For years the advice about ransomware ended in the same place: keep good backups and you can refuse to pay. It was solid advice, and a growing share of attacks have quietly moved past it.
Increasingly, attackers do not encrypt anything. They break in, spend time finding what matters, copy it out, and then contact you — not to sell a decryption key, but to be paid for not publishing what they took.
Why the shift makes sense for them
Encryption is loud. It stops systems, triggers alerts, and forces a response. Theft can be silent for weeks. It also avoids the part attackers found least profitable: rebuilding a business that could restore itself anyway.
And the leverage is different in kind. A restore fixes encrypted files. Nothing fixes a client list, an employee file, or a set of contracts that is already in someone else’s hands. Your backups are irrelevant to that conversation, which is precisely the point.
What this changes for your defenses
Backups still matter enormously — plenty of attacks still encrypt, and a business that cannot restore is in trouble regardless. But protecting against theft asks different questions.
Can you see data leaving? Encryption announces itself. Exfiltration looks like ordinary network traffic unless something is watching for volume, destination, and timing that do not fit the pattern.
How long could someone stay unnoticed? The gap between first access and discovery is where this attack lives. Shrinking it from weeks to hours is worth more than almost any single product.
How much can one account reach? Theft is bounded by access. A compromised account that can read three folders takes three folders. This is the same argument as segmentation and least privilege, arriving from a different direction.
Is the sensitive material identifiable? Businesses are routinely surprised by where regulated data has accumulated — old exports, a shared drive, someone’s mailbox. You cannot protect what you have not located.
Would encryption at rest actually help? Sometimes yes, often not: if the attacker has a valid account, they read the data decrypted, exactly as your staff do. It is worth knowing which of your systems fall into which category.
The obligations arrive whether you pay or not
This is the part that catches businesses out. Once data has left, you may have notification duties to clients, regulators, or insurers, and those duties are not canceled by paying. A payment buys a promise from a criminal not to publish; it does not undo the disclosure or return the copies.
Which means the decisions that matter get made in advance: knowing what you hold, who must be told, how quickly, and by whom. Working that out during the incident is how a bad week becomes a bad quarter. Our compliance work and continuity planning exist to have those answers on the shelf.
What to do about it
Nothing exotic: reduce what an intruder can reach, watch for the quiet phase rather than only the loud one, know where your sensitive data lives, and rehearse the notification path alongside the technical recovery.
If you would like to know how visible this kind of activity would be on your network today, that is worth a conversation.