Google Warns Ransomware Groups Shift to Data Theft as Profits Decline
ID: f5f80440-3ed3-5199-8e73-628b372ca741
STIX ID: report--f5f80440-3ed3-5199-8e73-628b372ca741
Feed Name: GBHackers
Google Threat Intelligence Group reports a 2025 shift in ransomware economics: as encryption-for-ransom becomes less profitable, actors increasingly steal data for extortion, with nearly 50% more data leak site (DLS) listings than 2024 and about 77% of analyzed incidents involving suspected or confirmed data theft. Operators exploit edge VPNs and firewalls, misconfigurations, credential theft and brute-force, increasingly target virtualized environments (≈43% of intrusions), abuse cloud sync/exfil tools (Rclone, MEGA, Azure, AWS, OneDrive), and RaaS affiliates now offer "data-theft-only" options while focusing more on smaller organizations with weaker defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
