Many businesses still fear ransomware attacks. But is this threat still as relevant today? A few years ago, at the peak of ransomware’s popularity, the term “ransomware” was practically synonymous with malicious encryption of data. But in reality blocking access to information had long been little more than a symbolic gesture. In a May Securelist post on shifts in the ransomware threat landscape, our experts noted that in 2026, attackers are encrypting company data for ransom less and less frequently. Here’s a striking example: while investigating an incident, Kaspersky’s Global Emergency Response Team (GERT) uncovered the PAYLOAD extortion campaign, whose operators didn’t even bother using ransomware. They took a different route instead.
In this campaign, instead of using ransomware, the attackers seized control of the Active Directory environment, and created a malicious group policy object (GPO). They used it to deploy a ransom note, change wallpapers, and lock screens on workstations, and set up a banner to display at system login. Naturally, they also disabled local administrator accounts while they were at it. This move let the attackers demonstrate their presence in the compromised infrastructure and prove they’d accessed confidential information — just as effectively as encryption would have. Detailed information about this incident, along with indicators of compromise, can be found in the same Securelist post. What interests us more, though, is the trend of abandoning encryption.
Why data encryption has lost relevance
Let’s start with the fact that in a large company with thousands of infected computers, decrypting data is an extremely effort-intensive process. Restoring data from backups, which has become common practice largely thanks to mass ransomware attacks, is far easier than waiting for criminals to hand over a key, hoping it’s genuine, and trusting that the ransomware itself didn’t have bugs that made the data unrecoverable. As a result, cybercriminals found it harder and harder over time to actually collect a ransom for the decryption key.
Attackers tried to adapt to this shift. Alongside encryption, they increasingly began stealing confidential data and threatening to publish it. Publishing confidential information puts a company’s reputation, its security, and the safety of its business partners at risk. This is especially true if the data includes people’s personal information: more than 140 countries around the world have data protection laws, so a leak puts an organization at a fairly high risk of a hefty fine. Sometimes that’s far scarier than simply losing data, and no backup can help with that.
Data exfiltration has another advantage from the attackers’ perspective: it’s usually much harder to detect than malware activity. File encryption, for instance, triggers a spike in disk activity that endpoint protection tools pick up fairly quickly. By contrast, data exfiltration is easy to disguise as normal traffic. This is precisely what the ShinyHunters group exploits, building its attacks around the standard OAuth mechanism. On top of that, attackers can steal data much quicker if they don’t bother with encryption, which also makes it harder to catch the threat in time.
As a result, encryption has become a kind of calling card — proof that the attackers had access to the data. So cybercriminals finally decided to drop this optional step altogether.
What businesses should do
Standard cyberhygiene practices can help protect against a wide range of extortion schemes — regardless of whether or not they involve encryption:
- Run regular, automatic backups. By storing backups on two types of media — physical and cloud — a business need not fear serious disruption to its operations. After all, the downtime required to restore from backups is nothing compared with the consequences of losing all of its data.
- Install patches and updates promptly. For attackers, vulnerabilities remain one of the main entry points into infrastructure. To reduce the risk, we recommend setting up automated update management for operating systems, software, and drivers. It’s also important to scan systems regularly for security gaps, and triage the found vulnerabilities with a focus on critical flaws. Specialized vulnerability management solutions can help with this.
- Strengthen endpoint protection. Set up multi-factor authentication for every system in an infrastructure, and deploy a reliable workstation and server security solution. A SIEM or EDR solution can help security specialists gain full visibility into events, and respond to incidents quickly.
- Monitor external perimeter. Regularly check the company’s infrastructure (servers, databases, clouds, and legacy subdomains) for open ports and services exposed to the internet.
- Adhere to the principle of least privilege. This means giving users, systems, and processes only the access privileges they need to do their jobs. Revoke unused privileges, and fully disable access for former employees.
- Invest in staff training. Attackers still exploit the human element to break into a company’s infrastructure. Raising threat awareness among employees can keep them from falling victim to phishing.
Ransomware
Tips