/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Some ransomware rings have started stealing data before they encrypt to use stolen data as leverage, ensuring that even victims with backups make the payment

Ransomware operators stealing data before they encrypt means backups are not enough.  —  Not every ransomware attack is an unmitigated disaster.

Ars Technica Sean Gallagher

Context & Ripple Effects

This is the latest escalation in a decade-long arms race that began when crypto-ransomware turned every network intrusion into a potential payday back in 2016. Since then, the payment side of the market has been exposed twice by ProPublica: data recovery firms marketing 'hi-tech' decryption while quietly paying the ransom themselves, and cyber insurers who prefer paying ransoms over funding restoration because it saves claim costs.

Exfiltration-before-encryption attacks the one defense those payment dynamics left standing: backups. If stolen data can be published or sold regardless of whether files are restored, a victim's recovery plan stops being leverage against the attacker — and the insurer-and-recovery-firm pipeline built around fast payment gets a fresh justification.

First-order effects

  • Victims with tested backups lose their walk-away option: restoring systems no longer neutralizes the threat once sensitive data is already in the attackers' hands.
  • Negotiations gain a second lever — publication risk stacks on top of downtime risk, raising the expected cost of refusing to pay for every named victim.

Second-order effects

  • Cyber insurers already inclined to pay rather than restore to save claim costs now face breach-liability exposure on top of ransom costs, further tilting their math toward settlement.
  • Data recovery firms whose business model was decryption-after-infection find their value proposition hollowed out, since recovering encrypted files does nothing about the exfiltrated copy.

Third-order effects

  • If exfiltration becomes standard practice, ransomware shifts from an availability attack to a data-breach event, dragging every incident into breach-notification obligations and regulatory scrutiny regardless of whether systems are restored.
  • Defense budgets follow the leverage: spending migrates from backup-and-restore assurance toward egress monitoring and data-loss prevention, because the asset being extorted is now the data itself.

The trend: Ransomware is evolving from encrypt-and-extort into full-scale data theft extortion, with each escalation designed to defeat the previous generation of defenses and keep the payment pipeline flowing.

Discussion

  • @amatthiesen Alexandra Matthiesen on x
    This article offers clear insight into the state of ransomware today, demonstrating the striking evolution of ransomware operator behaviors and models. https://arstechnica.com/...
  • @paula_piccard Paula Piccard on x
    “Not every ransomware attack is an unmitigated disaster. But even the most prepared organizations, it seems, can have small-scale disasters in the era of mass scans, spear phishes, and targeted #ransomware.” @arstechnica #security #cybersecurity https://arstechnica.com/...