The New Extortion Economy: When Ransomware Doesn’t Need Encryption

Posted by Dan Rearden on Sep 29, 2026, 4:59:16 PM

Many of the core elements of a ransomware attack haven’t changed. Attackers still phish victims, exploit vulnerabilities, or purchase valid credentials to gain initial access to a network. From there, they may spread to other systems, escalate their privileges, and export data.

What happens next is changing.

A 2025 Sophos survey found that only 51% of attacks on U.S. organizations included data encryption, down from 58% the previous year. In healthcare, only 34% of attacks resulted in data being encrypted in 2025, the lowest level in five years. Those same healthcare providers also recovered faster: 58% recovered within a week, up from just 21% the year before, according to Sophos’s healthcare ransomware research.

That doesn’t mean encryption—or ransomware—is disappearing. In 2025, the number of reported ransomware victims rose 58% year over year, with manufacturing accounting for 14% of victims, according to GuidePoint Security’s 2026 Ransomware and Cyber Threat Report. Sophos’s 2026 report also shows encryption climbing back to 56% of attacks. But encryption has become optional. Palo Alto Networks’ Unit 42 reports that encryption-based extortion fell 15% in 2025 as more attackers skipped encryption and went straight to data theft.

In healthcare, extortion-style attacks in which data was stolen but nothing was encrypted tripled to 12% in 2025, according to Sophos. And in 2026, Sophos found that organizations whose data was encrypted restored it from backups in 66% of cases, while 48% of victims whose data was encrypted paid a ransom. In 16% of attacks, data was both encrypted and stolen.

Backups may bring your files back. But they can’t bring back data that’s already been stolen.

The 'Delete' Fallacy and Secondary Extortion

A company doesn’t need to be re-compromised for a ransomware attack to keep costing it.

PowerSchool, a major K-12 software provider, disclosed in January 2025 that hackers had used a stolen credential to break into its customer support portal and steal student and teacher data, including Social Security numbers and medical information. According to charging documents reported by K-12 Dive, the attacker had been inside since September 2024, and the stolen data covered more than 60 million students and 10 million teachers.

The attacker demanded approximately $2.85 million in Bitcoin. PowerSchool ultimately paid a ransom after receiving assurances that the stolen data would be deleted, although the company has not publicly disclosed how much it paid. Then, the following May, school districts in the U.S. and Canada began receiving extortion demands using data from that same breach.

It wasn’t a new compromise. The attacker didn’t need new data. What had been stolen the first time still had value.

And there is little reason to assume that paying a ransom makes that value disappear. When law enforcement seized LockBit’s servers in 2024, investigators found data belonging to victims who had already paid to have it deleted. Once attackers have a copy of sensitive data, victims have no reliable way to know that every copy has actually been destroyed.

Once data leaves an organization’s control, attackers have multiple ways to extract value from it. AI can make that process faster. GuidePoint Security reported in 2026 that threat actors were using large language models to analyze exfiltrated data, personalize ransom negotiations, and create psychological pressure. Anthropic separately documented ShinyHunters-linked operators using AI agents to perform “nearly all of the work” in data-theft operations, including attacks in which stolen information was publicly staged to pressure victims into paying.

If the deadline passes and no payment is sent, stolen data can also be packaged into bundles, known as dumps, and taken to dark web markets and forums to be sold. Reporting on criminal dark-web markets describes this secondary market for stolen information. Criminals can validate that data and combine it with other breaches to build fuller profiles of victims. Kaspersky’s Olga Altukhova has described stolen data as a “persistent weapon” in an analysis of the lifecycle of stolen data.

That persistence is what makes data theft different. A password can be reset and a credit card can be reissued, but Social Security numbers, birth dates, medical records, biometric information, and other stolen information can remain sensitive for years or, in some cases, for life. That’s why stolen data can be hoarded, combined with other breaches, resold, or used again for extortion.

A ransom payment might buy a moment of respite. But it doesn’t make the data any less valuable to whoever still holds a copy.

Extortion Moves Beyond the Organization

Ransomware attacks remain at high levels, but that doesn’t mean threat actors are getting paid. In Q3 2025, only 23% of victims paid a ransom. By Q2 2026, Coveware found that victims paid in only about 15% of cases where the only threat was leaking the data, another record low.

When the threat of a leak stops working, attackers can look for other sources of pressure, which could include the people whose information they stole.

