Ransomware Attacks Are Down, But the Threat Is Getting Sharper

A new quarterly report from security firm Halcyon delivers a mixed message for anyone tracking ransomware trends: the overall volume of attacks is falling, but the techniques behind the attacks that do succeed are becoming significantly harder to detect and stop. The key finding is that ransomware groups are increasingly deploying so-called 'EDR kill' techniques, methods for disabling endpoint detection and response (EDR) software before deploying file-encrypting malware.

EDR tools are the security software that many organizations rely on to spot suspicious behavior on laptops, servers, and workstations before it turns into a full-blown breach. When attackers can quietly switch off or blind that software first, they buy themselves time to move through a network, steal data, and encrypt systems with far less chance of being caught mid-attack.

From Specialist Trick to Standard Practice

According to Halcyon's Q2 2026 data, what was once considered a niche, highly technical capability reserved for the most sophisticated ransomware crews has now become a routine part of the attack chain. Disabling or bypassing endpoint security is no longer the exception; it's increasingly the expectation for groups running modern ransomware operations.

This shift matters because EDR has been one of the primary defensive layers organizations invest in to catch intrusions early. If disabling that layer becomes a standard, repeatable step rather than a rare bespoke technique, it lowers the skill barrier for less sophisticated groups to achieve the same outcome as top-tier operators. It also means that traditional signs of compromise, like an EDR alert firing, may simply never appear, leaving security teams with less warning before data is stolen or systems are locked.

The irony highlighted in Halcyon's report is that this is happening even as the raw number of ransomware attacks declines. Fewer incidents don't necessarily mean less risk. It can mean that the attacks still occurring are more targeted, better resourced, and harder to stop once they begin, since the attackers behind them have adapted their tradecraft specifically to defeat the tools defenders rely on most.

Why This Matters for Privacy, Not Just IT Security

It's tempting to treat EDR kill techniques as a purely technical, back-office concern for IT departments. But the consequences land squarely on ordinary people whose data sits inside the organizations being targeted. Ransomware attacks today rarely stop at encryption; groups routinely exfiltrate sensitive files first and threaten to leak them if a ransom isn't paid. When attackers can disable detection tools and operate undisturbed for longer, they have more time to locate and copy exactly the kind of data that matters most, customer records, employee files, financial documents, and proprietary business information.

The recent case of Gentlemen Ransomware hitting Soja de Portugal, which resulted in 491GB of sensitive corporate data being leaked, is a clear illustration of how these attacks translate into real exposure for individuals and companies alike. Whether or not that specific incident involved EDR evasion, it shows the scale of data that can be swept up once attackers gain a foothold and are able to operate with minimal interference.

What This Means For You

For most readers, this isn't a call to panic, it's a reminder that the security assumptions many organizations lean on are shifting. If you work in IT or security, Halcyon's findings underscore that EDR alone can no longer be treated as a guaranteed early warning system; layered defenses, network monitoring, and rapid response planning matter more than ever. If you're an individual whose personal data is held by companies, schools, healthcare providers, or service platforms, this trend is a reminder that a breach at any of those organizations could expose your information with less advance warning than in the past, since attackers are getting better at operating silently.

Actionable Takeaways

A few practical steps can help regardless of your role:

  • If you manage security infrastructure, don't rely solely on EDR alerts; combine them with network-level monitoring and regular tabletop exercises that assume detection tools might be disabled.
  • Push for and support security policies that include offline backups, since ransomware groups that successfully disable EDR often have more time to also target backup systems.
  • As an individual, use unique passwords and enable multifactor authentication wherever your data is stored, so that even if a company you rely on suffers a breach, your other accounts stay protected.
  • Keep an eye on breach notifications from companies you do business with, and act quickly on any recommended password changes or credit monitoring offers.

Ransomware may be trending down in raw numbers, but the sophistication of EDR kill techniques means the attacks that do happen carry more risk for the data they touch. Staying informed about how these threats evolve is one of the simplest ways to stay a step ahead.