Key Takeaways

  • Attackers increasingly steal sensitive data without encrypting business systems
  • Leak sites and publication threats can create leverage even when recovery tools work
  • Security programs need stronger controls around identities, cloud data, and exfiltration

The familiar ransomware scenario starts with locked systems, a ransom note, and a scramble to restore operations. That picture is becoming incomplete. The U.S. Cybersecurity and Infrastructure Security Agency now explicitly distinguishes ransomware from broader data extortion, reflecting how criminal groups can demand payment without deploying file-encrypting malware at all.

Instead, intruders steal sensitive information and threaten to publish it, sell it, or notify customers and regulators. The pressure shifts from operational recovery to confidentiality and reputational exposure. Backups may restore a server, but they cannot retrieve files that have already left the network. That changes both the attacker's economics and the victim's response options.

The numbers illustrate the shift. ENISA reported that ransomware represented 40% of financially motivated cyber events it analyzed in 2025, while data breaches accounted for 31%. Google Threat Intelligence found that data theft accompanied 77% of observed ransomware intrusions in 2025, up from 57% in 2024. Data-only extortion exceeded 15% of financially motivated incidents.

Encryption adds technical complexity and risk for attackers. Malware can malfunction, trigger endpoint defenses, or reveal an intrusion before valuable information has been removed. Data theft can be quieter. Once criminals obtain credentials and locate useful cloud repositories, collaboration systems, email archives, or internal databases, they may already have enough leverage to demand payment.

Leak sites amplify that leverage. Check Point Research counted 2,139 victims published by double-extortion groups in Q2 2026, 33% more than in Q2 2025. The number of active groups also increased from 71 to 93. Operations such as Qilin, The Gentlemen, and Clop use stolen credentials, publication deadlines, and public victim listings to intensify pressure, including in cases where encryption is limited.

Encryption has not disappeared, of course. Sophos found that 56% of 2,158 organizations affected by ransomware experienced successful data encryption, while average recovery costs reached $1.7 million. The distinction is that encryption is becoming one option within a broader extortion playbook, rather than the defining feature of every incident.

That said, data-only extortion creates an awkward management question: what does recovery mean when systems are still running? Incident teams may need to investigate exactly what left the environment, assess legal notification requirements, communicate with customers, and monitor potential publication. Business leaders can face consequential decisions before forensic teams have established the full scope of theft.

Industrial organizations face an especially difficult version of this problem. NCC Group recorded 1,073 ransomware victims in August 2026, with industrial organizations accounting for 31% of reported incidents. A manufacturer may keep production online while still losing engineering files, supplier records, employee information, or operational documentation. Avoiding downtime does not make the event minor.

Defenses therefore need to look beyond malware execution. Identity monitoring, phishing-resistant authentication, restricted service accounts, cloud-storage logging, and controls on bulk downloads can help expose the activity that precedes extortion. Organizations can also map detections to MITRE ATT&CK, including T1486 for data encrypted for impact and T1530 for data taken from cloud storage objects.

Response exercises should test both tracks. One scenario can involve encrypted infrastructure; another can assume that attackers stole regulated or commercially sensitive information without disrupting systems. Who decides whether customer notification is warranted? How quickly can teams determine which cloud objects were accessed? Those questions are increasingly central because the ransom leverage may now be the information itself, not the availability of the machines holding it.