Cybercriminals shift from ransomware to data theft

Quorum Cyber has published research indicating that cybercriminals are shifting from traditional ransomware to data theft and extortion. The analysis draws on threat intelligence gathered during the first half of 2026.

The Edinburgh-based cyber security company said attackers are increasingly choosing to steal sensitive information, identities and cloud access rather than encrypt systems. Its mid-year review found that criminals can now profit through extortion, resale and follow-on attacks without deploying ransomware.

The findings point to a shift in the economics of cybercrime. Once attackers gain trusted access through stolen credentials, phishing, compromised cloud identities or insider manipulation, their main objective is often to extract valuable data rather than disrupt operations.

That information can include customer records, intellectual property, source code, cloud credentials and software-as-a-service identities. Many organisations still focus most of their defences on preventing encryption-based ransomware, leaving them less prepared to detect or stop large-scale data exfiltration.

Shift in tactics

Researchers said attackers are relying less on malware deployment and more on methods that exploit legitimate access. These include buying compromised credentials, recruiting insiders, abusing help desk processes, stealing authentication tokens and targeting cloud environments before quietly removing sensitive information.

The report also suggests that ransomware groups are becoming more commercially structured. Some are moving to extortion-only models because they believe companies may fear regulatory scrutiny, customer notification duties and reputational damage more than short-term operational disruption.

Others are using more formal negotiation tactics to increase the chances of payment. This marks a further step away from the earlier model, in which system encryption was the central means of pressure.

Jack Alexander, Global Intelligence Lead at Quorum Cyber, said the close link between ransomware and cybercrime over the past decade is starting to weaken.

“In the last 10-12 years ransomware has become synonymous with cybercrime, but we’re seeing a significant change in attacker behaviour. Increasingly, cybercriminals don’t need to encrypt systems to achieve their objectives. If they can steal an organisation’s most valuable data, they already have the leverage they need,” Alexander said.

His assessment places data at the centre of the current threat environment. The report argues that information itself has become a direct source of criminal revenue, whether through blackmail, sale to other threat actors or use in later intrusions.

“Data has become the more valued currency of cybercrime. Once attackers gain trusted access through compromised credentials, phishing or social engineering, their priority is increasingly to identify what information they can take before they’re detected. That data can then be used for extortion, sold to other threat actors or exploited in follow-on attacks,” Alexander said.

Identity focus

A core theme in the research is the growing importance of identity in cyber attacks. Rather than forcing entry through noisy malware campaigns, attackers are seeking access that appears legitimate within cloud services and software platforms.

That trend reflects wider changes in corporate technology estates as businesses place more operations, users and data in cloud systems and software subscriptions. In that environment, compromised credentials or hijacked authentication tokens can give intruders a path to sensitive information without immediately triggering alarms designed for older ransomware patterns.

This leaves defenders facing a broader challenge than system recovery alone. Detecting abnormal access, monitoring data movement and protecting sensitive information are becoming as important as blocking encryption-based attacks.

Quorum Cyber also linked the trend to wider adoption of cloud services, SaaS platforms and artificial intelligence tools, which can increase both the volume of valuable data and the number of access points that need to be secured.

“The findings reflect a significant change across the threat landscape, and identity, trust and data are now the primary targets for financially motivated cybercriminals. As organisations continue to adopt cloud services, SaaS platforms and AI-powered tools, protecting sensitive information and detecting abnormal access is becoming increasingly important alongside traditional cyber defences,” Alexander said.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *