Key Takeaways
- Tower’s appearance on a ransomware leak site is an unverified extortion claim, not confirmation of a breach.
- Investigators need to check identity, endpoint, network and data-egress evidence before drawing conclusions.
- The episode highlights how data theft and publication threats increasingly occur without file encryption.
Tower has been named on a ransomware leak site, creating a potentially serious security issue for the insurer while leaving a central question unresolved: did attackers actually gain access to its systems or data?
A leak-site post alone does not answer that. Cybercriminal groups use these sites to pressure victims, attract attention and impose deadlines, but their claims can be exaggerated, recycled or based on data obtained from another source. Until Tower validates the post against its own technical evidence, the listing should be treated as an unverified extortion claim rather than proof of compromise.
That distinction matters. A premature public assertion could mislead customers, regulators and business partners, while a slow or overly narrow investigation could allow evidence to disappear. Tower’s immediate task is to establish whether there are corresponding signs of unauthorized identity access, endpoint activity, lateral movement, encryption or unusual data staging and egress.
Ransomware no longer reliably announces itself by locking files and displaying a payment note. Attackers may steal information and move straight to extortion, particularly if encryption would create too much operational noise or trigger an earlier response.
The broader figures underline that shift. Industry data indicates that 77% of Mandiant’s ransomware intrusions in 2025 involved suspected data theft, up from 57% in 2024. Ransomware-related intrusions represented 13% of Mandiant’s incident-response investigations, while extortion appeared in 23% of cases. In other words, the extortion problem is wider than the subset of cases involving conventional ransomware deployment.
Enterprise survey findings point in a similar direction. According to Sophos data from 2025, 49% of organizations affected by ransomware experienced data encryption, while 47% stopped the attack before encryption. That leaves plenty of room for theft, attempted theft or threats based on partial access.
The European Union Agency for Cybersecurity, or ENISA, reported that ransomware deployment accounted for 40% of financially motivated cyber events it analyzed in 2025, alongside data theft and extortion activity. A Security Affairs review of the ENISA Threat Landscape 2025 also illustrates why incident classification has become less tidy. Encryption, theft and coercion can occur together, separately or in stages.
So what should Tower look for first? Identity logs may show suspicious authentication, token abuse, unusual administrative actions or access from unexpected infrastructure. Endpoint telemetry could reveal credential dumping, discovery commands, remote-management tools or attempts to disable security controls. Network records may expose lateral movement, connections to unfamiliar external services or large outbound transfers.
Investigators also need to preserve evidence before rebuilding systems or rotating infrastructure too aggressively. NIST SP 800-61 Rev. 2 provides an established model for incident handling, while the NIST Cybersecurity Framework 2.0 places the work across Govern, Detect, Respond and Recover activities. The practical point is simple: containment and evidence preservation need to proceed together.
Threat-group branding should receive similar caution. Qilin was especially prominent on leak sites during 2025, while Akira/REDBIKE and Gunra have also used publication threats. The US Cybersecurity and Infrastructure Security Agency’s Gunra ransomware advisory describes the group’s use of a dedicated leak site to threaten release of allegedly stolen information. Even so, a criminal group’s logo or victim entry is not independent verification.
The incident also lands amid growing concern about operational resilience across financial services. The RBNZ director of financial stability has stated, "Cyber risks are growing," in the context of scenarios including a data breach, cloud services outage and ransomware attack. For Tower, that makes the response broader than malware analysis. Legal, privacy, communications, vendor management and executive governance teams may all need to work from the same verified timeline.
For now, the defensible position is measured: investigate quickly, preserve evidence and communicate confirmed facts. If Tower finds no supporting telemetry, the leak-site entry may amount to bluff or mistaken attribution. If evidence of access or exfiltration emerges, the focus can shift to containment, notification and recovery. Either way, the listing is a trigger for validation, not a verdict.
⬇️