Skip to content
Field reportTI-2026-0428

Ransomware crews are skipping the encryption

Extortion without a payload is faster, quieter, and defeats the control most organisations invested in.

SeverityCritical

9 minThreat Intelligence

A growing share of extortion incidents involve no encryption at all. The operator exfiltrates, demonstrates possession, and negotiates. There is no ransomware to detect, no encryption routine to interrupt, and backups — the control most organisations spent the last five years improving — provide no leverage.

Detection has to move upstream, to the movement of data rather than to its destruction.

What the incidents had in common

  • Access through a valid account, usually a contractor or a service identity, not through malware.
  • Weeks of dwell time spent reading rather than deploying anything.
  • Exfiltration in volumes small enough to sit inside normal variance for that host.
  • First contact from the operator, not from a monitoring alert.
We had immutable backups and a tested restore. It was completely irrelevant to what happened to us.
CISO, professional services firm

What to watch

Whether cyber insurance treats data-theft-only events on the same terms as encryption events. Several policies still assume business interruption as the trigger, and there is not much of it here.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined