A growing majority of extortion attacks never encrypt anything. Instead, attackers steal information and threaten to publish it. Small and midsize businesses face encryption-less extortion at higher rates than large ones.

Over the past few years, we’ve started to notice that conversations about ransomware have taken on a fairly recognizable shape.  There’s a discussion about backups, somebody asks about a recovery time objective, the phrase “immutable storage” comes up, and before long the room has moved on to other topics, satisfied that the ransomware question has been handled. Until recently, that was an entirely appropriate discussion to have. But, as ever, things have changed.  A growing majority of extortion attacks now skip encryption entirely. Meaning, that restore procedure your organization is so comfortable with may suddenly have nothing to do.

Data Extortion Without Encryption

In late July, the semiconductor company Analog Devices disclosed that unauthorized access to its systems had occurred and files had been taken. The company said it did not believe the incident would materially affect its business or operations. Around the same time, a group calling itself ExfilSquad claimed to be holding roughly 570,000 records of customer information taken from the company.

But there had been no frozen screens, no ransom note in a text file on a desktop, and, significantly, nothing for anyone to restore. Analog Devices was correct that its operations were unaffected, but weirdly the statement was beside the point, because the damage from this kind of attack doesn’t exist anywhere operations can reach it. The damage relates to regulators, to the customers whose information was in those files, and, to be blunt, to whichever plaintiff’s firm files first.

There’s an instructive epilogue here. Analog Devices later stopped appearing on the group’s leak site, which threat researchers note is common once negotiations begin. Take that for whatever it’s worth, along with the observation from SOCRadar that some of ExfilSquad’s claims elsewhere appear inflated. Extortion is a business built on assertions that the victim cannot easily check.

Encryption-Less Ransomware is No Edge Case

The Analog hack isn’t some strange, one-off incident. The insurer Resilience found that 65% of the extortion claims it handled in the second half of 2025 involved no encryption at all, up from 49% in the first half of the same year. By the end of that year, attacks relying on encryption alone accounted for 13% of its ransomware claims, while data theft, on its own or paired with encryption, accounted for 87%. Palo Alto’s Unit 42 saw encryption present in 78% of extortion cases in 2025, down from levels at or above 90% in the preceding four years. Google’s threat intelligence team tracked incidents involving only data theft rising from roughly 2% in 2020 to more than 15% in 2025.

Why this shift?  Essentially, the evolution occurred because the defenses worked. Cybersecurity experts spent over a decade telling organizations to build real backup and recovery capability, and enough of them listened that encryption stopped being reliable leverage. Criminals are rational operators, and like you, they have margins to protect.

If you run a company of fifty or two hundred people, you might reasonably assume this is a large-enterprise problem. Sophos found the opposite. Extortion-only attacks showed up at 13% of companies with 100 to 250 employees, against 3% of companies with 3,000 to 5,000.

That tracks with how the attacks actually work. Encrypting a large environment is loud, technically demanding, and increasingly likely to trip somebody’s detection stack partway through. Copying files out of a midsize company with limited egress monitoring is comparatively undemanding.

How to Build an Incident Response Plan for Data Theft

When it comes to planning for encryptionless ransomware, the best time (as the saying goes) is yesterday, and the second-best time is now. Start by finding out where your sensitive data actually lives. You can’t protect an inventory you can’t locate.

Then keep a close watch what leaves and how. Most midsize environments have decent controls on what comes in and almost nothing looking at outbound volume. Nobody is going to call the helpdesk to report a data theft in progress, because it produces no symptom that an employee can feel.

This may seem like an odd suggestion, but hear us out.  The next step is to hold a tabletop exercise for an incident in which, apparently, nothing goes wrong. Everyone’s logged in, the servers are fine, and the entire event is a legal and communications problem running on a regulatory clock. Notice how much of your existing plan is still useful. My experience is that it’s less than people expect; that’s the kind of discover you want to make in a conference room during an exercise, rather than finding it out the hard way.

Last, delete things you no longer need. Retention discipline is the only control on this list that reduces the size of the eventual disclosure. Too many companies operate on a “save everything” hoarder mentality.  But records you disposed of in 2023 can’t turn up on a leak site in 2026.

So the question I’d put to your team is what happens on the day everything is working. The phones ring, the email flows, nobody notices anything at all, but somehow, half a million of your records are sitting on somebody’s website. Who speaks first, and to whom?

TMG helps small and midsize organizations plan for the incidents that don’t announce themselves. If your ransomware plan is a restore procedure, we should talk.

Leave a Reply

Your email address will not be published. Required fields are marked *