Ransomware Gangs Are Rewriting Their Playbook
Ransomware has traditionally worked in a simple, if brutal, way: attackers break into a network, encrypt every file they can find, and demand payment for the decryption key. A new report from Coveware by Veeam suggests that model is quietly fading. According to the data, ransomware gangs are increasingly skipping encryption altogether and moving straight to data-theft extortion, stealing sensitive files and threatening to leak them rather than bothering to lock up systems at all.
The financial numbers in the report are striking. Average ransom payments in Q2 2026 jumped 176% to $1.88 million, even though the median payment actually fell. That gap between average and median matters. It suggests a smaller number of very large, high-value extortion cases are pulling the average sharply upward, while a broader base of smaller attacks is settling for lower payouts. In other words, attackers appear to be getting more selective and more surgical about which victims they squeeze hardest.
Why Data-Theft Extortion Without Encryption Works
Skipping encryption might sound like attackers are doing less work, but it is really a strategic shift rather than a shortcut. Encrypting an entire network is noisy, technically demanding, and increasingly easy for defenders to spot and contain, especially as organizations have gotten better at backups and recovery. If a company can restore its systems from backup, an encryption-based ransom demand loses much of its leverage.
Data theft solves that problem for attackers. Once sensitive files, customer records, financial documents, or internal communications have been copied and exfiltrated, no backup in the world can undo that exposure. The threat shifts from "pay us to get your systems back" to "pay us or we publish your data." That is a harder problem for victims to engineer their way out of, because the damage is reputational and regulatory as much as operational.
This mirrors a broader trend already documented elsewhere in the security research community. A recent Kaspersky report on the state of ransomware in 2026 found that attackers are increasingly targeting small and mid-sized businesses, often using them as a stepping stone into larger partner networks. The Coveware findings add another layer to that picture: even when gangs do go after bigger targets directly, the extortion method itself is evolving away from disruption and toward pure information leverage.
The Privacy Fallout for Businesses and Consumers
For everyday consumers, this shift matters more than it might first appear. When ransomware was primarily about encryption, the main risk to ordinary people was indirect: a hospital, school, or local government might go offline for days or weeks while systems were restored. Data-theft extortion changes the calculus entirely. The files stolen in these attacks routinely include the personal information of employees, customers, patients, or students, names, addresses, financial details, medical records, and login credentials.
Even if a targeted organization refuses to pay, or negotiates the ransom down, the stolen data can still end up published on leak sites or sold to other criminal groups. That means the people whose information was in that database face identity theft and fraud risk regardless of whether their employer or service provider ultimately paid up. The rising average payment figures in the Coveware report also hint that some organizations are willing to pay steep sums specifically to prevent that kind of exposure, which tells us how seriously companies now weigh reputational and legal fallout from leaked customer data.
What This Means For You
If you are an individual consumer, this trend is a reminder that a company's ransomware incident is not just an IT problem, it is a direct threat to your personal data even when your bank balance or account access was never touched. If you are a business owner or IT decision-maker, it means encryption-focused defenses like backups, while still essential, are no longer sufficient on their own. Data-theft extortion demands equal attention to network monitoring, access controls, and limiting how much sensitive data sits exposed and reachable in the first place.
Actionable Takeaways
Consumers should treat any breach notification seriously, even ones described as "low impact," and consider credit monitoring or fraud alerts if a service they use discloses a data-theft incident. Businesses should audit what sensitive data they actually need to store, since data that does not exist cannot be stolen. Organizations should also pressure-test incident response plans specifically for data-theft extortion scenarios, not just encryption-and-recovery drills. As ransomware gangs continue refining data-theft extortion as their primary weapon, the responsibility for reducing exposure falls on both the companies holding sensitive data and the individuals who should stay alert to how that data is used once it leaves their control.




