Out of the Crypt: The Evolving Cyber Extortion Economy
This report from Palo Alto Unit 42 highlights a significant shift in the cyber extortion landscape, moving away from ransomware-based pressure towards pure data theft and extortion. The trend is driven by factors like advanced backup systems, regulatory pressures, and the increased speed of data exfiltration. Notably, data-only extortion campaigns are becoming more prevalent, particularly targeting Professional Services, Healthcare, and Consumer Services firms, with a surge in activity within the Construction sector. The report also details the involvement of threat actors like TGR-CRI-1135 and their evolving tactics, including supply chain compromises and partnerships with RaaS/EaaS operators.
The cybersecurity landscape is undergoing a transformation, with extortion attacks increasingly prioritizing data theft over ransomware payments. Unit 42’s analysis reveals a dramatic decline in the use of encryption for extortion, dropping to 78% in 2025 compared to near-100% levels in previous years. This shift is fueled by several converging factors, including improved backup and recovery capabilities, enhanced endpoint security, and the escalating pressure from regulatory frameworks. Organizations are now facing potentially crippling fines and reputational damage for data breaches, making data theft a more attractive and effective extortion strategy. The rise of frontier AI models is also contributing to this trend, offering threat actors new ways to automate and scale their operations.
Data-only extortion campaigns are disproportionately targeting specific sectors, with Professional Services, Healthcare, and Consumer Services experiencing a significant increase in incidents. The Construction sector has seen a particularly sharp rise in data-only extortion, driven by the value of financial blueprints and bidding data. The report emphasizes the role of regulatory compliance in this shift, with mandates like the SEC’s disclosure window and GDPR’s reporting rules creating a ‘regulatory countdown clock’ that compels organizations to negotiate quickly before they can fully assess the damage. The average cost of data theft extortion has soared to $5.08 million, further incentivizing threat actors to exploit this vulnerability.
Threat actors are diversifying their tactics, leveraging supply chain compromises and partnerships with RaaS/EaaS operators. TGR-CRI-1135, a group known for its supply chain attacks, is now collaborating with LAPSUS$ Group for extortion via data leak sites and with Vect ransomware operators. The release of an open-source version of Shai-Hulud by TGR-CRI-1135 on BreachForums underscores the evolving sophistication and adaptability of these threat actors. The rapid exfiltration times – as little as 39 seconds – further amplifies the urgency and severity of these attacks.
