Market Insight: The Shift From Ransomware Encryption to Data-Theft-Only Extortion

From Ransomware Encryption to Data-Theft–Only
CyTwist Research Team

Executive Overview

CyTwist Research has identified a material shift in adversary behavior during 2025: a growing move away from ransomware encryption toward data-theft-only extortion campaigns.

This evolution reflects both tactical adaptation by threat actors and structural changes in enterprise security environments. Improved backup strategies, faster recovery capabilities, and more mature ransomware response processes have reduced the effectiveness of encryption as a primary coercion mechanism. In response, attackers are increasingly prioritizing data exfiltration and reputational leverage over disruptive encryption.

Based on CyTwist research, corroborated by public reporting, data-theft–only extortion now represents a majority of observed extortion activity, signaling a durable strategic shift rather than a temporary deviation.

Observed Trend: Encryption Is No Longer Central

Key Observation

In 2025, extortion campaigns relying solely on data theft, without deploying encryption,  accounted for an estimated 52% of observed extortion incidents, surpassing traditional ransomware attacks.
This shift is operationally consistent across multiple threat groups and industry verticals.

Drivers Behind the Shift

1. Reduced Effectiveness of Encryption

Encryption-based ransomware increasingly fails to deliver predictable outcomes due to:

  • Widespread adoption of resilient backup and recovery strategies
  • Improved incident response and containment playbooks
  • Faster ransomware detection and response by security tools


From an attacker’s perspective, encryption has become higher risk with diminishing returns.

2. Lower Risk and Higher Consistency of Data Extortion

Data theft offers attackers:

  • Lower technical and operational complexity
  • Reduced likelihood of early detection
  • Greater flexibility in timing and pressure
  • More reliable leverage via regulatory, reputational, and contractual exposure


Modern data-theft-only extortion campaigns are deliberately designed to minimize operational noise. Attackers rely on legitimate administrative tools and standard operating system functionality to locate, stage, and prepare sensitive data for exfiltration. When viewed in isolation, these actions resemble normal IT activity and frequently remain below alert thresholds.

As a result, encryption is increasingly optional rather than essential.

Supporting Evidence From Threat Actor Activity

Multiple well-documented groups illustrate this sustained transition:

  • BianLian
    Initially operated as a ransomware group; transitioned fully to data theft after its encryption tooling was compromised.
  • Cl0p
    Conducted large-scale data exfiltration campaigns targeting MOVEit and Oracle E-Business Suite without deploying encryption.
  • Karakurt
    Established specifically for data extortion; encryption was never part of its operational model.
  • Scattered Spider
    Focuses on identity abuse, cloud access, and data exfiltration using legitimate tooling, largely avoiding ransomware deployment.


Collectively, these cases indicate a deliberate and sustained strategy: remain quiet, blend into legitimate activity, extract data, and apply pressure only after leverage is secured.

Implications for Detection and Response

Data exfiltration in modern extortion operations is not a single discrete event. It typically unfolds as a sequence of preparatory actions – asset discovery, local staging, transformation or compression, and gradual outbound transfer – often distributed across time and systems.

Detection approaches that focus on isolated events rather than sequence and progression are poorly aligned with this attack model.

Encryption-Centric Detection Models Are Insufficient

Many security controls and operational playbooks remain optimized for:

  • Malware execution
  • Exploit delivery
  • Encryption activity


Data-theft-only campaigns frequently bypass these detection points entirely.

Silent Dwell Time Increases

In extortion-without-encryption scenarios:

  • Attackers may remain active for extended periods
  • Activity blends with legitimate administrative behavior
  • Alerts are low-severity, fragmented, or context-poor
  • No clear “breach moment” occurs until extortion begins


The absence of disruptive signals reduces escalation urgency and increases the likelihood of missed attacker progression.

Managed Detection and Response (MDR) teams face growing pressure under this model. Without encryption or malware execution to anchor investigations, prioritization increasingly depends on understanding attacker progression rather than alert severity alone.

The Economic Model of Modern Extortion

Attack ModelOperational CostDetection RiskRevenue Predictability
Encryption-based ransomwareHighHighDeclining
Data-theft–only extortionLowLowConsistent

This economic reality strongly incentivizes continued use of data theft as the primary extortion mechanism. Fear of reputational damage, regulatory exposure, and loss of customer trust has proven more reliable than system disruption.

Strategic Detection Gap

The core challenge for defenders is no longer visibility, but interpretation.

In many observed incidents, security controls successfully record the underlying activity associated with data theft. Failure occurs at the interpretation and correlation layer. Without contextual analysis across time and stages, legitimate actions associated with attacker progression are misclassified as benign operational behavior.

Most environments already collect:

  • Endpoint telemetry
  • Authentication logs
  • Process and command-line activity
  • Network events


However, many tools evaluate events individually rather than as part of an evolving attack sequence, creating blind spots when adversaries abuse trusted tools and system behavior.

Implications for MDR and Advanced Detection

This trend reinforces the importance of MDR, but also exposes its limitations when:

  • No malware alert anchors the investigation
  • No encryption activity elevates severity
  • No clear IOC or signature triggers response

Detection strategies must evolve to:

  • Correlate signals across time and stages
  • Assess intent rather than isolated event abnormality
  • Identify attacker progression before data exfiltration occurs


Conclusion and Outlook

The evidence indicates that encryption-less extortion is no longer an exception – it is becoming the dominant extortion model.

CyTwist Research observes a structural inversion in extortion tactics. Data exfiltration, once a fallback when encryption failed, has become the primary mechanism for coercion. Ransomware encryption is increasingly used selectively as a pressure amplifier rather than the central objective.

Organizations that continue to rely on encryption-centric detection strategies will increasingly discover incidents after data has already been exfiltrated and leverage established.

Security programs should reassess their assumptions and ensure they can identify:

  • Silent attacker progression
  • Abuse of legitimate tools
  • Long-dwell, low-noise intrusions
  • Pre-exfiltration activity


In 2026, the ability to detect extortion before encryption, or without encryption at all, will be a defining capability of effective cyber defense.

Share

Ready to stop
stealth targeted
attacks?

Market Insight: The Shift From Ransomware Encryption to Data-Theft-Only Extortion

CyTwist Research Team
CyTwist Research has identified a material shift in adversary behavior during 2025: a move away from ransomware toward data-theft-only extortion campaigns.
From Ransomware Encryption to Data-Theft–Only

Share

Ready to stop
stealth targeted
attacks?

More posts like this

Skip to content