractual notification clauses.
What the after-action report should capture
- Time to regulatory assessment decision
- Message consistency across channels
- Negotiation posture agreed and documented
- Contractual obligations discovered late
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
