Ransomware gangs are changing their playbook, and the shift matters for every business that stores customer data, not just the ones that get hit with headline-grabbing encryption attacks. A new report from Coveware by Veeam, covering the second quarter of 2026, shows a clear and growing preference among criminal groups for pure data-theft extortion over the traditional lock-and-ransom approach. The findings point to a ransomware data-theft extortion trend that is reshaping how attackers operate and, just as importantly, how defenders need to respond.
What the Coveware Q2 2026 Report Reveals
According to the report, average ransom payments in Q2 2026 rose 176% to $1.88 million, even though the median payment actually declined during the same period. That gap between average and median is telling. It suggests a smaller number of very large payouts are pulling the average upward, likely tied to high-value targets willing to pay big sums to keep stolen data out of public view. Meanwhile, more routine cases are settling for smaller amounts, or victims are refusing to pay at all.
The bigger structural change is the move away from encryption entirely. Rather than locking up files and demanding payment for a decryption key, more groups are simply stealing data and threatening to leak it. This approach skips the noisy, disruptive step of encrypting systems, which can trigger faster detection and recovery efforts. Pure extortion is quieter, harder to detect in real time, and still gives attackers powerful leverage, especially against organizations handling sensitive customer or employee records.
How Silent Ransom and Scattered Spider Get In
The report names groups like Silent Ransom and Scattered Spider as leading examples of this shift, and their method of entry is at least as important as their extortion strategy. Both groups have leaned heavily on help desk social engineering, meaning they don't need to exploit a software vulnerability at all. Instead, they call or message IT support, impersonate legitimate employees, and talk their way into password resets or multi-factor authentication bypasses.
This is a fundamentally different threat model than the malware-laden phishing emails many organizations have trained staff to spot. It targets human trust and internal processes rather than technical weaknesses. A convincing phone call to a help desk, paired with basic details scraped from social media or previous breaches, can be enough to gain a foothold. From there, attackers move laterally, locate valuable data, exfiltrate it, and then make their extortion demand, all without ever needing to deploy ransomware payloads that antivirus tools might catch.
Why VPNs and Network Security Alone Fall Short
This is where the limits of traditional network security become obvious. A VPN can encrypt traffic and hide a user's location, and zero-trust network access can restrict who reaches which systems, but neither one verifies whether the person on the other end of a help desk call is actually who they claim to be. If an attacker successfully social engineers their way past identity verification, they can walk through the same secure tunnels and access controls that were built to keep outsiders out.
That's not a reason to abandon VPNs or zero-trust architecture. Those tools remain essential for encrypting data in transit and limiting blast radius once an intruder is inside. But the Coveware findings underscore that identity verification, not just network perimeter defense, has become the weak link attackers are exploiting. Organizations need stronger help desk verification procedures, callback protocols, and out-of-band confirmation before granting password resets or access changes, especially for accounts with elevated privileges.
What This Means For You
For small and mid-sized businesses, this trend is particularly relevant. Attackers increasingly favor targets that may lack dedicated security operations teams but still hold data valuable enough to extort. The pattern shows up repeatedly in real incidents. The Play ransomware attack on Barrett Mahony Consulting Engineers illustrates how a mid-sized professional services firm can become a target regardless of its size. Similarly, Cisco Talos' research on rising ransomware activity in Japan found that small and medium enterprises are absorbing much of the increase in attacks, reinforcing that this isn't just a problem for large enterprises with deep pockets.
Consumers aren't off the hook either. When companies get hit with data-theft extortion, the stolen information (names, financial details, sometimes government IDs) often ends up posted or sold regardless of whether a ransom is paid, as seen in cases like the Deadlock ransomware leak of LT Group passport data. That means personal vigilance around credit monitoring and password hygiene matters even when you weren't directly targeted.
Actionable Takeaways
Businesses should audit help desk verification procedures now, since a phone call or chat message is an increasingly common entry point rather than a rare edge case. Multi-factor authentication resets and privileged access changes deserve extra scrutiny, including callback verification through a known, separate channel. Employees at every level, not just IT staff, should understand that social engineering attempts can target support desks just as easily as inboxes.
For everyday users, the practical steps remain familiar but urgent: use unique passwords, enable multi-factor authentication wherever it's offered, and monitor accounts for unusual activity after any company you interact with discloses a breach. The ransomware data-theft extortion trend documented in Coveware's Q2 2026 report shows that attackers are adapting faster than many defenses, which makes layered security, spanning technical controls and human verification alike, more important than ever.




