Key Takeaways

  • Attackers increasingly steal information and demand payment without encrypting systems or leaving a traditional ransom note.
  • Backups remain useful for operational recovery, but they cannot prevent criminals from exposing data that has already been copied.
  • Smaller businesses should expand ransomware defenses to cover identity compromise, unusual access, and outbound data movement.

The familiar ransomware warning signs are becoming less reliable. Threat intelligence from 2026 points to an accelerating shift toward attacks in which criminals quietly copy sensitive information, leave systems running, and contact the victim later with a threat to publish the stolen material.

This approach removes several noisy stages of a conventional ransomware attack. Encryption can trigger endpoint controls, disrupt business operations, and draw immediate attention from security teams. Data theft may be harder to notice, particularly when attackers use a legitimate account, an approved file-transfer product, or ordinary cloud storage traffic to move information.

The National Cyber Security Centre notes that some criminal groups now conduct data theft and extortion without encrypting systems. That changes what a ransomware incident can look like. There may be no locked files, red warning screen, or ransom note sitting on a server. The first visible signal could arrive weeks later as an email containing sample records and a payment deadline.

By the time an extortion demand appears, an attacker may have had enough time to examine shared drives, identify high-value records, and determine which information would create the most pressure if released. Customer details, contracts, payroll files, financial documents, and employee records can all become leverage.

A successful system restore does not retrieve data confidentiality. The Cybersecurity and Infrastructure Security Agency recommends offline, encrypted backups as part of ransomware preparation, and that remains sound guidance for recovering from destructive attacks. However, if criminals have already copied the files, restoring clean systems does nothing to erase the attacker’s copy.

The 3-2-1-1-0 backup rule can still strengthen resilience. It generally calls for three copies of data, on two media types, with one copy off-site, one offline or immutable copy, and zero unverified backup errors. Yet businesses should treat that model as one layer of defense rather than a complete answer to modern extortion.

Recent campaigns illustrate the distinction. The 2025 Cl0p activity involving Cleo file-transfer products was described as pure data theft, with demands linked to the threatened publication of stolen information rather than system decryption. For a victim, operations might initially appear normal even while the legal, regulatory, and reputational exposure is growing.

When systems remain unencrypted, security teams must monitor outbound data flows. Large transfers, unusual archive creation, access to many folders in a short period, and connections to unfamiliar storage services can signal staging or exfiltration. Smaller transfers spread across several days may be more difficult to distinguish from normal work, which makes behavioral baselines useful.

Identity monitoring also moves closer to the center of ransomware defense. Logins from unexpected locations, unusual privilege changes, repeated multifactor authentication prompts, and service accounts accessing new repositories can indicate that an attacker is operating through trusted credentials. Strong authentication can help, but organizations also need controls for session theft, excessive permissions, and dormant accounts.

Incident planning needs a similar update. The National Institute of Standards and Technology treats incident response as an organization-wide risk activity, not simply a technical cleanup exercise. For encryptionless extortion, response teams may need to preserve logs, determine exactly what left the environment, assess notification obligations, and prepare communications while the attacker is applying pressure.

Small and mid-sized businesses face a particularly awkward challenge. They may have limited monitoring coverage, yet they often hold information belonging to larger customers and partners. File-transfer systems, managed service accounts, and shared cloud repositories can create concentrated points of exposure.

Backups and patch management still matter, but the absence of encrypted files no longer offers much reassurance. In the emerging no-note extortion model, the central question shifts from whether a business can restore its systems to whether it can detect data leaving the network before extortion begins.