Threat Intelligence, Breach, Ransomware

Remote access abuse drives majority of breaches

Hacker attack computer hardware microchip while process data through internet network, 3d rendering insecure Cyber Security exploit database breach concept, virus malware unlock warning screen

Data-only extortion surged dramatically in 2025, highlighting a shift in attacker tactics toward theft and coercion rather than encryption, according to new findings from Arctic Wolf, according to IT Brief Australia.

In its 2026 Threat Report, the firm said ransomware, business email compromise, and data incidents accounted for 92% of response engagements, with data-only extortion jumping elevenfold and rising from 2% to 22% of cases. Analysts observed that 65% of non-BEC breaches began with abuse of remote access tools, reflecting a preference for "logging in instead of breaking in," as Vice President Ismael Valenzuela noted.

Ransomware remained prevalent, though 77% of impacted organizations declined to pay, and negotiated settlements cut demands by an average of 67%. Phishing drove 85% of BEC incidents, amplified by AI-enabled social engineering. In Australia, small and midsize businesses represented 71% of victims, with groups such as Qilin and Akira active. Executives stressed that disciplined identity controls, patching, and early detection significantly reduce disruption.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds