Cybercriminals are increasingly moving away from encryption-led ransomware attacks and instead focusing on stealing data for extortion, according to new threat intelligence analysis from Quorum Cyber covering the first half of 2026.
In its “2026 Global Cyber Risk Mid-Year Review”, the company reports a growing shift towards operations centred on data theft, identity compromise and quiet exfiltration after attackers gain trusted access via stolen credentials, phishing, compromised cloud identities or insider manipulation. Quorum Cyber said the approach reflects cybercrime economics where threat actors can monetise access and information without deploying ransomware.
The report highlights that stolen customer data, intellectual property, source code, cloud credentials and SaaS identities are being monetised through extortion, resale or subsequent attacks. Quorum Cyber added that many organisations remain primarily focused on preventing encryption-based ransomware, leaving gaps in detection and response for large-scale data exfiltration.
Jack Alexander, Global Intelligence Lead at Quorum Cyber, commented: “In the last 10-12 years ransomware has become synonymous with cybercrime but we’re seeing a significant change in attacker behaviour. Increasingly, cybercriminals don’t need to encrypt systems to achieve their objectives. If they can steal an organisation’s most valuable data, they already have the leverage they need.”
He continued: “Data has become the more valued currency of cybercrime. Once attackers gain trusted access through compromised credentials, phishing or social engineering, their priority is increasingly to identify what information they can take before they’re detected. That data can then be used for extortion, sold to other threat actors or exploited in follow-on attacks.” Quorum Cyber also said threat actors are increasingly exploiting trusted identities and legitimate access, including purchasing compromised credentials, recruiting insiders, abusing help desk processes, stealing authentication tokens and targeting cloud environments, while some ransomware groups evolve towards “extortion-only” models and more structured negotiation tactics.
Quorum Cyber said it will host a webinar on Aug. 18, 2026 to discuss the findings in more detail.













Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.