Talos Incident Response has been engaged with a couple of these attacks, which involved the use of targeted ransomware. The concept is simple: Get access to a corporate network, gain access to many systems, encrypt the data on a large chunk of them, ask for a large lump sum payment to regain access to those systems. More recently, attackers have taken the extra step of exfiltrating data, which they claim they will release to the public unless payment is received, a form of doxxing.”]
Source: https://blog.talosintelligence.com/2019/12/IR-Lessons-Maze.html

