Ransomware Shifts Toward Data Theft
Coverage from BleepingComputer, Infosecurity Magazine, and others
Articles
18
Active Days
208
The Topic

Ransomware is increasingly monetized through stolen data and extortion, either alongside encryption or without it, as attackers exploit the threat of publication, resale, and downstream pressure on customers or partners. Organizations are often detecting intrusions only after data theft, while improved recovery capabilities, regulatory scrutiny, and law-enforcement activity appear to be reducing the share of victims that pay. The threat remains significant because attacks are becoming more fragmented, operationally disruptive, and capable of extracting larger payments from a smaller pool of willing victims.
First Article: 01/01/26
Latest Article: 07/27/26
Summary
- Data theft alone or combined with encryption accounted for most ransomware claims by the end of 2025, according to insurance-sector reporting.
- Organizations are frequently discovering intrusions only after attackers have stolen data, with prolonged dwell times and legitimate-looking activity complicating detection.
- Chainalysis reported a 28% victim payment rate in 2025, even as claimed attacks increased and the median ransom rose substantially.
- Ransomware groups are applying multi-extortion pressure by threatening publication, selling stolen data, or contacting customers and partners.
- Payment does not reliably ensure data suppression; one cited report found that 30-40% of organizations paying for suppression did not achieve that outcome.
- The ransomware ecosystem is more fragmented, with 85 active extortion groups reported in 2025 and initial access brokers continuing to supply compromised access.
- Incidents at Nidec and the University of Mississippi Medical Center illustrate potential effects on manufacturing investigations, healthcare systems, clinical operations, and data confidentiality.
History
The story is now more explicit that ransomware economics are shifting toward multi-extortion and data suppression failures, not just data theft and lower payment rates. It also adds evidence that initial access brokers and named incidents are sustaining the operational and victim-pressure dimensions of the problem.
The story now emphasizes that ransomware is not just about data theft and leak threats, but about a more fragmented extortion ecosystem where attackers prolong access, increase pressure on victims’ wider networks, and detection often happens only after theft. The new version also adds concrete operational examples from manufacturing and healthcare that show the business disruption and ambiguity around stolen-data claims.
