Cybercriminals shift from ransomware to data theft, Quorum Cyber says
Quorum Cyber says attackers are moving away from encrypting systems and toward stealing sensitive data for extortion, resale and follow-on attacks. The Edinburgh firm says the shift leaves many organizations underprepared for large-scale data theft even as criminals become more commercially sophisticated.
Why it matters: - Cybercriminals can now pressure victims without locking systems, which raises the risk of extortion even when operations stay online. - Organizations focused mainly on encryption-based ransomware may miss large-scale data theft, identity abuse and cloud compromise. - The shift puts customer data, intellectual property, source code, cloud credentials and SaaS identities at higher risk.
What happened: - Quorum Cyber released a new threat intelligence analysis, the “2026 Global Cyber Risk Mid-Year Review,” based on intelligence gathered in the first half of 2026. - The Edinburgh-based cybersecurity company says attackers are increasingly abandoning traditional ransomware in favor of data theft and extortion. - Quorum Cyber will host a webinar on Aug. 18, 2026, to discuss the findings. - The webinar is titled “AI, Identity and Trust: Secure the Foundations of Cyber Resilience in 2026.”
The details: - The report says attackers are shifting from encrypting systems to operations centered on stealing data, compromising identities and extorting organizations. - Once attackers gain trusted access through stolen credentials, phishing, compromised cloud identities or insider manipulation, their main goal is often to extract valuable information. - Quorum Cyber says stolen data is being monetized through extortion, resale or subsequent attacks. - The report says attackers are increasingly buying compromised credentials, recruiting insiders, abusing help desk processes, stealing authentication tokens and targeting cloud environments. - The analysis also says some ransomware groups are moving toward extortion-only operations. - Other groups are using more structured negotiation tactics to increase the chance of payment. - Jack Alexander, Global Intelligence Lead at Quorum Cyber, said ransomware has become synonymous with cybercrime over the last 10 to 12 years, but attacker behavior is changing. - Alexander said criminals no longer need to encrypt systems if they can steal an organization’s most valuable data. - Alexander said data has become the more valued currency of cybercrime. - Alexander said attackers are using compromised credentials, phishing and social engineering to figure out what information they can take before detection. - Alexander said stolen data can be used for extortion, sold to other threat actors or used in follow-on attacks. - The report says many organizations still focus heavily on preventing encryption-based ransomware and are less prepared for large-scale data exfiltration.
Between the lines: - The economics of cybercrime appear to be changing, with theft of information offering attackers faster leverage than shutting down systems. - Quorum Cyber says criminals may prefer data theft because organizations fear regulatory scrutiny, customer notifications and reputational damage. - The report suggests identity, trust and data are becoming the primary targets for financially motivated cybercriminals. - As more organizations adopt cloud services, SaaS platforms and AI-powered tools, abnormal access detection becomes more important alongside traditional defenses.
What's next: - Quorum Cyber is using the webinar to expand on the report’s findings and the security steps organizations should prioritize. - Organizations are likely to face continued pressure to strengthen identity controls, cloud monitoring and data-loss detection. - The report points to a security focus shift from stopping ransomware encryption to spotting unauthorized access before data leaves the environment.
The bottom line: - The newest cybercrime playbook is less about locking files and more about stealing the information that gives attackers leverage.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
IT Press Releases
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.