Some ransomware rings have started stealing data before they encrypt to use stolen data as leverage, ensuring that even victims with backups make the payment
Ransomware operators stealing data before they encrypt means backups are not enough. — Not every ransomware attack is an unmitigated disaster.
Context & Ripple Effects
This is the latest escalation in a decade-long arms race that began when crypto-ransomware turned every network intrusion into a potential payday back in 2016. Since then, the payment side of the market has been exposed twice by ProPublica: data recovery firms marketing 'hi-tech' decryption while quietly paying the ransom themselves, and cyber insurers who prefer paying ransoms over funding restoration because it saves claim costs.
Exfiltration-before-encryption attacks the one defense those payment dynamics left standing: backups. If stolen data can be published or sold regardless of whether files are restored, a victim's recovery plan stops being leverage against the attacker — and the insurer-and-recovery-firm pipeline built around fast payment gets a fresh justification.
First-order effects
- Victims with tested backups lose their walk-away option: restoring systems no longer neutralizes the threat once sensitive data is already in the attackers' hands.
- Negotiations gain a second lever — publication risk stacks on top of downtime risk, raising the expected cost of refusing to pay for every named victim.
Second-order effects
- Cyber insurers already inclined to pay rather than restore to save claim costs now face breach-liability exposure on top of ransom costs, further tilting their math toward settlement.
- Data recovery firms whose business model was decryption-after-infection find their value proposition hollowed out, since recovering encrypted files does nothing about the exfiltrated copy.
Third-order effects
- If exfiltration becomes standard practice, ransomware shifts from an availability attack to a data-breach event, dragging every incident into breach-notification obligations and regulatory scrutiny regardless of whether systems are restored.
- Defense budgets follow the leverage: spending migrates from backup-and-restore assurance toward egress monitoring and data-loss prevention, because the asset being extorted is now the data itself.
The trend: Ransomware is evolving from encrypt-and-extort into full-scale data theft extortion, with each escalation designed to defeat the previous generation of defenses and keep the payment pipeline flowing.