Maze ransomware ring has dumped stolen data from about 25 companies online and has threatened full dumps as leverage against victims who don't pay the ransom
Maze operators “gift” Pensacola by removing data dump, but others not so lucky. — The Maze ransomware ring has taken extortion …
Context & Ripple Effects
Maze is the ring that turned ransomware into a two-stage extortion business: it steals data before encrypting so that even victims with clean backups face publication, a shift Ars Technica documented days after this story in its coverage of the steal-before-encrypt tactic. The Pensacola 'gift' — deleting one city's dumped dataset — is the same playbook run in reverse, showing the operators treat publication itself as a negotiable asset.
The arc that follows confirms the model stuck: Maze went on to hit business-services firm Conduent in a ten-hour intrusion later that year, and by early 2021 Chainalysis counted at least $350M in annual ransom payments with Maze already defunct — its tactics outliving the brand.
First-order effects
- The roughly 25 listed companies face exposure of stolen data whether or not they restore from backups, since Maze's threat targets the data copy, not the encrypted systems.
- Pensacola gets its dataset pulled from the dump site, a selective act of mercy that functions as advertising for paying up rather than a policy change.
Second-order effects
- Rival crews read the leak-site model as proven revenue: NetWalker's operators reach Ryuk-league earnings within months, and LockBit is tracked as climbing toward parity with Maze-class packages.
- Victims' calculus changes — backup-and-restore stops being an exit strategy, pushing buyers toward prevention and negotiation services instead of recovery alone.
Third-order effects
- If the pattern holds, ransomware consolidates around extortion economics rather than encryption tooling: the $350M-plus annual take recorded for 2020 reflects payment under threat of disclosure, a structure that persists across brands even after Maze itself shuts down.
- Municipalities and enterprises become standing targets whose liability is measured in leaked records, making pre-breach data minimization a board-level requirement rather than an IT detail.
The trend: Ransomware is evolving from encrypt-for-ransom into publish-or-pay extortion, with each crew's leak site — not its crypto locker — becoming the core weapon.