Why cybercriminals no longer need to encrypt your files

by Black Hat Middle East and Africa
on
Why cybercriminals no longer need to encrypt your files

A month ago we wrote about LockBit’s legacy, and how ransomware’s real strength lies in its business model. Taking down infrastructure disrupted one of the world's biggest operations – but it didn't remove the expertise, affiliate networks or financial incentives that underpin the market.

The latest GRIT Q2 ransomware report adds another dimension. GRIT recorded 2,279 publicly posted victims during Q2 2026, representing a 7% increase on the previous quarter and a 43% rise year on year. At the same time, the number of ransomware and extortion groups posting victims reached a record 91.

Those figures show an extortion economy that continues to grow. But more interesting than that is the number of groups that are changing the way they create leverage.

According to GRIT, data extortion is steadily gaining ground over the traditional double-extortion model because it is operationally cheaper and quieter. Rather than encrypting systems and demanding payment for a decryption key, attackers focus on stealing sensitive information and threatening to publish it.

For organisations with mature backup strategies, this changes what it means to be prepared. Business operations may recover, but stolen customer data, intellectual property and regulatory exposure can continue to create leverage.

The value now lies in the data

Encryption creates urgency by disrupting operations and complicating recovery.

Data theft creates its own pressure.

GRIT argues that encryption requires threat actors to develop and maintain malware, manage encryption keys and operate decryption infrastructure. Data extortion centres on two objectives: gaining access and exfiltrating valuable information. Enterprise SaaS sprawl, connected cloud services and shadow AI provide a growing number of opportunities to achieve exactly that.

We can use FulcrumSec to illustrate how this model works. The group has claimed 21 victims across multiple industries, while GRIT reports that researchers have observed no ransomware binaries across its known operations. Instead, the group's campaigns focus on stealing data and using that information as the basis for extortion.

Another example comes from TeamPCP. GRIT says the group evolved from ransomware and cryptomining into SaaS-focused ‘smash and grab’ operations, harvesting more than 300GB of cloud tokens, SSH keys, Kubernetes secrets and LLM keys. Researchers say the group then monetised that access through partnerships with ransomware affiliates rather than deploying encryption itself.

These examples show we’re working with an expanding cybercrime economy where access, credentials and sensitive information have become valuable products in their own right.

The attack surface has moved

The report also highlights a broader change in where attackers are investing their efforts. During Q2, GRIT observed increased activity targeting:

  • Software supply chains
  • Third-party integrations
  • Code repositories 
  • Cloud access tokens

Researchers found a common thread running through several major incidents: attackers abused trusted relationships between organisations and services to reach valuable data.

The Klue incident, described in the report, is a strong example of this trend. According to GRIT, attackers exploited a stale integration credential, harvested customer OAuth tokens, and used those credentials to automate the extraction of CRM data from connected Salesforce environments. The stolen CRM data then became the basis for extortion demands sent to multiple security vendors.

As organisations expand their SaaS ecosystems, every application, API and third-party integration becomes part of the attack surface. Sensitive information now flows across environments that endpoint and perimeter-focused ransomware defences might monitor poorly.

AI is making stolen data more valuable

Much of the public conversation around AI focuses on futuristic attack techniques – but this research suggests we’re dealing with a more immediate challenge. 

Researchers assess that FulcrumSec used a large language model to analyse a victim's complex production databases, helping the group explain exactly how records could be linked together and why the stolen information justified its ransom demand. The assessment is based on the sophistication of the analysis, along with the language used during negotiations and the speed with which that analysis appeared.

That represents a practical application of AI rather than a dramatic new capability. Language models help threat actors:

  • Understand stolen information more quickly.
  • Communicate with greater precision.
  • Build stronger negotiating positions around the value of the data they already possess. 

And as those capabilities become more accessible, sophisticated negotiations become available to a much wider pool of threat actors.

What organisations can learn from this 

Our LockBit article explored how ransomware expertise survived a major disruption. Now, this latest research suggests the business model continues to evolve in equally significant ways.

For cybersecurity practitioners, the focus needs to broaden beyond malware alone. Protecting identities, monitoring third-party integrations, understanding where sensitive data resides, and limiting unnecessary access all play a growing role in reducing extortion risk.

The ransomware economy still revolves around leverage. But now, leverage can come from what attackers know about an organisation's data – rather than just what they’ve encrypted.

Share on

Join newsletter

Join the newsletter to receive the latest updates in your inbox.


Follow us


Topics

Sign up for more like this.

Join the newsletter to receive the latest updates in your inbox.

Related articles

Are security teams wasting their time?

Are security teams wasting their time?

Security teams spend 42% of their time investigating low-priority risks. Discover why alert fatigue and poor prioritisation waste valuable analyst time – and how continuous exposure management can help.

Read More