Cybersecurity

Data-Only Extortion Is the New Ransomware: What Changes for Your Backup and IR Plan

TuniCyberLabs Team
7 min read

Attackers increasingly steal data without encrypting it, so backups restore operations but not confidentiality. Here is how encryption-less extortion changes your backup strategy, exfiltration detection, and incident-response plan, and why paying rarely solves anything.

What is data-only extortion, and how is it different from ransomware?

Data-only extortion (also called exfiltration-only or encryption-less extortion) is an attack where criminals steal your data and threaten to leak or sell it unless paid, but never deploy encryption. There is no locked file to decrypt; the leverage is confidentiality and reputation, not availability.

Differences that matter for defenders:

  • No encryption event to trip alarms. Classic ransomware announces itself by mass-encrypting files; pure extortion is quiet until the demand arrives.
  • Backups do not neutralize the threat. You can restore operations, but you cannot un-leak stolen records.
  • Speed and stealth win. Groups like Cl0p industrialized this by exploiting managed file-transfer software (MOVEit, GoAnywhere, Cleo) to bulk-steal data from many victims at once, per public reporting.

Public reporting also notes groups such as BianLian and Hunters International shifting toward data-theft-only operations, dropping encryption entirely.

Why are ransomware payments falling while attacks rise?

Fewer victims are paying, yet the number of attacks and named victims keeps growing. Per public reporting from incident responders and blockchain-analysis firms, the share of ransomware victims who pay has declined for several years, pushing total ransom revenue down even as attack volume climbs.

Why the divergence:

  • Better preparedness. More organizations have tested, immutable backups, so encryption-based leverage is weaker.
  • Law-enforcement pressure and takedowns raised the operational cost for some groups.
  • Sanctions risk. Paying certain groups can violate OFAC sanctions, and insurers and counsel increasingly advise against it.

Criminals adapted by dropping the expensive, noisy encryption step and monetizing pure data theft instead: attacks up, encryption down. The economics behind this shift are worth understanding, see Dark Web Economics: Reading the Criminal Balance Sheet.

Why will backups not save you from data-only extortion?

Backups restore availability, not confidentiality. When the attack is theft rather than encryption, a perfect restore changes nothing about the criminals' leverage, they still hold your data. Backups remain essential, but they stop being your primary answer to extortion.

  • The harm is disclosure. Leaked customer PII, source code, contracts, or health records cause regulatory, legal, and reputational damage that no restore reverses.
  • Restore speed is irrelevant to the threat. Your RTO and RPO protect operations; they do nothing for a data-leak-site countdown.
  • You may not even have downtime. Many victims first learn of the breach from the extortion email, not from an outage.

This does not make backups optional, see Ransomware Resilience in 2026: Backups That Actually Restore, Faster Detection, and Recovery You Can Prove. It means backups are now table stakes for a different failure mode.

What must change in your backup strategy?

Keep immutable, tested backups for availability, but re-weight investment toward preventing and detecting exfiltration. The backup conversation shifts from can we restore to can we prove what left, and limit what was worth stealing.

  • Immutable and offline copies still matter. Follow 3-2-1-1-0: object-lock/WORM storage (such as S3 Object Lock), one offline or air-gapped copy, and zero errors on a tested restore.
  • Minimize what is stealable. Data minimization, retention limits, tokenization, and field-level encryption shrink the blast radius. See Privacy Engineering in 2026: Data Minimization, Consent, and Cross-Border Data.
  • Protect the backups as data, too. Exfiltrated backup files are themselves a data breach; encrypt them and restrict read access.
  • Instrument data stores so large or unusual reads are logged and alertable, the backup team and the detection team must share telemetry.

In practice, your backup budget stops being a single line item for storage and restore testing. Part of it moves to data-loss-prevention tooling, egress controls, and the data-classification work that tells you which datasets would actually hurt if leaked. Restoring a system in two hours is a hollow win if the attacker walked out with your customer database a week earlier. The metric that matters is no longer only how fast you recover, but how confidently you can enumerate exactly what left the building.

How does incident response change when nothing is encrypted?

Your IR plan must treat every intrusion as a potential data breach with regulatory clocks, not just an availability incident. When there is no encryption, the critical questions become what data left, whose data it was, and what you must disclose, and those drive legal, comms, and notification workstreams from hour one.

Update your playbook to include:

  • Exfiltration scoping. Determine what was accessed and staged, from egress logs, cloud data-access logs, and DLP alerts, not just which hosts were touched.
  • Regulatory notification triggers. GDPR Article 33 generally expects breach notification to the supervisory authority within 72 hours; NIS2 adds its own early-warning timelines. These rules are in flux, verify against primary EU sources and your DPO before relying on any specific window.
  • Legal, comms, and negotiation tracks running in parallel with technical containment.
  • Evidence preservation for the leak itself.

A useful test: run your existing playbook against a scenario where the only signal is a threat actor emailing a sample of your data, with every system online. If the plan grinds to a halt because there is no host to isolate and no ransom note on a screen, it was built for the last war. The forensic goal shifts from restoring service to answering, with evidence, which records were exfiltrated, because that answer, not the outage, drives your notification and disclosure obligations.

