惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
V
V2EX
Jina AI
Jina AI
爱范儿
爱范儿
M
MIT News - Artificial intelligence
量子位
L
LangChain Blog
Google DeepMind News
Google DeepMind News
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
腾讯CDC
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Why pure extortion is replacing traditional ransomware
Pierluigi Paganini · 2026-05-23 · via Security Affairs

Ransomware gangs are shifting from encryption to pure extortion, focusing on stolen data, reputational pressure, and stealthier attacks.

Ransomware groups are quietly changing strategy in 2026. Instead of encrypting systems and causing immediate disruption, many attackers are now focusing on pure extortion: stealing sensitive data and threatening to leak it publicly if victims refuse to pay.

This shift is happening for a simple reason. Encryption is noisy, risky, and easier for defenders to detect. Data theft is often faster, quieter, and in many cases more profitable.

Several recent reports suggest attackers are increasingly prioritizing credential theft, long-term access, and exfiltration over traditional ransomware deployment. The pressure point is changing too. Companies are no longer paying just to restore operations, they are paying to avoid reputational damage, regulatory fallout, and exposure of sensitive internal documents.

The biggest incidents of the past months show the same pattern again and again: attackers are causing enormous damage without encrypting systems at all.

The shift is now visible at scale.

According to Kaspersky’s State of Ransomware 2026, ransom payment rates have collapsed from roughly 76% in 2019 to just 28% in 2026. In practice, fewer than one in three victims now pays.

“The new model is pure data extortion: steal it, threaten to publish it, monetise either through victim payment or, increasingly, direct resale on the data leak site. In May 2026 this isn’t an exotic experiment.” reads the report published by the Ransomnews Research Team. “It’s the default playbook.” continues the report.

Attackers adapted because the old model became less effective. Better backups, stricter cyber-insurance rules, regulatory pressure, and improved incident response reduced the profitability of large-scale encryption campaigns.

Encryption also creates operational problems for attackers. It generates forensic evidence, triggers EDR alerts, and gives defenders time to react.

“The shift is rational. Encryption is operationally expensive for the attacker, it leaves loud forensic artifacts, triggers EDR alerts on file-rewrite patterns, requires per-victim key management, and exposes the operator to law-enforcement decryption assistance.” continues the report.”Extortion-only attacks are faster, quieter, and far harder for backup-and-restore strategies to neutralise. The data is already out the door before the victim notices.”

The numbers behind recent attacks explain why this model is becoming dominant.

In May 2026, ShinyHunters claimed to have stolen around 3.65 TB of data from Instructure, the company behind Canvas LMS. The leak allegedly affected roughly 275 million students, teachers, and staff across approximately 9,000 educational institutions.

Around the same period, the Nitrogen gang targeted Foxconn’s North American operations, reportedly exfiltrating:

  • 11 million files
  • nearly 8 TB of internal data
  • technical drawings
  • project documentation
  • confidential manufacturing information

In both cases, encryption was either absent or secondary. The pressure came entirely from data exposure.

That changes the defensive equation significantly.

Traditional ransomware response plans focused heavily on:

  • restoring systems,
  • recovering encrypted files,
  • rebuilding infrastructure,
  • and negotiating decryption keys.

But when attackers skip encryption entirely, those controls lose much of their value. Organizations can restore systems quickly and still suffer a catastrophic breach because the stolen data already exists outside their control.

The economics have changed too:

“When the leak site itself is the product, the victim’s negotiation position weakens dramatically.” states the report. “The most important strategic shift is the one with the least technical content. In the 2020 model, the data leak site was a coercion device: pay or we publish. In the 2026 model, the data leak site is the product. Operators have built downstream relationships with carders, identity-fraud rings, and (in some confirmed cases) sanctioned intelligence services that purchase exfiltrated datasets directly. Victim payment is no longer the only, or even the primary, revenue channel for some operators.”

Leak sites are no longer just pressure tools. They became marketplaces. Stolen datasets are increasingly monetized through resale to fraud groups, identity theft operations, and other criminal buyers even if victims refuse to pay.

Another major trend in 2026 is the widespread adoption of EDR-killer utilities.

Attackers now routinely disable endpoint detection systems before beginning reconnaissance or exfiltration. The most common method remains BYOVD (Bring Your Own Vulnerable Driver), where attackers load signed but vulnerable Windows drivers to terminate security tools at kernel level.

What used to be considered advanced tradecraft in 2024 is now becoming standard even among mid-tier ransomware affiliates.

Operational timelines are also shrinking:

  • Initial access to reconnaissance: often 2–7 days
  • Data exfiltration: sometimes completed in 1–4 days
  • Public leak-site listing: often within hours after exfiltration

By removing the encryption phase entirely, attackers cut several days from the attack lifecycle while also eliminating the loudest detection stage.

For defenders, this means the old ransomware playbook is no longer enough.

The priority is shifting toward:

  • exfiltration detection,
  • outbound traffic monitoring,
  • cloud-storage abuse detection,
  • off-host logging,
  • DLP controls,
  • and rapid disclosure readiness.

Backups still matter. But backups alone do not protect against a public data leak involving millions of records or years of intellectual property.

The uncomfortable reality is that ransomware did not become weaker. It became quieter, faster, and more focused on long-term data exposure instead of immediate operational disruption.

“It would be easy to read the encryption-less shift as good news. After all, encryption was the part of ransomware that did the most operational damage to victims, locked systems, broken supply chains, halted hospitals. If operators stop encrypting, isn’t that a defensive win?” concludes the report. “Not exactly. The reduction in encryption is balanced by an increase in the scope and persistence of the data exposure. A 275-million-record dataset on a public leak site is a 30-year liability for the victims of that data. A 10-million-file Foxconn dump rewrites the threat models of every downstream brand whose IP it touches. The visible operational damage is smaller. The invisible long-tail damage is much larger.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)