← All advisories
KSG-ADV-2026-005 Severity: Critical Audience: All businesses

Pay or We Publish: What Small Businesses Need to Know About Data Theft and Extortion

Executive Summary

Kariba Security Group is issuing this advisory at Critical severity because the threat it describes has reached small businesses — a category that was previously considered too low-value to be worth the effort of sophisticated data theft and extortion operations.

That calculus has changed. AI has made data theft and extortion attacks faster, cheaper, and accessible to individual operators who previously lacked the skills and resources to conduct them. Small businesses are now viable targets.

Anthropic's September 2026 threat intelligence report documents multiple clusters of financially motivated cybercrime activity conducted by operators suspected to be affiliates of the ShinyHunters collective (tracked as GTG-50014), a group known for large-scale data theft operations followed by pay-or-leak extortion demands. Documented victims include a technology provider (over a terabyte of data exfiltrated, including hundreds of thousands of national identifiers and millions of payment card records), an airline (systems holding tens of millions of passenger records), and an energy company (where the operators claimed they could remotely control the charging current of customers' home EV chargers).

The tactics used in these large-scale attacks are the same tactics now being applied to smaller targets.

The Complete Attack Lifecycle

Phase 1: Initial access

Attackers gain entry to your systems through one of several common vectors:

Phase 2: Data discovery and exfiltration

Once inside, attackers use AI-assisted tools to rapidly identify and extract the most valuable data: customer records, financial information, employee data, intellectual property, and internal communications. AI has dramatically accelerated this phase — what previously took weeks now takes hours.

Phase 3: The demand

You receive a message. It typically includes a sample of the stolen data as proof, a demand for payment (usually in cryptocurrency), a deadline, and a threat to publish the data publicly or sell it if you don't pay. The message is designed to create panic and pressure you into paying before you've had time to assess your options.

Phase 4: The lever

If you have customer data, the attacker's real leverage isn't against you — it's against your customers. The threat of notifying your customers that their data was stolen, or publishing their information publicly, puts your customer relationships and your PIPEDA breach notification obligations in direct conflict with the attacker's demands.

Should You Pay?

Kariba Security Group does not recommend paying extortion demands, for several reasons:

However, this is a business and legal decision that you should make with qualified legal counsel, not under time pressure created by the attacker. The deadline in an extortion demand is a tactic, not a constraint — engaging legal counsel immediately is always the right first step.

If You Receive an Extortion Demand

  1. Do not respond to the attacker immediately. Engaging without counsel often escalates the demand and gives the attacker more information about your posture.
  2. Contact a lawyer immediately — specifically one with data breach experience. They will guide your response strategy and help you understand your PIPEDA notification obligations.
  3. Preserve all communications from the attacker, including the original message, any samples they provided, and all subsequent contact.
  4. Report to the Canadian Centre for Cyber Security — current reporting guidance is published at cyber.gc.ca.
  5. Investigate the breach to understand what was actually taken, when, and how. This determines your notification obligations and your response options.
  6. Contact your cyber insurance provider if you have coverage — extortion events are often covered, and your insurer may have incident response resources available to you.

Prevention: Reducing Your Exposure

Data minimisation

You can't lose data you don't have. Regularly review what customer data you collect, how long you retain it, and whether you actually need it. Data that isn't stored can't be stolen.

Access controls

Limit who in your organisation can access sensitive customer data, and ensure that access is logged. A breach that exposes only the data accessible to a compromised account is significantly less severe than one that exposes everything.

Multi-factor authentication

Enable MFA on every system that holds sensitive data. Stolen passwords are the most common initial access vector — MFA makes them significantly less useful to attackers.

Software updates

Keep all software — operating systems, plugins, SaaS platforms, and any software your business runs — updated. Many successful breaches exploit known vulnerabilities that patches had already addressed.

Cyber insurance

Consider a cyber liability policy if you don't have one. For small businesses handling customer data, the cost of a policy is often significantly lower than the cost of a single incident response.

Incident response plan

Identify your incident response contacts before you need them. A lawyer who handles data breach matters, a technology professional who can investigate and contain a breach, and your insurance provider are the minimum. Knowing who to call at 11pm when you discover a breach is worth more than any technical control.

Prevention Checklist

  • Enable MFA on all systems holding customer or financial data
  • Review and minimise what customer data you collect and retain
  • Restrict and log access to sensitive data
  • Keep all software and plugins updated
  • Consider cyber liability insurance
  • Identify your incident response contacts before you need them

If You Receive a Demand

  • Do not respond to the attacker immediately
  • Contact a data breach lawyer first
  • Preserve all attacker communications
  • Report to the Canadian Centre for Cyber Security (cyber.gc.ca)
  • Contact your cyber insurance provider
  • Investigate the breach to understand your notification obligations