Data Theft Without Encryption: Why “No Ransomware Note” Doesn’t Mean You’re Safe 

Data Theft Without Encryption hero image

For years, the ransomware playbook was predictable: attackers broke in, encrypted your files, and left a note demanding payment for the decryption key. If your screens weren’t full of red warning text, you assumed you’d dodged the bullet. That assumption is now dangerously out of date. 

Threat intelligence from 2026 shows a clear and accelerating shift: attackers are increasingly skipping encryption altogether. They break in, quietly copy your sensitive data, and leave. No locked files, no ransom note, no obvious sign anything happened. Weeks later, the first indication of a breach might be an email threatening to publish customer records, financial data, or employee files unless you pay. This is extortion without encryption, and it’s rewriting the rules of ransomware defense for small and mid-sized businesses.

The Data Behind the Shift

This isn’t speculation, it’s a documented trend across multiple independent threat intelligence sources tracking ransomware trends 2026-2027. 

  • Encryption use in extortion cases is falling fast. Palo Alto Networks’ Unit 42 found that encryption was used in only 78% of extortion-related incidents in 2025, down from nearly 90% or higher between 2021 and 2024. 
  • Extortion-only attacks are climbing steadily. Google reported that pure data-theft extortion incidents rose from roughly 2% of cases in 2020 to about 15% by 2025, a staggering sevenfold increase. 
  • The trend accelerated within a single year. Cyber insurer Resilience observed extortion-only incidents jump from 49% of cases in the first half of 2025 to 65% in the second half. 
  • Kaspersky’s 2026 threat landscape review identifies “switching from data encryption to data leaks” as one of the defining ransomware trends of the year, driven directly by falling ransom payment rates. 
  • Security researchers now describe “pure extortion” as cheaper, faster, and quieter than traditional encryption-based attacks, and harder for defenders to detect, since there’s no encryption event to trip alarms. 
Ransomware trends for 2026 to 2027 infographic

Why the pivot? Because encrypting a network is loud. It triggers EDR alerts, crashes systems, and gives defenders an obvious, unmistakable signal that something is wrong. Data theft, by contrast, can look like normal outbound traffic, especially when attackers use legitimate remote access tools and cloud storage services to move stolen files, a technique known as “living off the land.” 

Why Attackers Are Abandoning Encryption

The economics have changed. Ransom payment rates have collapsed across the board: 

  • Coveware’s incident response data shows the overall ransom payment rate — across encryption, data exfiltration, and other extortion — fell to a historic low of 23% in Q3 of 2025, continuing a six-year downward trend. Payment rates for data-exfiltration-only attacks fell even further, to just 19% in the same quarter. 
  • Chainalysis found only 28% of identified ransomware victims paid in 2025, down from 62.8% in 2024 and nearly 79% in 2022. 
  • Verizon’s 2025 Data Breach Investigations Report found 64% of organizations now refuse to pay ransom demands, up from 59% the year before. 

Better backups and faster recovery have made the “pay for a decryption key” pitch far less compelling. If a business can restore from a backup in days, there’s little incentive to pay a ransom purely to unlock files. Attackers noticed and adjusted. Encrypting a system no longer guarantees payment, but threatening to leak stolen data still creates real leverage: regulatory exposure, customer lawsuits, and reputational damage that no backup can undo. As threat researchers at CyberMaxx and Morphisec have both noted, the pressure point has shifted from “restore our operations” to “protect our reputation and avoid legal fallout” and that pressure works just as well, arguably better, without a single file being touched. 

Why "No Encryption" Feels Safe — and Why That's the Trap

For business owners, the absence of a ransom note may create a false sense of security. No locked screens. No production downtime. No obvious crisis. It’s tempting to conclude that nothing serious happened, or that the incident was a minor intrusion rather than a full-blown breach. 

Data theft with no ransomware note graphic

That instinct is exactly what attackers are counting on. A quiet data theft attack can sit undetected for weeks or months; industry research puts average breach dwell time at well over 100 days for smaller organizations without dedicated monitoring. During that window, attackers can: 

  • Exfiltrate customer records, financial data, employee PII, and intellectual property 
  • Sell that data on dark web marketplaces even if the ransom is never paid 
  • Return later with a second extortion attempt using the same stolen data 
  • Trigger regulatory breach-notification obligations the business doesn’t even know it has yet 

This is why the “no ransomware note” myth is so dangerous for small and mid-sized businesses in particular. SMEs are already disproportionately targeted, roughly 43% of all cyberattacks are aimed at small and mid-sized businesses, according to industry breach data, and the average cost of a full data breach for organizations under 500 employees runs into the millions once legal, notification, and remediation costs are included. Most SMEs lack the security operations maturity to detect a quiet exfiltration event, and many discover the breach only when a leak site, or a customer, tells them first. 

Rethinking Your Defense Strategy

The traditional ransomware defense checklist: backups, patching, endpoint protection, is still necessary, but it’s no longer sufficient on its own. Backups solve the encryption problem. They do nothing to stop data that’s already left the building. Defending against extortion without encryption requires a different set of priorities: 

  1. Detect exfiltration, not just encryption. Monitoring needs to flag unusual outbound data transfers, large or unusual file access patterns, and use of remote access tools, not just wait for encryption-triggered alerts. 
  2. Assume credential theft is the entry point. Most quiet data-theft intrusions start with compromised credentials or phishing, not malware deployment. Multi-factor authentication and credential monitoring matter more than ever. 
  3. Reduce dwell time with active threat hunting. The longer attackers sit undetected, the more data they can move. Continuous monitoring and managed detection and response (MDR- link to page) shrink that window dramatically compared to periodic security reviews.  
  4. Build an incident response plan that covers data-theft-only scenarios, not just encryption-and-recovery playbooks. Legal notification requirements, PR response, and negotiation strategy differ significantly when there’s no downtime but real exposure risk. 
  5. Monitor leak sites and dark web marketplaces proactively. In many cases, the first confirmed sign of a breach is a listing on a leak site, businesses that monitor these sources catch incidents earlier than those waiting for an extortion email.  

Staying Ahead of the Curve

The shift toward encryptionless extortion is one of the clearest signals yet that ransomware defense has to evolve beyond “can we restore from backup?” At CyberClan, we’ve built our incident response and managed detection services around this shifting reality, treating data exfiltration as seriously as encryption, hunting for the quiet signals attackers hope you’ll miss, and helping businesses respond to extortion threats whether or not a single file was ever locked. 

The absence of a ransom note isn’t proof you’re safe. Increasingly, it’s proof the attackers just got smarter about not leaving one. 

Learn more about CyberClan's Incident response services

Under Attack? Guaranteed 15 minute response time.

Please call our emergency hotline below or fill out the form with your name, email, and phone number.

US/CAD

1 800 762 3290

UK

0800 368 8731

AUS

61 1800 413 128

Email

response@cyberclan.com

The information you provide in this form is only used exclusively to assist you. We do not share your data.

Sugandha Sood

Executive Vice President, Finance

As a professional accountant Sugandha, CPA, CGA has over 15 years of progressive finance and accounting experience across multiple industries including healthcare, medical, nuclear waste, and transportation.

Prior to joining CyberClan she worked at Energy Solutions Canada and was responsible for various aspects of accounting, financial reporting, internal controls, process improvements and taxation. Sugandha is eager to leverage her professional skills and play a vital role in the growth of the company by providing information to make informed decisions.