Why are Ransomware Hackers giving victims only 7 days to pay the Ransom | #ransomware | #cybercrime


Ransomware attacks have evolved significantly over the years. What initially began as a form of malware designed primarily to encrypt files and demand payment for their recovery has now developed into a much more aggressive cyber extortion model. Cyber-criminals are increasingly combining data theft, encryption, and additional extortion tactics to put greater pressure on victims.

One of the latest tactics attracting attention is the increasingly short ransom deadline. In several recent incidents, ransomware groups have given victims as little as 172 hours, or seven days, to pay the demanded ransom. If the victim refuses to pay or fails to respond within the specified period, attackers threaten to publish the stolen information on the dark web, sell it to interested parties, or release it through underground cybercrime forums.

The seven-day deadline could be more than just an intimidation tactic. Cybersecurity experts believe that ransomware groups may be deliberately keeping the ransom window short to reduce the possibility of law enforcement identifying and tracking them.

The latest example involves the Gentleman ransomware group, which reportedly gave Glassdoor approximately one week to respond to its demands concerning allegedly stolen information. According to the threat posted by the attackers, once the 172-hour countdown expires, the data could either be published on an underground forum or offered for sale to other parties.

Glassdoor, a platform widely used by job seekers and professionals to search for employment opportunities and research companies, has yet to publicly confirm the alleged breach. However, a screenshot circulating on Telegram claims that the attackers obtained various categories of information. This allegedly includes corporate data, employee information, professional details associated with job postings, and contact information.

If confirmed, such an incident would demonstrate why modern ransomware attacks are no longer limited to encrypted files. Attackers now understand that sensitive information itself can become a valuable bargaining tool.

This evolution has resulted in what is commonly described as double or triple extortion. In a double-extortion attack, criminals first steal sensitive data and then encrypt the victim’s systems. They subsequently threaten to leak the stolen information if the ransom is not paid. Triple extortion operations can add further pressure, such as targeting customers, partners, employees, or other associated organizations.

So, why are ransomware gangs increasingly choosing a seven-day ransom deadline?

One possible explanation is operational security. A longer deadline gives cybersecurity teams, incident responders, and law enforcement agencies more time to investigate the attack, identify infrastructure used by the criminals, trace cryptocurrency transactions, and potentially disrupt the attackers’ operations.

A shorter deadline, on the other hand, creates urgency. Victims have less time to investigate the breach, negotiate with attackers, assess the stolen information, or coordinate their response with law enforcement and cybersecurity specialists. The countdown also creates psychological pressure, encouraging organizations to make rapid decisions.

However, a short ransom deadline does not necessarily mean that attackers will immediately delete or publish the data when the deadline expires. In many cases, ransomware groups use deadlines as leverage and may extend negotiations if they believe a victim is capable of paying.

The growing use of seven-day ransomware deadlines therefore appears to reflect a combination of psychological pressure and operational security. As ransomware groups become more organized, their attacks are increasingly designed not just to disrupt businesses but also to exploit the fear of sensitive data being exposed.

For organizations, the trend reinforces the importance of maintaining reliable backups, implementing strong access controls, monitoring unusual network activity, protecting sensitive information, and having a well-defined ransomware incident response plan before an attack occurs.

Join our LinkedIn group Information Security Community!



Click Here For The Original Source.

——————————————————–

..........

.

.