Unit 42 published a fresh look at the extortion economy this week, and the headline finding is the one defenders keep missing: the people robbing your network mostly stopped bothering with encryption. There’s no countdown timer painted across your endpoints. There’s no neon-green ransom note. There’s just a quiet email a week later, attaching twelve files you wish nobody had, asking for money. That’s the cybersecurity reality of 2026, and most detection programs are still built around the old movie.

Unit 42 illustration depicting the modern cyber extortion economy
Unit 42’s 2026 extortion economy report tracks the shift from encryption to pure data theft.

The crews dropped the loud half of the playbook

The economics finally caught up. Encrypting a fleet is noisy, expensive in tooling, and triggers every EDR alarm you bought. Dragging out a few hundred gigabytes of customer records and threatening to publish them is quieter, cheaper, and works whether or not the victim has backups. Unit 42 reports double-extortion shrinking into single-vector data-theft extortion across the major affiliate programs.

The banking-trojan world is showing the same evolution from a different angle. WatchGuard and ESET this week documented parallel Grandoreiro and BTMOB campaigns targeting Spain, Portugal, Mexico, and Brazil across Windows and Android. Neither malware family encrypts anything. Both are pure exfiltration: session cookies, banking credentials, two-factor seeds, contact lists, anything monetizable. That’s the same operating model the ransomware affiliates have adopted, just aimed at retail customers instead of enterprises.

Encryption was always the part of the attack chain defenders were best at detecting. Mass file rewrites, shadow copy deletion, ransom note creation – all of these light up behavioral rules that have been mature for years. Quietly walking 80GB out the back door over six weeks lights up almost nothing.

Why your cybersecurity stack still watches for the wrong movie

Walk into most SOCs and you’ll find detection content stacked deep on encryption behaviors, ransom note artifacts, and lateral movement immediately before payload detonation. Those rules aren’t wrong. They’re just defending against the smaller half of the threat now.

Talos’s release of EvidenceForge this week, a tool that generates realistic synthetic security logs for detection training, makes the gap visible. The reason analysts need synthetic data in the first place is that nobody has good labelled examples of slow, quiet, exfiltration-only intrusions. Encryption-era datasets are everywhere. Twelve-week silent egress campaigns are not. You can’t tune what you can’t see, and you can’t see what hasn’t been collected.

Layer the AI dimension on top of that. The UK’s GCHQ director went on record this week calling AI “an unstoppable force” and warning that Russia is operating aggressively in the gray zone below the threshold of war. Whatever you think of the politics, the operational point is real: extortion crews now have AI helping them triage stolen data, identify the most damaging files faster, draft tailored extortion notes, and run negotiation chats at scale. The attacker’s per-incident labor cost is dropping while their hit rate goes up. Your defense budget did not.

What actually moves the needle

You don’t need to rip out your existing threat-protection stack. You need to rebalance it toward the threat that’s actually present. The shift is from “stop the payload” to “see the data leave.” That’s a different set of telemetry, a different set of detections, and a different incident response runbook.

Concrete things to do this quarter, ranked roughly by impact-per-effort:

  • Inventory your data egress paths. Every cloud bucket, every SaaS export endpoint, every developer pipeline that touches production data. If you can’t list them, you can’t watch them. Most teams discover three or four they forgot existed.
  • Baseline outbound volume by host and identity. A workstation that suddenly emits 4GB to a residential ASN over a weekend isn’t subtle once you have the baseline. Without the baseline, it’s invisible.
  • Alert on first-seen destinations. Modern extortion crews rotate exfiltration domains constantly. A first-seen egress to a six-month-old domain at 2am is one of the cheapest, highest-signal detections you can deploy.
  • Cut session lifetimes aggressively. Banking trojans and enterprise extortion crews both depend on stolen session tokens. If your sessions live for two weeks, you’re paying for that convenience in incidents.
  • Block brute-force at the edge. Tools like fail2ban or IPBan close the credential-stuffing door that often opens the initial foothold. The crews moved upstream, but the front door still matters.
  • Rehearse the data-theft-only IR scenario. Run a tabletop where there’s no ransom note, no encryption, just a journalist calling at 4pm Friday with a sample of your customer data. Your existing playbook probably wasn’t built for that opening.
  • Apply defense in depth to the exfil path specifically. Proxy enforcement, DNS filtering with logging that’s actually reviewed, DLP rules tuned for volume rather than content matching, and egress-only firewall rules per segment. Each layer is imperfect; together they make slow exfiltration loud.

None of this is exotic. It’s the unglamorous security hardening that nobody puts on a conference keynote, and it’s what actually changes outcomes when the next campaign hits.

The geopolitical layer nobody owns

Cloudflare confirmed this week that Iran’s internet is partially restored after a three-month shutdown, sitting around 40% of pre-shutdown levels. That sounds like a foreign-policy story until you remember how state-aligned extortion crews exploit exactly these windows. Infrastructure churn means traffic looks weirder than usual, baselines get noisier, and detection thresholds tend to drift wider to suppress alert fatigue. Crews count on it.

The UK warning about Russia and the Romanian sentencing this week of the Oregon Office of Emergency Management hacker bracket the same point from opposite directions. The talent pool for data-theft extortion is global, mobile, and rented by whoever pays. Arrests happen. Operations don’t slow down. The Oregon case took two years from compromise to sentence, and the crew kept working through every minute of it.

Threat detection, threat intelligence, and incident response programs were built assuming you’d see the loud, fast, encryption-shaped attack. The economy moved on. The crews are quieter, leaner, and increasingly AI-augmented. Your detection content, your IR playbooks, and your tabletop exercises should reflect what the attackers are actually doing in 2026, not the highlight reel from 2021.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.