If your current playbook assumes an encryption event as the trigger, it will miss silent theft, Incident Response Playbooks That Teams Actually Use covers building ones that hold under pressure.

How do you detect exfiltration before the extortion email?

Detection has to move upstream to the data-movement stage, because there is no encryption to catch. The goal is to spot staging and egress, large reads, compression, and outbound transfers, while the attacker is still inside, not when the demand lands.

High-value controls:

  • Egress monitoring and filtering. Baseline normal outbound volume and destinations; alert on spikes, new cloud-storage endpoints, or DNS tunneling.
  • Canary tokens and honeytokens. Seed fake credentials and documents that fire an alert the moment they are accessed or exfiltrated.
  • Data-access analytics (UEBA/DSPM). Flag a service account or user reading far more records than its baseline.
  • Network and endpoint telemetry. Zeek or NDR sensors on egress paths, plus EDR that flags archiving and transfer utilities (7-Zip, WinRAR, rclone) staging data, catch the collection phase that precedes an upload.
  • MFT and edge hardening. Patch internet-facing file-transfer and edge appliances fast, Cl0p's campaigns exploited MOVEit (CVE-2023-34362) and Cleo (CVE-2024-50623) before most victims had patched.

The common thread is that exfiltration leaves a trail long before the extortion note: reconnaissance, staging, compression, and a large outbound transfer to somewhere the environment has never talked to. Instrumenting for that trail buys you the one thing pure-extortion crews rely on you not having, a chance to intervene while the data is still yours.

Should you pay a data-only extortion demand?

Assume payment guarantees nothing and may be illegal. Paying a data-only demand buys, at best, a promise to delete data you cannot verify was deleted, and criminals frequently re-extort or leak anyway. Treat the decision as legal and strategic, made with counsel and law enforcement, not as a technical fix.

  • No verifiable deletion. You have no way to confirm copies are destroyed; re-extortion is common.
  • Sanctions and legal exposure. Payments to sanctioned entities can breach OFAC and equivalent regimes; involve counsel early.
  • Notification obligations stand regardless. Paying does not erase your duty to notify regulators and affected individuals.
  • Prepare the decision in advance in tabletop exercises so you are not deciding under a countdown, see Designing Tabletop Exercises That Expose Real Gaps.

How TuniCyberLabs helps

We re-engineer backup, detection, and IR for the exfiltration era: immutable backups plus egress monitoring, canary tokens, DLP, and a breach-ready incident-response playbook with regulatory timelines built in. Book a resilience review to pressure-test your plan against data-only extortion.

TAGS
data extortionransomwareincident responsebackup strategydata exfiltrationextortionDLPbreach notification

Frequently Asked Questions

What is data-only extortion?

+

Data-only extortion is a cyberattack where criminals steal data and threaten to publish or sell it unless paid, without encrypting your systems. Also called exfiltration-only or encryption-less extortion, its leverage is confidentiality and reputation rather than downtime. Because nothing is locked, backups restore operations but do not remove the attackers' leverage over your stolen data.

Is ransomware declining?

+

Encryption-based ransomware is evolving, not disappearing. Per public reporting, the share of victims paying and total ransom revenue have fallen, thanks to better backups, law-enforcement pressure, and sanctions risk. But attack volume keeps rising as many groups pivot to data-only extortion, dropping the noisy encryption step and monetizing stolen data directly.

Why do backups not protect against data extortion?

+

Backups restore availability, not confidentiality. If attackers stole your data rather than encrypting it, a flawless restore does nothing about their copy or their threat to leak it. Backups remain essential for recovery and for encryption-based attacks, but against data-only extortion they are table stakes, not a solution, you must prevent and detect exfiltration.

How do you detect data exfiltration early?

+

Monitor for the data-movement stage rather than an encryption event: baseline outbound traffic and alert on volume spikes, new destinations, or DNS tunneling; deploy canary tokens and honeytokens that fire when touched; and use UEBA or DSPM to flag accounts reading abnormal record volumes. Patch internet-facing file-transfer appliances quickly, since those are common entry points.

Should you pay a data extortion ransom?

+

Assume payment guarantees nothing. You cannot verify stolen data is deleted, re-extortion is common, and paying certain groups may violate OFAC and other sanctions. Payment also does not remove your legal duty to notify regulators and affected individuals. Treat it as a legal and strategic decision made with counsel and law enforcement, and decide it in advance via tabletop exercises.

What regulatory deadlines apply after a data breach?

+

Under GDPR Article 33, controllers generally must notify the supervisory authority within 72 hours of becoming aware of a qualifying breach; NIS2 adds early-warning and reporting timelines for in-scope entities. These rules and their timelines are evolving, so verify specifics against primary EU sources and your data-protection officer before relying on any particular window.

Need help with
this topic
?

Our team specializes in the technologies and strategies discussed in this article. Let’s talk about how we can help your business.

Get in Touch