Data-only extortion surged dramatically in 2025, highlighting a shift in attacker tactics toward theft and coercion rather than encryption, according to new findings from Arctic Wolf, according to IT Brief Australia.In its 2026 Threat Report, the firm said ransomware, business email compromise, and data incidents accounted for 92% of response engagements, with data-only extortion jumping elevenfold and rising from 2% to 22% of cases. Analysts observed that 65% of non-BEC breaches began with abuse of remote access tools, reflecting a preference for "logging in instead of breaking in," as Vice President Ismael Valenzuela noted.Ransomware remained prevalent, though 77% of impacted organizations declined to pay, and negotiated settlements cut demands by an average of 67%. Phishing drove 85% of BEC incidents, amplified by AI-enabled social engineering. In Australia, small and midsize businesses represented 71% of victims, with groups such as Qilin and Akira active. Executives stressed that disciplined identity controls, patching, and early detection significantly reduce disruption.
Threat Intelligence, Breach, Ransomware
Remote access abuse drives majority of breaches

(Adobe Stock)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



