AUTO-UPDATED

Why pure extortion is replacing traditional ransomware

Ransomware groups are shifting away from system encryption in 2026, favoring quiet data theft and extortion to bypass security defenses and monetize stolen information through secondary criminal marketplaces.

Key Points

  • Ransom payment rates have dropped significantly, falling from 76% in 2019 to just 28% in 2026.
  • Attackers are increasingly using "extortion-only" tactics, prioritizing the exfiltration of sensitive data over disruptive system encryption.
  • Recent high-profile breaches include the theft of 3.65 TB of data from Instructure and significant exfiltration from Foxconn’s North American operations.
  • Cybercriminals are now utilizing "Bring Your Own Vulnerable Driver" (BYOVD) techniques to disable endpoint detection systems before initiating data theft.
  • Stolen datasets are frequently sold to identity-fraud rings and intelligence services, turning leak sites into profitable marketplaces rather than simple coercion tools.

Why it Matters

This strategic pivot renders traditional backup-and-restore recovery plans insufficient, as organizations can no longer rely on system restoration to mitigate the impact of a breach. Companies now face long-term liability and regulatory risks from public data exposure, which often persists long after the initial security incident is contained.
Securityaffairs.com Published by Pierluigi Paganini
Read original