For years, ransomware was synonymous with file encryption . Attackers would lock down victims’ systems and demand a ransom to restore access. But today, the landscape is changing dramatically. More and more cybercriminal groups are abandoning encryption and turning to a quieter but equally destructive model : extortion data .

From ransomware to data extortion
In the data extortion model, attackers are not necessarily interested in disrupting an organization. Instead, they focus on stealing sensitive data — personal information, financial data, intellectual property, or confidential documents. They then threaten to publish or sell that data if the victim does not pay.
See also: MacSync Stealer bypasses Apple's malware protections
The absence of encryption reduces the noise of the attack and increases the chances of success. Many businesses don't even realize they've been compromised until they receive the ransom message.
Why attackers are abandoning encryption
File encryption is starting to lose its effectiveness. Organizations are now investing in backups, recovery plans, and incident response exercises. In many cases, victims can restore their systems without paying.

In contrast, the threat of data breaches touches on nerves that backups cannot cover: legal penalties, GDPR fines, loss of customer trust, and serious reputational damage. For criminals, this translates into greater pressure and higher payout rates.
How data extortion attacks are carried out
Attacks typically begin with credential compromise, phishing, or exploiting vulnerabilities in VPNs, email servers, and cloud services. Once they gain access, attackers move discreetly through the network, targeting critical systems and storage.
Data extraction is done gradually, often after hours, to avoid triggering detection mechanisms. In many cases, the attackers have already left the network when the extortion begins.
The psychology of blackmail
Unlike traditional ransomware, data extortion relies more on psychological pressure. Threat groups often provide “samples” of the stolen data to prove their credibility. Other times, they publish a small portion of the files on leak sites, increasing the sense of urgency.
See also: OAuth device code phishing: New technique for compromising Microsoft 365 accounts
Blackmail can target not only the company, but also customers, partners or even executives, intensifying fear and pressure for payment.
Which organizations are being targeted?
No industry is left untouched. Healthcare, education, finance, technology and the public sector are often targeted due to the value and sensitivity of the data they manage. Companies that rely heavily on cloud infrastructure and third-party providers, without adequate access control, are particularly vulnerable.

How can businesses defend themselves?
Tackling data extortion requires a change in mindset. Protecting against file encryption. Organizations must focus on data loss prevention, access control , and monitoring outbound traffic.
Technologies like Zero Trust , Data Loss Prevention (DLP) tools , and user behavior analysis can identify suspicious actions before they escalate into a crisis. At the same time, staff training and a clear incident management plan are crucial.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities
The future of digital blackmail
Data extortion is not just a trend; it is the new normal. As defenses strengthen, attackers are adapting, choosing methods that directly target trust and reputation. The real question for businesses is not whether they will face such a threat, but whether they are prepared to deal with it without succumbing to extortion.
