> It's just a matter of time before it goes online, ransom or not
Sometimes the groups want a good reputation for not disclosing stuff if the ransom was paid. They earn that reputation over time.
Sometimes the groups want a good reputation for not disclosing stuff if the ransom was paid. They earn that reputation over time.
One should assume at this point that it's not a question of whether the files will be leaked but when.
Often the data isn't exfiltrated at all, only encrypted in place, which should be relatively easy to prove.
If they delete the files, it's not out of decency. It's out of a desire to build a reputation of post-ransom trustworthiness so others will pay in the future.
j/k, of course.