Ransomware crews are skipping the encryption
Extortion without a payload is faster, quieter, and defeats the control most organisations invested in.
SeverityCritical
9 minThreat Intelligence
A growing share of extortion incidents involve no encryption at all. The operator exfiltrates, demonstrates possession, and negotiates. There is no ransomware to detect, no encryption routine to interrupt, and backups — the control most organisations spent the last five years improving — provide no leverage.
Detection has to move upstream, to the movement of data rather than to its destruction.
What the incidents had in common
- Access through a valid account, usually a contractor or a service identity, not through malware.
- Weeks of dwell time spent reading rather than deploying anything.
- Exfiltration in volumes small enough to sit inside normal variance for that host.
- First contact from the operator, not from a monitoring alert.
We had immutable backups and a tested restore. It was completely irrelevant to what happened to us.
What to watch
Whether cyber insurance treats data-theft-only events on the same terms as encryption events. Several policies still assume business interruption as the trigger, and there is not much of it here.