logo

Ransomware Without Encryption: Why Pure Exfiltration Attacks Are Surging—and Why They’re So Hard to Catch 

ID: b6261c77-9435-56ed-afcc-2985b1e9162c

STIX ID: report--b6261c77-9435-56ed-afcc-2985b1e9162c

Feed Name: Morphisec Blog

Date Published: 2026-01-01

Date Updated: 2026-04-28

...
...

Morphisec’s CTO briefing explains that modern ransomware is increasingly “encryption-less,” focusing on stealthy data exfiltration and delayed extortion that evade traditional detections and frustrate forensics. Attackers leverage trusted tools and cloud services—such as Azure Copy, RClone, Mega, Bitbucket, PowerShell, and RoboCopy—to mimic normal operations, leaving few alerts and scant evidence. The report underscores regulatory and reputational pressures that still drive payments and advises shifting to preemptive defense, expanding visibility into outbound/cloud data flows, hardening identity and remote access, validating exfiltration claims before negotiating, and securing non-agent assets like gateways, NAS, and backup servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.