Cybercriminals are increasingly abandoning file encryption in favor of data-theft extortion, stealing sensitive information and demanding payment to prevent its publication. A Resilience report found that 65% of extortion-related claims in H2 2025 did not involve encryption, up from 49% in H1, while by year-end only 13% of attacks relied on encryption alone. Insurers and researchers said stronger backup and recovery practices have reduced the leverage of traditional ransomware, making data exfiltration a faster, lower-risk path to monetization for attackers.
Recent campaigns illustrate the shift. Silent Ransom (Luna Moth) has targeted law firms since 2023 and reportedly extracted multimillion-dollar payments from Goodwin Procter and WilmerHale, while BlackFile/Redact used high-volume vishing and SaaS data theft against real estate, healthcare, technology, finance, and legal organizations, with Google Threat Intelligence Group estimating it collected more than $10 million between February and mid-May. Researchers warned that paying for data suppression is unreliable—30-40% of policyholders that paid still saw data leaked, sold, or shared—and urged organizations to prioritize stopping exfiltration, protect cyber-insurance information, and rehearse extortion-response decisions through tabletop exercises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group said that in July 2026 BlackFile concentrated on financial and legal targets, including private equity firms, law firms, and financial rating agencies.
Google Threat Intelligence Group said BlackFile changed focus in June 2026 to target large technology, transportation, and hospitality organizations.
Google estimated from Bitcoin transactions that BlackFile collected more than $10 million in ransom payments between February and mid-May 2026.
Google Threat Intelligence Group said BlackFile spent April and May 2026 targeting enterprises in the real estate, healthcare, and insurance sectors.
The newsletter says Reuters reported a series of attempted cyberattacks against Wall Street organizations that were linked to BlackFile, including major hedge funds and private equity firms.
The newsletter says the Cyber Risk Insurer reported that WilmerHale paid Silent Ransom an $18 million ransom in 2026.
The newsletter says the Cyber Risk Insurer reported that Goodwin Procter paid Silent Ransom a $10 million ransom in 2026.
The Risky Biz newsletter identifies BlackFile, later calling itself Redact, as a data-theft extortion group that emerged in early 2026.
Resilience said 65% of extortion-related claims it handled in H2 2025 did not involve data encryption, showing a marked increase from the first half of the year.
Resilience reported that 49% of extortion-related claims it handled in H1 2025 did not involve data encryption, indicating a growing shift toward data-theft-led extortion.
By the end of 2025, Resilience reported that only 13% of attacks relied on encryption alone, while data theft alone or combined with encryption accounted for 87% of ransomware claims.
A January report cited by Infosecurity said there were almost 1,500 extortion incidents in 2025 that relied on data theft alone.
The Infosecurity article cites a January report stating there were 28 extortion incidents relying on data theft alone in the prior year.
The newsletter cites the 2024 UnitedHealth ransomware incident as an example showing that encrypting ransomware still causes serious real-world disruption despite the rise of data-theft extortion.
The Risky Biz newsletter says Silent Ransom, also known as Luna Moth, has targeted law firms since 2023 as part of its data-theft extortion activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
news.risky.biz
Open sourcerisky.biz
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.