Unit 42's 2026 Global Incident Response Report found encryption present in just 78% of 2025 extortion cases, down from more than 90% in prior years, as data theft alone becomes a viable business model on its own. The fastest quarter of intrusions now reach exfiltration in 72 minutes, and the recovery playbook built for encryption is not built for that.
Key Takeaways
For most of the last decade, ransomware meant one thing: a locked file system, a ransom note, and a recovery plan built around backups. Security teams spent years and budget making sure they could restore from a clean copy rather than pay. That plan assumed the attacker's leverage was the lock. Unit 42's 2026 Global Incident Response Report shows the lock itself has become optional, and the leverage has quietly moved to something a backup cannot undo: the copy of the data the attacker already took.
Encryption still shows up in a majority of extortion cases, 78% in 2025 according to Unit 42, but that figure has been sliding from more than 90% in prior years. Meanwhile 57% of extortion cases involved data theft, a share large enough that a meaningful slice of incidents now involve theft with no encryption at all.
The economics reflect the shift. Median initial ransom demands rose to $1.5 million in 2025, up from $1.25 million in 2024, and median payments rose to $500,000 from $267,500. Negotiation still works, cutting the median demand by 61% before payment, and attackers kept their side of the bargain in 68% of cases. None of that requires a single encrypted file, only proof that the stolen data is real and that releasing it would hurt.
That proof is easier to find than it used to be. Unit 42 found SaaS platforms relevant to 23% of 2025 cases, up from just 6% in 2022, as more of the data worth stealing lives outside the traditional network perimeter a backup policy was designed to protect.
Speed is the other half of the shift. Unit 42's fastest quartile of 2025 intrusions reached exfiltration in a median of 72 minutes, down from 285 minutes in 2024, and 22% of incidents crossed that line in under an hour entirely, up from 19% the year before. In simulated attacks using current AI tooling, time-to-exfiltration fell to 25 minutes.
Eon's 2026 analysis of cloud ransomware puts a sharper number on the same trend, citing CrowdStrike data showing average eCrime breakout time fell to 29 minutes in 2025, with the fastest recorded intrusion moving from initial access to lateral movement in just 27 seconds. Unit 42 attributes much of that speed to identity weaknesses: 89% of investigations involved identity-related elements, 65% of initial access came through identity techniques, and 99% of cloud users, roles and services carried excessive permissions. Eon separately found 63% of logins involved in cloud ransomware cases used credentials already compromised elsewhere.
A detection and response programme built around a multi-day window, which is still the median across Unit 42's full dataset at two days, is not built for a threat whose fastest quarter now closes in barely over an hour.
Eon's report documents what this looks like in practice through Storm-0501, a group Microsoft's threat intelligence team tracked compromising on-premises Active Directory, moving laterally into Azure, gaining Global Administrator privileges through an unprotected non-human account, exfiltrating data with native cloud tools, and mass-deleting backup infrastructure before ever issuing a ransom demand through a compromised Teams account. Backup-based recovery fell from 73% to 53% of incidents industry-wide in 2025, and Storm-0501 shows one direct reason why: if the backups are gone before the ransom note arrives, recovery capability was never the deciding factor.
Quorum Cyber's threat intelligence team has labelled 2026 the year of exfiltration risk for exactly this reason. “Attackers are shifting their tactics to steal sensitive information rather than deploying ‘noisy’ ransomware payloads and attracting lots of unwanted attention,” the firm's researchers wrote, pointing to recruited insiders, compromised help desk workflows, OAuth tokens, malicious SaaS integrations, CI/CD secrets and unsanctioned AI platforms as the quiet access paths now preferred over the phishing email that used to announce an intrusion.
Unit 42's own framing is the clearest summary available: more than 90% of the breaches in its dataset involved preventable gaps in coverage and inconsistently applied controls, not novel attacker sophistication. The tools to close those gaps already exist. What changed is how little time there is left to use them.
The number worth remembering is not the ransom figure, it is 72 minutes. Encryption was always the visible part of a ransomware attack, the part that triggered an incident response plan built years in advance. Exfiltration is the quiet part, and it is now finishing before most of those plans ever fully engage.
Guide
When exfiltration finishes in 72 minutes, the warning signs before encryption ever starts are the only window left to catch it.
Download
Guide
With 23% of extortion cases now touching SaaS platforms, the data worth stealing increasingly lives where a backup policy never reached it.
Download
Whitepaper
The wider research behind the shift this article covers, tracking how extortion tactics are moving away from the ransom note attackers used to need.
Download
Only 21.9% of enterprises treat AI agents as independent identities, with 45.6% still on shared API keys.
IBM put the global average breach at $4.99 million, up 12% in a year.
Researchers recovered synced passkey private keys despite policies requiring phishing-resistant MFA.