Security

Ransomware Skips Encryption, and the Fastest Attacks Now Exfiltrate Data in Under Two Hours

Unit 42's 2026 Global Incident Response Report found encryption present in just 78% of 2025 extortion cases, down from more than 90% in prior years, as data theft alone becomes a viable business model on its own. The fastest quarter of intrusions now reach exfiltration in 72 minutes, and the recovery playbook built for encryption is not built for that.

September 10, 2026 · Security
A dark data centre aisle lined with server racks and cabling, with no people in frame

Key Takeaways

  • Unit 42's 2026 Global Incident Response Report found encryption present in 78% of 2025 extortion cases, down from more than 90% in prior years, while 57% of cases involved outright data theft.
  • The fastest quarter of 2025 intrusions reached exfiltration in a median of 72 minutes, down from 285 minutes in 2024, and simulated AI-driven attacks cut that further to 25 minutes.
  • CrowdStrike recorded an average eCrime breakout time of 29 minutes in 2025, with the fastest observed intrusion moving from initial access to lateral movement in 27 seconds.
  • Backup-based recovery fell from 73% to 53% of ransomware incidents in 2025, because restoring encrypted files does nothing once the data itself has already left the network.

For most of the last decade, ransomware meant one thing: a locked file system, a ransom note, and a recovery plan built around backups. Security teams spent years and budget making sure they could restore from a clean copy rather than pay. That plan assumed the attacker's leverage was the lock. Unit 42's 2026 Global Incident Response Report shows the lock itself has become optional, and the leverage has quietly moved to something a backup cannot undo: the copy of the data the attacker already took.

Encryption Is Declining Even Where It Still Appears

Encryption still shows up in a majority of extortion cases, 78% in 2025 according to Unit 42, but that figure has been sliding from more than 90% in prior years. Meanwhile 57% of extortion cases involved data theft, a share large enough that a meaningful slice of incidents now involve theft with no encryption at all.

The economics reflect the shift. Median initial ransom demands rose to $1.5 million in 2025, up from $1.25 million in 2024, and median payments rose to $500,000 from $267,500. Negotiation still works, cutting the median demand by 61% before payment, and attackers kept their side of the bargain in 68% of cases. None of that requires a single encrypted file, only proof that the stolen data is real and that releasing it would hurt.

That proof is easier to find than it used to be. Unit 42 found SaaS platforms relevant to 23% of 2025 cases, up from just 6% in 2022, as more of the data worth stealing lives outside the traditional network perimeter a backup policy was designed to protect.

The Exfiltration Clock Has Collapsed to Minutes

Speed is the other half of the shift. Unit 42's fastest quartile of 2025 intrusions reached exfiltration in a median of 72 minutes, down from 285 minutes in 2024, and 22% of incidents crossed that line in under an hour entirely, up from 19% the year before. In simulated attacks using current AI tooling, time-to-exfiltration fell to 25 minutes.

Eon's 2026 analysis of cloud ransomware puts a sharper number on the same trend, citing CrowdStrike data showing average eCrime breakout time fell to 29 minutes in 2025, with the fastest recorded intrusion moving from initial access to lateral movement in just 27 seconds. Unit 42 attributes much of that speed to identity weaknesses: 89% of investigations involved identity-related elements, 65% of initial access came through identity techniques, and 99% of cloud users, roles and services carried excessive permissions. Eon separately found 63% of logins involved in cloud ransomware cases used credentials already compromised elsewhere.

A detection and response programme built around a multi-day window, which is still the median across Unit 42's full dataset at two days, is not built for a threat whose fastest quarter now closes in barely over an hour.

Why the Backup Plan Stops Helping

Eon's report documents what this looks like in practice through Storm-0501, a group Microsoft's threat intelligence team tracked compromising on-premises Active Directory, moving laterally into Azure, gaining Global Administrator privileges through an unprotected non-human account, exfiltrating data with native cloud tools, and mass-deleting backup infrastructure before ever issuing a ransom demand through a compromised Teams account. Backup-based recovery fell from 73% to 53% of incidents industry-wide in 2025, and Storm-0501 shows one direct reason why: if the backups are gone before the ransom note arrives, recovery capability was never the deciding factor.

Quorum Cyber's threat intelligence team has labelled 2026 the year of exfiltration risk for exactly this reason. “Attackers are shifting their tactics to steal sensitive information rather than deploying ‘noisy’ ransomware payloads and attracting lots of unwanted attention,” the firm's researchers wrote, pointing to recruited insiders, compromised help desk workflows, OAuth tokens, malicious SaaS integrations, CI/CD secrets and unsanctioned AI platforms as the quiet access paths now preferred over the phishing email that used to announce an intrusion.

Unit 42's own framing is the clearest summary available: more than 90% of the breaches in its dataset involved preventable gaps in coverage and inconsistently applied controls, not novel attacker sophistication. The tools to close those gaps already exist. What changed is how little time there is left to use them.

The number worth remembering is not the ransom figure, it is 72 minutes. Encryption was always the visible part of a ransomware attack, the part that triggered an incident response plan built years in advance. Exfiltration is the quiet part, and it is now finishing before most of those plans ever fully engage.

Share

More in Security

All Resources →