HomeSecurityRansomware 2026: 49% do not understand the attack before data is stolen

Ransomware 2026: 49% don't understand the attack before data is stolen

The ransomware landscape in 2026 is getting tougher – not because defenses are lacking, but because attacks are moving more “silently” and organizations often realize what’s happening when it’s already too late.

Ransomware 2026

ExtraHop has released its “ 2026 Global Threat Landscape Report ,” presenting findings from a survey of 1,800+ security and IT leaders. The figures that stand out are of immediate interest to CISOs, CIOs , and executives – and are ideal for starting a conversation about investing in detection/response.

Ransomware 2026: The shocking numbers

According to the announcement:

– Attackers had access to corporate networks for nearly 2.5 weeks on average before being detected by victims’ security teams

– 49% of organizations did not identify the threat actor before data was stolen (up from 31% last year).

– 14% only learned of the attack when they received a ransom message (up from 6% previously).

At the same time, ExtraHop notes an interesting “trade-off” from attackers:

– The average ransom payment fell to $2.8 million from $3.6 million in 2025.
– However, the percentage of victims paying rose to 83% from 70%.

Simply put: less money per victim, but more payments overall.

See also: INTERPOL: Phishing, Ransomware and AI Scams Sweep Asia-Pacific

Which “players” dominate the ransomware landscape?

ExtraHop reports that LockBit and RansomHub were the two groups with the most detections for the second year in a row. It also reports that detections related to the group APT41 decreased by 50% compared to last year.

Regardless of whether an organization “sees” all these names in its own telemetry, the message is clear: ransomware ecosystems have matured and operate almost like an “industry.”.

Ransomware 2026: 49% don't understand the attack before data is stolen

AI: New surface attack, new noise

A key point of the report is that AI adoption opens up new entry points. ExtraHop states that:

– 55% of respondents consider AI agents/agentic infrastructure/GenAI apps to be the biggest attack risk.
– 85% report having experienced an incident or data exposure related to an AI system.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This doesn't mean that "AI is bad" — but that organizations are putting new systems into production without clear governance, data controls, and monitoring.

See also: INC Ransomware: Over 830 victims since 2023

Why attacks get away: The problem of detection

ExtraHop lists reasons that delay the detection of critical alerts, such as:

– encrypted channels that bypass detection,
– activity that resembles legitimate procedures,
– use of valid high-privilege accounts,
– alert fatigue.

The “key” here is that modern attacks don’t always look like malware outbreaks. They often look like “normal” usage — until ransomware or data theft unfolds.

Ransomware 2026: 49% don't understand the attack before data is stolen

What does it mean for Greece / businesses / decision makers

For Greek businesses (especially SMEs and organizations with limited SOC), the findings translate into 3 practical conclusions:

1) Ransomware is data theft , then encryption. If you expect to figure it out at encryption, you’re lost.
2) “Silent stay” for weeks is realistic. This requires logging, centralized visibility, and incident response processes.
3) AI adoption requires security by design. Shadow AI and vendor AI integrations can open up new avenues of leakage.

See also: Conti Ransomware member pleads guilty

Practical steps for today

– Invest in visibility (logs/EDR/NDR where it makes sense) and in use cases that capture lateral movement, credential abuse and exfiltration.
– Reduce risk from privileged accounts (MFA, least privilege, PAM where possible).
– IR exercise: tabletop for “data theft + ransomware” (not just “ransomware encryption”).
– Governance for GenAI: which applications are allowed, which data, with which controls.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS