A newly tracked threat actor known as GSG has spent the past three months building a public leak site full of victim listings, but researchers have yet to find any evidence the group actually encrypts anything. That detail matters. It points to a form of data theft extortion without ransomware that skips the most disruptive part of a traditional attack while keeping the pressure tactics that make extortion work.
What GSG's Listings Actually Show
According to tracking site Ransomware.live, GSG had posted 48 victim listings through September 21. The pattern of those postings tells its own story. The group launched with 29 listings in a single day in July, ending the month with 31 total. August saw the pace drop sharply to 12 new listings. September has been quieter still, with only 5 listings so far.
What hasn't dropped is the scale of the claims attached to each listing. The listings that GSG has posted claim a median of 213 GB of stolen data per victim, a substantial haul by any measure. So while the group's posting frequency is fading fast, the individual claims remain large, suggesting GSG may be shifting toward fewer, higher-value targets rather than losing steam entirely.
Why No Encryptor Has Surfaced
Here is the part that separates GSG from a typical ransomware operation: no public source has documented a GSG encryptor or a ransom note. In conventional ransomware attacks, victims discover the intrusion when files are locked and a note demands payment for a decryption key. That evidence trail, malware samples, note text, encrypted file extensions, is usually how researchers build a technical profile of a group.
With GSG, that trail simply isn't there. The absence of an encryptor doesn't mean the group is any less serious. It means GSG appears to be operating purely on the threat of publishing stolen data rather than locking it up. Based on this pattern, the working assessment is, at low confidence, that GSG is a data-theft extortion operation rather than a full ransomware group. Low confidence here reflects genuinely limited public evidence, not a settled conclusion, but the pattern lines up with a well-documented industry trend covered in the 2026 Outlook on ransomware and data theft merging, where encryption is increasingly treated as optional rather than essential to extortion.
How Extortion-Only Tactics Change the Risk Calculus
Skipping encryption changes the math for both attackers and victims. For attackers, it lowers the technical bar. Building and deploying a working encryptor takes real engineering effort, while exfiltrating data and threatening to leak it requires comparatively less infrastructure. It also removes a major operational headache: encryptors can be reverse-engineered, decryption tools sometimes get published, and locked systems can occasionally be restored without paying.
For victims, the risk shifts from an obvious, visible disruption (frozen systems, halted operations) to a quieter but potentially longer-lasting threat: the exposure of sensitive data with no clear end date. A company that gets its files encrypted knows immediately that something is wrong. A company whose data is quietly copied out may not know until a leak site names them. This is exactly the shift seen with other emerging groups. ExfilSquad, which surfaced with 14 claimed victims and no encryption component either, follows the same playbook: steal first, threaten to publish, skip the disruption. GSG's declining post volume paired with large claimed data sizes suggests a similar model, one built around leverage rather than sabotage.
Defensive Steps: Backups, Segmentation, and Monitoring
Because extortion-only groups don't need to encrypt anything to cause harm, defenses built solely around backup and recovery aren't enough on their own. Backups still matter for resilience against traditional ransomware, and that groundwork remains worth maintaining. But the bigger priority against a group like GSG is limiting what can be taken in the first place and catching it while it's happening.
Network segmentation reduces how much data an intruder can reach from a single foothold, which matters directly against a group whose entire model depends on large-volume data theft. Just as important is monitoring for the signs of exfiltration itself: unusual outbound data transfers, unfamiliar cloud storage destinations, and spikes in data volume leaving the network at odd hours. These are the signals that show up before a group ever posts a listing, and they're often the only warning a victim gets when there's no ransom note to tip them off.
What This Means For You
For organizations of any size, GSG is a reminder that ransomware defenses built around encryption alone are incomplete. Data theft extortion without ransomware is becoming a recognized category of its own, and it demands attention to data access controls and exfiltration monitoring, not just backup strategy. The broader trend lines up with what's been observed elsewhere: threat intelligence tracking ransomware activity in Japan and rising attack volumes globally shows attackers adapting their methods, not slowing down.
Takeaways
GSG's shrinking post count with steady large-data claims suggests a group narrowing its focus rather than fading out. Treat any sign of unusual outbound data movement as seriously as you'd treat a ransomware alert. Review data segmentation so that a single compromised account can't reach your entire data store. And keep watching how groups like GSG and ExfilSquad evolve, since they represent a pattern, not an isolated incident, in how extortion is carried out today.




