Cyber insurance and threat reporting indicate ransomware operators are increasingly leaning on data theft and extortion as organizations improve backup and recovery. Coalition’s 2025 claims data (across 100,000+ policyholders) shows business email compromise (BEC) and funds transfer fraud (FTF) dominated claims volume, while ransomware represented a smaller share but featured sharply higher initial demands (average just over $1.0M, with some as high as $16M) even as average loss severity declined—consistent with improved restoration and response reducing the leverage of pure encryption-only attacks.
In parallel, the broader ransomware ecosystem continues to reorganize rather than shrink despite sustained law-enforcement disruption of major RaaS brands (e.g., LockBit/Hive/ALPHV), with reporting citing high victim-post volumes across dozens of active operations. Halcyon reported a tactical shift among pro-Iranian/pro-Palestinian-aligned operators away from Sicarii toward BQTLock (Baqiyat 313 Locker), including promotion of “free” RaaS access via Telegram and targeting focused on the UAE, US, and Israel. Separately, ShinyHunters claimed a major theft from AI merchant-data platform Woflow (alleging internal data, PII, and transaction/order details) but provided no sample for verification at the time of reporting, while a separate SC Media piece used the SoundCloud incident (reported exposure of data tied to ~29.8M accounts) to highlight incident-response and crisis-management considerations rather than new technical findings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A newly advertised dark-web service called Leak Bazaar proposed processing data stolen by ransomware gangs into structured, searchable intelligence for sale or more targeted extortion. Researchers said the model could increase pressure on victims and enable follow-on crimes, though its practicality remained unproven.
Coalition published 2025 cyber insurance claims findings showing ransomware accounted for 21% of claims, with frequency flat and average loss severity down, even as initial ransom demands rose sharply. The report said improved backup recovery was reducing impact, but dual-extortion and data theft remained prevalent, with VPNs the most frequently targeted technology in confirmed ransomware intrusions.
ShinyHunters allegedly claimed it had compromised Woflow and stolen hundreds of millions of corporate and customer records, including internal data, PII, and transaction details. The group threatened to leak the data on March 6, while Woflow had not responded publicly and no sample was provided to verify the claim.
After Sicarii's administrator said the group could not handle a surge in affiliate requests, operators were redirected to the Baqiyat 313 Locker (BQTlock) RaaS platform. Halcyon said BQTlock was being promoted via Telegram, including free access for hacktivists targeting the 'Zionist entity.'
In late February 2026, pro-Iranian ransomware operators were pushed to use Sicarii more broadly even though the malware reportedly had defects that made decryption impossible. This marked an attempted expansion of Sicarii before operators were later redirected elsewhere.
Halcyon reported that the pro-Iran-aligned BQTlock ransomware operation had been targeting organizations in the UAE, the United States, and Israel since July 2025. The group was described as combining political messaging with double-extortion tactics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourceosintteam.blog
Open sourcehalcyon.ai
Open sourceclaimsjournal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.