IronSights

Data theft extortion · Australia · answered 24/7

They took your data and encrypted nothing.

No locked files, no ransom note on the server, just a message saying they have your data and a deadline. There is nothing to restore, so the response is entirely about what they actually took, how they got in, and what you now have to report.

Don't reply to them yet. The first useful move is evidence: preserve the message, pull the logs before they age out, and find out whether the claim holds. Australian business incident response, any hour.

This service is for businesses and organisations. If your personal accounts have been compromised or someone is threatening you, report it via ReportCyber and contact IDCARE.

Why this is not a ransomware job

  • Nothing to decryptNo encryption means no recovery step. Backups do not help, and neither does ScanCrypt: the files were never touched.
  • The question is scopeWhat was actually taken, from where, by which account. That is a log and forensics problem, not a restore problem.
  • The clock is regulatoryYour deadline comes from the Notifiable Data Breaches assessment and, if anyone pays, the Cyber Security Act 2024, not from the attacker.

Files locked as well? That is a different job: ransomware recovery.

Just received the message?

Do this first. Logs expire faster than deadlines.

Do

  • Preserve the evidence: the extortion email or portal message, any sample files they sent, and the headers. Screenshot everything before anything expires.
  • Work out what account or system they came through, and lock it: rotate credentials, revoke active sessions, and check for mail rules or API tokens they left behind.
  • Pull the logs while they still exist. Sign-in logs, admin activity, and SaaS audit logs typically have short retention, and they are how you establish what was actually taken.
  • Start the Notifiable Data Breaches clock deliberately. Note the time you first suspected, because the 30-day assessment runs from there.

Don't

  • Don't reply to the attacker, or open a negotiation, before you know what they actually hold.
  • Don't assume the claim is true, and don't assume it is false. Both are decisions that need evidence.
  • Don't delete the mailbox, the account or the logs to "contain" it. That destroys the evidence you need for the assessment.
  • Don't tell customers what was taken until you can support it. A correction later is worse than a day's delay now.

Verify before you react

The ransom note is a sales pitch, not a finding.

Extortion crews overstate what they hold, because scope is leverage. Occasionally they understate it, because a small sample is enough to start the conversation. Neither the claim nor your relief is evidence. Four things decide what you are actually dealing with:

Does the sample prove anything?

Extortion crews send a sample to prove possession. Check whether it is genuinely yours, how current it is, and where it could have come from. Old data from a system you decommissioned is a very different problem from a live export of your customer database.

What do the logs actually show?

Volume of records read, API calls, bulk exports, unusual download sizes, the account and IP behind them. This is what turns a claim into a finding, and it is what the OAIC assessment and your insurer will both want.

How did they get in, and are they still there?

Data theft usually starts with a valid credential, a token, or a connected third-party app rather than malware. Until you know the route, you cannot say it is closed.

Is the scope what they say it is?

Attackers routinely overstate. Inflated claims are a negotiating tactic, and a bluff is common. Equally, a modest-looking sample sometimes sits on top of a much larger export. The evidence decides, not the note.

The payment question

What paying does, and does not, buy.

With ransomware there is at least a mechanical question: does the decryptor work. With data theft there is no mechanism at all. You are paying for a deletion you cannot verify, from people whose business model is not keeping promises.

We do not negotiate with attackers and we do not advise on whether to pay. That decision sits with your board and your lawyers. What we do is make sure it is made against evidence rather than the note, and that whatever you choose, the obligations are met properly.

Four realities to weigh

  • You are buying a promise from the people who just stole from you, and there is no way to verify deletion. Copies may already sit with affiliates or buyers.
  • Payment does not remove your obligations. If personal information was accessed, the Notifiable Data Breaches assessment still applies, and paying does not undo the access.
  • In Australia, a ransomware or cyber extortion payment by a business with annual turnover of $3 million or more must be reported to the Department of Home Affairs within 72 hours under the Cyber Security Act 2024.
  • Sanctions exposure is real. Paying a listed entity or someone acting for one carries legal risk that sits with you, which is why the payment decision belongs with your lawyers, not with the responder.

Detail on both obligations: the NDB scheme and the Cyber Security Act 2024. General guidance, not legal advice.

If files were locked too

Most ransomware crews now steal first and encrypt second.

Double extortion means you can have both problems at once: locked files and a publication threat. If your files carry a new extension and there is a note on the server, start with the strain, because that decides what is recoverable.

Want to see which groups are currently hitting Australian organisations, and whether they encrypt or only steal? Our Australian data breach tracker is a running, human-reviewed list.

Common questions

Extortion without encryption, answered.

Mid-incident? Call 1300 004 766. Answered 24/7.

  1. Attackers say they have our data but nothing is encrypted. What is this?

    Extortion without encryption, sometimes called exfiltration-only or data-theft extortion. The attacker steals data and threatens to publish or sell it, skipping the encryption step entirely. It has become the preferred model for several groups because it is faster, quieter, and avoids the operational noise of locking systems. There is nothing to restore, so the whole response is about verifying what was taken, closing the route in, and meeting your obligations.

  2. Who are ShinyHunters?

    A long-running data-theft and extortion crew, associated with large-scale breaches of cloud and SaaS platforms rather than file-encrypting ransomware. Australian organisations have been named in their campaigns, including cases recorded in our own Australian data breach tracker. Because they steal rather than encrypt, a ShinyHunters incident is a data-theft extortion response, not a decryption or file-recovery job.

  3. Should we pay to stop them publishing?

    Understand what payment does and does not buy before anyone decides. It buys a promise from the people who just took your data, with no way to verify deletion and no effect on copies already shared. It does not remove your obligations: if personal information was accessed, the assessment and any notification still apply. And in Australia a payment by a business turning over $3 million or more triggers a separate report to Home Affairs within 72 hours under the Cyber Security Act 2024. The decision belongs with your board and your lawyers; our job is to make sure it rests on evidence.

  4. How do we know whether the claim is real?

    The sample and the logs. Check whether the sample is genuinely yours and how current it is, then match it against sign-in, admin and audit logs for bulk reads, exports and unusual volumes. Attackers overstate scope routinely, and occasionally understate it. Pull the logs early: SaaS audit retention is often short, and the evidence you need for the OAIC assessment expires quietly.

  5. Do we have to notify if the data was only stolen, not encrypted?

    Very possibly, and encryption has nothing to do with it. The Notifiable Data Breaches scheme turns on unauthorised access to or disclosure of personal information that is likely to result in serious harm. Theft is unauthorised access by definition, so an exfiltration-only incident is squarely in scope. Our guide to the NDB scheme covers the assessment, the 30-day limit and what goes in the statement.

  6. Our data was taken from a SaaS platform, not our own servers. Is that different?

    The response is, the obligation is not. If you are the entity that holds the personal information, it is your breach to assess even when the data sat in someone else's platform. Practically it means the investigation runs through that platform's audit logs and connected-app permissions rather than your endpoints, and it means checking what other integrations share the same token or account.

  7. What does IronSights do on an extortion-only incident?

    Verify the claim against the evidence, find and close the route in, establish what was actually accessed, and give you a report structured for the OAIC assessment, your insurer and your board. We do not negotiate with attackers, and we do not advise on whether to pay. We make sure the decision, whoever makes it, is based on what the logs show rather than what the note claims.

The IronSights incident response team in Australia

Answered 24/7

Find out what they actually have.

Before you answer them, before you tell customers, and before anyone talks about paying. We verify the claim against your logs and give you a report your board, your insurer and the OAIC can all work from.