Hunters International attacked Fred Hutch Cancer Center in Seattle in November 2023. Fred Hutch refused a ransom demand of 50 Bitcoin, valued at approximately $2 million at the time. The attackers then began harassing individual patients whose information was contained in the stolen data, an example of triple extortion.

They sent emails to patients containing their personally identifiable information, information about where their data would be sold, and instructions to pay $50 in Bitcoin to have it removed. Fred Hutch told patients not to pay and to block and delete the emails.

The attackers escalated further, threatening some patients with “swatting” if they didn’t pay. Swatting involves making a false report to law enforcement intended to trigger an armed police response at someone else’s location, putting victims and the people around them in physical danger.

The consequences extended beyond the initial breach. Fred Hutch faced several class-action lawsuits, eventually reaching a settlement valued at approximately $52.5 million. The settlement included $11.5 million in cash payments to class members, $13.5 million for improvements to network security, and $25.5 million in two-year medical fraud-monitoring subscriptions.

The Fred Hutch case isn’t the only example of attackers transferring pressure from an organization to the people represented in its data. In September 2025, hackers who stole data on about 8,000 children from the Kido nursery chain in London contacted parents directly, pressuring them to get the nursery to pay.

The human consequences can extend further. In a report by Raconteur, one person said a ransomware ordeal contributed to a stroke they suffered shortly afterward, while a senior executive described having “a little bit of PTSD” every time they returned to the office.

Response teams can carry a different burden. They are responsible for triaging, remediating, and investigating incidents, often working long hours and overnights under pressure from internal teams, stakeholders, and the public. Research from RUSI and the University of Kent found that ransomware incidents leave IT and security staff dealing with stress, exhaustion, and burnout, and in some cases serious health problems.

It’s easy to focus on systems, data, and ransom demands and forget the people caught in the middle. As extortion increasingly targets those people directly, that distinction becomes harder to ignore.

Treat Data Theft as the Incident That Matters

Watch for data leaving, not just files locking. Alert on bulk uploads, known exfiltration tools like Rclone, large archive files, unusual cloud-storage destinations, and mass downloads from SharePoint, OneDrive, or other SaaS apps. In the fastest cases Unit 42 investigated, attackers went from initial access to stealing data in 72 minutes.

Keep less data, for less time. You can’t leak what you don’t keep. Set retention schedules and enforce them, purge old records, and know where your most sensitive data lives so you can answer “What did they take?” in hours, not weeks.

Harden identity. Identity weaknesses played a material role in nearly 90% of the incidents Unit 42 investigated for its 2026 Global Incident Response Report. Use phishing-resistant MFA, protect against session-token theft, and require call-back verification before the help desk resets a password. Verizon also found that half of ransomware victims had credential or infostealer exposure in the 95 days before an attack.

Know your third parties. Third-party involvement reached 48% of breaches in Verizon’s 2026 Data Breach Investigations Report, an increase of 60% year over year. Inventory the SaaS apps and integrations that touch your data and remove the ones you don’t use.

Plan for the people in the data. Have notification letters and “what to do if you’re contacted” guidance ready for customers, patients, students, or employees.

Don’t count on deletion. Decide your ransom-payment position with legal counsel and leadership ahead of time, and don’t treat an attacker’s promise to delete data as a reason to pay.

Practice the right scenario. Run a tabletop exercise where nothing gets encrypted, your data shows up on a leak site, and your customers and executives start getting calls.

The evolution of ransomware changes what it means to recover from an attack. Restoring systems is still important, but recovery no longer ends when the network is back online. Once sensitive data has been stolen, it can become leverage against an organization, its customers, its employees, or anyone else represented in that data.

The goal, then, isn’t simply to prepare for ransomware that locks your files. It’s to prepare for what happens when the attacker never needs to lock them at all.

Topics: Data Breaches, Incident Response, Data Exfiltration, Cyber Extortion

  • There are no suggestions because the search field is empty.

ProCircular is a Full-Service Information Security Firm

We are passionate about helping businesses navigate the complex world of information security, and our blog is another great source of inforamtion. We can assist you no matter where you are in your security maturity journey:

  • Breached or hit with ransomware?
  • Don't know where to start? 
  • Looking to confirm your security with a third party?

Secure your future with ProCircular.

Recent Posts

Subscribe to Email Updates