Also known as: cyberextortionist definition · cyber extortion coverage · ransomware extortion
Cyber extortion is a threat to lock, steal, or expose your data or systems unless you pay a ransom, and a cyberextortionist is the attacker making that demand.
Cyber extortion occurs when an attacker threatens to damage, encrypt, disrupt, or leak your systems or data unless you pay a demand, usually delivered through ransomware or a threat to publish stolen files. The cyberextortionist is the person or group behind that demand. Most cyber insurance policies include cyber extortion coverage, which can reimburse the ransom payment where paying is legal, along with the professional negotiation, forensics, and recovery costs that follow. For a tech startup, this is one of the most common and expensive claim scenarios, so how a carrier responds matters as much as the limit.
A cyberextortionist is the attacker who threatens to lock, steal, disrupt, or expose your systems or data unless you pay a ransom. They typically operate through ransomware that encrypts your files or through the threat of publishing data they have already stolen.
Most cyber policies include a cyber extortion insuring agreement that can cover the ransom payment where paying is lawful, plus the costs of a professional negotiator, forensic investigation, and system restoration. Coverage terms, sublimits, and payment conditions vary, so it is important to read the specific policy.
That decision should never be made alone. Notify your carrier immediately so their incident-response and negotiation team can engage, because paying certain groups can violate sanctions law and paying does not guarantee recovery. The response team helps you weigh the legal, financial, and technical options.
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.
Last updated: July 2026.