Ransomware is shifting from encryption to pure data theft

Morphisec notes that ransomware operations increasingly move from encrypting data to simply taking it. Extortion without encryption carries less risk for the attacker because exfiltration is quiet and hard to detect. Data can be drained gradually over weeks or months, and investigation is difficult once logs have rolled over and no clear point of compromise remains. The extortion still works, because regulations such as GDPR trigger disclosure duties. Attackers often use legitimate tools to blend into normal traffic.

What this means for your organisation

Backups do not help here. Data that has left has left. The impact moves from downtime to notification duties, regulators, customers and reputation, and it lands on the board and executive team. It also becomes harder to answer the first question a supervisory authority asks: exactly which personal data left, and when.

Berigo recommends

  • Extend log retention in core systems so an attack spanning months can actually be reconstructed.
  • Build detection for outbound data volume and for large extracts from file stores and databases.
  • Update the incident plan for a no-encryption scenario, with clear ownership of notification to the authority and to customers.
  • Classify where personal and business-critical data actually resides, before you need to know.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch