A Shift From Encryption to Pure Data Theft
For years, ransomware meant one thing: attackers broke into a network, encrypted files, and demanded payment for a decryption key. That model is changing. In a recent interview with HIPTHER, Jack Alexander of cybersecurity firm Quorum Cyber discussed the rise of data-only extortion, a tactic where criminals skip encryption entirely and instead threaten to leak stolen information unless a ransom is paid.
The distinction matters more than it might seem at first glance. Encryption-based ransomware disrupts operations immediately, systems go down, employees can't work, and the damage is visible right away. Data-only extortion is quieter. Files stay accessible, business continues as normal, but sensitive information, customer records, employee data, financial details, has already left the building. Alexander's discussion frames this as a growing trend that organizations and regulators alike need to take seriously as 2026 approaches.
Why Identity Security and GDPR Pressures Are Colliding
According to the interview summary, Alexander connects the rise of data-only extortion to broader identity security risks and mounting pressure from data protection regulations like GDPR. This connection makes sense when you consider how modern attacks actually unfold. Rather than deploying malware that triggers antivirus alerts, many attackers now rely on stolen or compromised credentials to log in like a legitimate employee. Once inside, they quietly copy sensitive files before anyone notices anything unusual.
This approach lowers the technical bar for attackers while raising the regulatory stakes for victims. Under GDPR and similar frameworks, organizations that suffer a data breach face strict notification timelines and potential fines, regardless of whether ransomware encrypted anything. A pure data theft incident can trigger the same legal and reputational fallout as a full-blown ransomware attack, sometimes with less warning that a breach even occurred.
This pattern isn't entirely new. Investigations into past ransomware campaigns have already shown how attackers exploit trusted cloud services to move stolen data out of a network without raising alarms. A previous case involving Vice Society ransomware abusing OneDrive for data theft illustrated exactly this kind of exfiltration technique, where attackers used a legitimate, widely trusted platform as the vehicle for moving sensitive files off a victim's network. As data-only extortion becomes more common, expect similar abuse of everyday cloud tools to keep showing up in incident reports.
AI's Role in Shaping 2026 Cyber Defense
The interview also touches on how artificial intelligence is reshaping both sides of the cybersecurity equation heading into 2026. Attackers are increasingly using AI-assisted tools to speed up reconnaissance, identify valuable data faster, and craft more convincing social engineering attempts. Defenders, in turn, are leaning on AI-driven detection systems to spot the subtle signs of unauthorized data access before it turns into a full-scale breach.
This arms race dynamic underscores why identity security has become such a central theme. If attackers can slip past defenses using legitimate credentials, traditional malware-focused detection tools may miss the activity entirely. Alexander's comments suggest that organizations preparing for 2026 need to think less about stopping malicious code and more about monitoring who has access to what data, and how that access is being used.
What This Means For You
For everyday internet users, the rise of data-only extortion is a reminder that a company doesn't need to suffer a dramatic system outage for your personal information to be at risk. A quiet, undetected breach can expose the same sensitive records, names, addresses, financial details, health information, that a headline-grabbing ransomware attack would.
This also means breach notifications may arrive later or with less fanfare than in the past, since there's no obvious operational disruption to tip off the affected organization. Staying alert to notification emails, monitoring your accounts for unusual activity, and using strong, unique passwords with multi-factor authentication all remain your best defenses regardless of which extortion method attackers choose.
Key Takeaways
- Data-only extortion skips encryption entirely, making breaches harder to detect quickly.
- Identity security, not just malware detection, is becoming central to preventing these attacks.
- GDPR and similar regulations apply even when no ransomware payload is involved, so notification obligations remain.
- AI is accelerating both attacker techniques and defensive monitoring as organizations prepare for 2026.
- Individuals should treat breach notifications seriously and maintain strong account hygiene, since quiet data theft can be just as damaging as a visible ransomware attack.
As data-only extortion becomes a bigger part of the threat landscape, staying informed about how attackers operate, and how organizations respond, will help you better protect your own information in the year ahead.




