Ransomware gangs are changing their playbook, and small businesses are paying the price twice over. Kaspersky's newly released State of Ransomware 2026 report finds that attackers are increasingly skipping encryption altogether in favor of encryptionless extortion, where stolen data rather than locked systems becomes the primary source of leverage. For smaller companies with limited security budgets, this shift matters for a reason that goes beyond their own operations: it turns them into entry points for attacks on the larger organizations they work with, making small business ransomware supply chain risk a growing concern for enterprises everywhere.

What Encryptionless Extortion Means for Small Businesses

Traditional ransomware attacks followed a predictable pattern. Criminals would infiltrate a network, encrypt files, and demand payment for a decryption key. That model required attackers to lock a victim out of their own systems, which often triggered immediate detection and response.

Kaspersky's report describes a quieter and, in some ways, more dangerous approach. Instead of encrypting data, attackers quietly copy confidential files, customer records, financial documents, contracts, and internal communications, then threaten to leak or sell that information unless the victim pays. There is no crashed server or frozen workstation to alert IT staff. The breach can go unnoticed for weeks, giving criminals time to study what they have stolen and decide how best to monetize it.

For small businesses, this is a particularly awkward threat. Many lack dedicated security teams capable of spotting slow, stealthy data exfiltration, and the absence of an obvious system outage means the attack can be well underway before anyone notices anything wrong.

Why SMBs Are the Weak Link in Corporate Supply Chains

The Kaspersky report's most significant finding for the broader business world is that small businesses are not just victims in isolation. They are frequently the weakest link connecting criminals to much larger targets. A small vendor, contractor, or service provider often holds credentials, network access, or sensitive data belonging to bigger corporate partners, but rarely has the same layered defenses those partners maintain.

Attackers understand this asymmetry. Rather than trying to breach a well-defended enterprise directly, it is often easier to compromise a smaller supplier first, then use that foothold or stolen data to pivot toward the larger organization down the chain. This is precisely the dynamic already playing out with active ransomware operations. Groups like Qilin and The Gentlemen have been escalating attacks specifically targeting small and mid-sized businesses, using them as a springboard rather than a final destination.

How Data Theft Differs From Traditional Ransomware Risk

The practical implications of encryptionless extortion are different from classic ransomware in several important ways. First, recovery is no longer just about restoring backups. If your data has already been copied, having a clean backup does not undo the exposure, the information is still out there and can still be leaked or sold regardless of whether operations are restored.

Second, the pressure tactics shift. Instead of a countdown clock on decrypting files, victims face the threat of public disclosure, regulatory penalties, and reputational damage from leaked customer or partner data. Third, and most relevant for supply chain risk, stolen data from a small business can include access credentials, shared drives, or communications that reveal exactly how to reach a larger partner organization. The small business becomes not just a victim, but effectively a map for the next attack.

Practical Steps: VPNs, Segmentation, and Data Minimization for SMBs

Small businesses do not need enterprise-level budgets to meaningfully reduce this risk. A few practical measures go a long way. Using a reputable VPN for remote access and secure external connections helps ensure that credentials and traffic are not exposed to interception, particularly for teams that regularly log into partner systems or share sensitive files remotely.

Network segmentation is equally important. Keeping systems that handle sensitive partner data separate from general office networks limits how far an attacker can move once inside. Data minimization also matters: businesses should regularly review what sensitive information they actually need to store, especially data belonging to larger clients, and delete or archive what is no longer necessary. The less there is to steal, the less leverage an attacker has.

What This Means For You

If you run or work for a small business, the takeaway from Kaspersky's report is not that you are a bigger target than large enterprises, but that you may be a more convenient one. Attackers are betting that smaller organizations have less monitoring, fewer resources, and slower detection times. If your business handles data or system access on behalf of larger partners, that relationship itself is now part of your threat model, and treating security as solely an internal concern is no longer enough.

Final Thoughts

The shift toward encryptionless extortion documented in Kaspersky's State of Ransomware 2026 report is a reminder that small business ransomware supply chain attacks are no longer a niche concern, they are a direct pathway into the networks of much larger companies. Strengthening basic defenses, securing remote access, segmenting sensitive systems, and minimizing stored data can meaningfully reduce that exposure. For a closer look at how these attacks are unfolding on the ground, read more about how Qilin and The Gentlemen ransomware gangs are escalating attacks on small businesses and what it reveals about the tactics criminals are using right now.