Ransomware is changing shape. According to a recent threat report, the traditional model of maliciously encrypting data is becoming less common because attackers find it less profitable and harder to execute effectively. What is replacing it is ransomware data theft extortion: criminals steal sensitive information, then pressure victims to pay to keep it private. For individuals, that shift matters, because your data can be exposed even when no files on a company's network are ever locked.

Why criminals are moving away from encryption

Encrypting files at scale is a demanding job. Attackers have to get past defenses, spread across systems, and deploy malware that works reliably. Defenders, meanwhile, have gotten better at backups and recovery, which means an encrypted network is not always a paying victim.

The source report describes encryption as both less profitable and more difficult to carry out effectively. Stealing data sidesteps those problems. If a company can restore its systems from backups, the criminals still hold something valuable: the stolen information and the threat of publishing it.

This is the core of the trend we covered in more depth in why ransomware gangs are ditching encryption for extortion. The leverage moves from "you cannot access your files" to "we will expose what we took."

How the PAYLOAD campaign abuses Active Directory

The report points to campaigns in 2026, such as PAYLOAD, as examples of this new approach. According to the source, attackers compromise Active Directory environments and then deploy malicious Group Policy Objects.

A quick explainer for non-technical readers:

  • Active Directory is the system many organizations use to manage user accounts, permissions, and devices across their network.
  • Group Policy Objects (GPOs) are the settings that an administrator pushes out to many computers at once, such as security rules or desktop configurations.

Because GPOs are a legitimate way to control lots of machines simultaneously, an attacker who gains control of Active Directory can use them to reach an entire organization quickly. In the PAYLOAD campaign, the report says malicious GPOs are used to display ransom demands and lock user access, rather than relying on classic file encryption.

The takeaway is that the attackers are abusing trusted administrative tools, not just dropping obvious malware. The source excerpt available to us is brief, so details beyond this description, such as specific victims or technical indicators, are not covered here.

What stolen data means for individuals

Most people will never manage an Active Directory server. But your information likely sits in systems that do: an employer's HR files, a healthcare provider's records, a school's databases, a retailer's customer accounts.

When the extortion model is based on data theft, the harm to individuals does not depend on whether the organization's systems went down. Consider what that means in practice:

  • Exposure without warning. A company might recover operations quickly, yet the stolen data still exists in criminal hands.
  • Pressure on the organization, risk to you. If the victim refuses to pay, the threat is to publish or leak what was taken, which can include personal details.
  • Follow-on abuse. Exposed personal information can fuel phishing, impersonation, and account takeover attempts.

The suggested angle here is simple: you do not have to be the direct target for your data to be at risk.

What This Means For You

You cannot control how well an organization protects its Active Directory. You can control how much damage a leak would do to you. Strong account hygiene limits what criminals can do with stolen details, and early awareness helps you respond before misuse spreads.

Practical steps to reduce your exposure

  1. Enable multi-factor authentication (MFA) on email, banking, and any account that holds personal data. Prefer app-based or hardware methods over SMS where possible.
  2. Use unique passwords for every account, managed with a password manager, so one leak does not unlock others.
  3. Review account privileges. If you administer systems at work or at home, remove admin rights from everyday accounts. Limiting who can change policies narrows what an attacker can abuse if one account is compromised.
  4. Check whether your data has appeared in breaches using a reputable breach-notification service, and change credentials for anything affected.
  5. Be skeptical of unexpected messages. After a breach, criminals may contact people directly. Verify through official channels before clicking links or sharing information.
  6. Limit what you share. Give organizations only the data they genuinely need, since information never collected cannot be stolen.

The bottom line

Ransomware data theft extortion reflects a pragmatic shift: encryption is harder and less rewarding, while stolen data keeps its value regardless of backups. Campaigns like PAYLOAD show attackers using the administrative tools organizations already trust. Your best response is practical: turn on MFA, tighten account privileges, and check regularly whether your data has surfaced in a breach. For broader context on why this model is spreading, read our piece on ransomware gangs moving from encryption to extortion.