They also threaten to leak your data if you don't pay. They know a lot of orgs can restore the data and won't need it decrypted. There's no real defense against this (other than good security practices).
You can never prove that they won't leak your data after paying though. I'm not a CEO/CTO and haven't had to make these decisions, but from my perspective it's an empty promise that by paying them they will actually keep their word and not leak your data.
If they do leak your data after you pay, then it'll ruin their reputation and make it less likely for other victims to pay in the future.
Which is why we should do „fake“ ransomware attacks where a company „pays“ and gets „betrayed“ when the attacker still leaks some „super important“ data after the payment.
What are the hackers gonna do? Sue you?
I mean, that's a whole nother kettle of fish. At that point they have you in the hook for indefinite blackmail, because after you pay they still have the days. Is that actually common, though? I think most of these ransomware cases are simply pay-to-decrypt.
Almost all of the ransomware gangs now also exfil data and use that as additional leverage.
yes, double extortions are getting common because people rely on backups