Why Ransomware Attacks Now Center on Data Theft, Not Encryption

For years, the standard ransomware playbook was simple: break in, encrypt files, demand payment for the decryption key. Backups were the answer. Restore your systems, ignore the ransom note, move on. That playbook is largely obsolete.

Today's ransomware groups have adapted to the fact that many organizations recover from encryption just fine. So they've shifted the leverage. Before locking anything down, attackers now quietly copy sensitive files, financial records, employee data, client information, off the network. Encryption has become almost secondary, sometimes skipped entirely. The real threat is a public leak site where stolen data gets posted if payment isn't made. This is the ransomware data extortion threat that security researchers have been tracking closely, and it changes what "being prepared" actually means for organizations of every size.

The pattern isn't isolated to any one region or industry. Reporting on ransomware incidents in India, for example, found that a majority of attacks now involve data theft rather than pure encryption, according to Proofpoint's analysis of ransomware activity there. The same dynamic is playing out closer to home, including in the St. Louis metro area.

What's Known About the St. Louis-Area Incidents

According to reporting from CHR Solutions, a St. Louis-based IT and cybersecurity firm, ransomware has struck school systems, city networks, and local businesses in the metro area within just the past few months. The firm, which works directly with regional organizations to close security gaps, frames this as a local and recurring problem rather than a distant headline. Specific details on individual incidents are limited in the available reporting, but the pattern described mirrors what's happening nationally: public-sector networks and small-to-midsize businesses are frequent targets, often because they have fewer dedicated security resources than large enterprises.

School districts and municipal networks are particularly attractive targets for extortion-based attacks. They hold large volumes of personal data, including records on students, employees, and residents, and they often face public pressure to avoid disruption, which can make them more likely to negotiate. When attackers know the leverage isn't just "can you function without your files," but "can you afford to have this data published," the pressure to pay increases significantly.

How Double Extortion Changes the Calculus for Small and Mid-Sized Businesses

Double extortion, encrypting systems while also threatening to leak stolen data, fundamentally changes the risk equation for smaller organizations. A business with solid, tested backups used to have a clear path to recovery: restore and rebuild. But backups don't stop a leak site from posting customer contracts, employee Social Security numbers, or proprietary business data.

This matters enormously for small and mid-sized businesses that may assume backups alone constitute a ransomware defense. A recent example of how these leak threats play out in practice involves the Play ransomware group's claimed attack on Kreysler & Associates, where the group followed its typical operating model of threatening to publish stolen data rather than relying solely on encryption to force payment. Cases like this illustrate that the negotiation leverage attackers hold has moved from "we locked your systems" to "we have your data and we will release it publicly." That's a reputational, legal, and regulatory risk that backup restoration simply cannot fix.

For smaller organizations without dedicated security teams, this shift means incident response planning needs to account for data exposure scenarios, not just system downtime.

Practical Hardening Steps That Address Extortion Risk

Backups remain essential, but they're no longer sufficient on their own. Organizations serious about reducing extortion risk should focus on a few areas that go beyond traditional disaster recovery:

  • Limit what attackers can steal. Reduce data retention where possible and segment networks so a single compromised account doesn't provide access to everything.
  • Monitor for exfiltration, not just encryption. Detection tools that flag unusual outbound data transfers can catch an attack before files leave the network, which is often earlier than encryption-focused monitoring would catch it.
  • Strengthen identity controls. Multi-factor authentication and tightly managed privileged accounts remain among the most effective barriers against the initial access attackers need to steal data in the first place.
  • Build an incident response plan that addresses leak threats. Legal, communications, and regulatory notification steps should be mapped out before an attack happens, not during one.

What This Means for You

If your organization's ransomware plan still centers primarily on backup and restore procedures, it's addressing yesterday's threat. The ransomware data extortion threat means the real risk is often what attackers already copied before you even noticed a problem. This applies whether you're a school district, a municipal office, or a small business handling customer data. Assuming you're too small to be a target is no longer a safe bet; smaller organizations are frequently chosen precisely because they have fewer defenses in place.

Key Takeaways

  • Ransomware attacks increasingly prioritize data theft and leak threats over pure encryption, a pattern seen both regionally and internationally.
  • Recovering from encryption with backups does not eliminate the risk of stolen data being published.
  • Small and mid-sized organizations, including schools and municipal networks, remain frequent targets due to limited security resources.
  • Effective defense now requires monitoring for data exfiltration, tightening access controls, and planning incident response around the possibility of a public leak, not just system downtime.