Scenario library / Extortion

Data Extortion with a Leak Site Countdown: a tabletop exercise scenario

An actor publishes a sample of regulated customer records and sets a seven-day countdown. Nothing is encrypted and operations are unaffected.

75–90 min · Executive + comms + legal

Abstract graphic representing data extortion with a leak site countdown

What this is modelled on

Modelled on extortion campaigns that skip encryption entirely: data is stolen, a sample is published, a countdown starts, and the pressure is reputational rather than operational.

Why it matters

With no outage, the temptation is to treat it as a communications problem. Regulatory clocks, negotiation posture and customer trust all move faster than forensic certainty.

Exercise objectives

  • Test regulatory assessment and notification timing
  • Rehearse public messaging with unverified scope
  • Set a negotiation and engagement posture in advance
  • Confirm board reporting cadence during a countdown

Decision points tested

  • Public statement now or hold pending scoping
  • Whether to engage the actor at all, and through whom
  • Notification to regulators with incomplete facts
  • Support offering for affected individuals

Sample inject timeline

  1. T+0

    Sample posted

    A leak site names the organisation with 300 records visible.

  2. T+20

    Scope unclear

    Forensics cannot yet confirm the full dataset or the exfiltration route.

  3. T+40

    Media enquiry

    A trade publication requests comment within two hours.

  4. T+65

    Customer escalation

    Two major customers invoke contractual notification clauses.

What the after-action report should capture

  • Time to regulatory assessment decision
  • Message consistency across channels
  • Negotiation posture agreed and documented
  • Contractual obligations discovered late

Run this scenario with your team

Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.