/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Maze ransomware ring has dumped stolen data from about 25 companies online and has threatened full dumps as leverage against victims who don't pay the ransom

Maze operators “gift” Pensacola by removing data dump, but others not so lucky.  —  The Maze ransomware ring has taken extortion …

Ars Technica Sean Gallagher

Context & Ripple Effects

Maze is the ring that turned ransomware into a two-stage extortion business: it steals data before encrypting so that even victims with clean backups face publication, a shift Ars Technica documented days after this story in its coverage of the steal-before-encrypt tactic. The Pensacola 'gift' — deleting one city's dumped dataset — is the same playbook run in reverse, showing the operators treat publication itself as a negotiable asset.

The arc that follows confirms the model stuck: Maze went on to hit business-services firm Conduent in a ten-hour intrusion later that year, and by early 2021 Chainalysis counted at least $350M in annual ransom payments with Maze already defunct — its tactics outliving the brand.

First-order effects

  • The roughly 25 listed companies face exposure of stolen data whether or not they restore from backups, since Maze's threat targets the data copy, not the encrypted systems.
  • Pensacola gets its dataset pulled from the dump site, a selective act of mercy that functions as advertising for paying up rather than a policy change.

Second-order effects

  • Rival crews read the leak-site model as proven revenue: NetWalker's operators reach Ryuk-league earnings within months, and LockBit is tracked as climbing toward parity with Maze-class packages.
  • Victims' calculus changes — backup-and-restore stops being an exit strategy, pushing buyers toward prevention and negotiation services instead of recovery alone.

Third-order effects

  • If the pattern holds, ransomware consolidates around extortion economics rather than encryption tooling: the $350M-plus annual take recorded for 2020 reflects payment under threat of disclosure, a structure that persists across brands even after Maze itself shuts down.
  • Municipalities and enterprises become standing targets whose liability is measured in leaked records, making pre-breach data minimization a board-level requirement rather than an IT detail.

The trend: Ransomware is evolving from encrypt-for-ransom into publish-or-pay extortion, with each crew's leak site — not its crypto locker — becoming the core weapon.

Discussion

  • @acronis @acronis on x
    📈 It's not just steeper ransoms, other factors contributing to the rising cost of ransomware include hardware replacement and repair costs, lost revenues, and damage to the victim's brand. 🛡️ Get #CyberFit with Acronis | via @Forbes https://www.forbes.com/...
  • @emsisoft @emsisoft on x
    “About 25 other victims are listed on Maze's site, with smaller “proof” data sets posted that include customer information.” - Via @thepacketrat for @arstechnica https://arstechnica.com/...