Blog / Threats
Threats
Data Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.
A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.
The countdown timer nobody took seriously
The owner of a 50-person logistics brokerage gets an email on a Thursday with the subject line "Your customer contracts." The body is short and correctly spelled. It says the company's files have been copied, it names three of his largest shipper clients, and it links to a page with a countdown clock reading four days. Attached are two PDFs. He opens one. It is a signed rate agreement with a client from the previous spring, complete with the client's signature.
Nothing on his network is locked. The systems all work. His IT provider says there is no malware on any machine. So the owner does what many owners do: he decides it is a scam built from a document that leaked somewhere, and he deletes the email.
On Tuesday one of the three shippers calls. The shipper has received an email too, with its own contract attached, and a note explaining that its logistics provider "has chosen not to protect your data." The shipper's general counsel is on the call. So is its procurement lead. Nobody on the call is asking whether it happened. They want to know what the brokerage intends to do about it, and by when.
The owner learns, over the following week, that the attacker had used a salesperson's cloud login for 19 days and downloaded the shared drive in ordinary-looking chunks, during business hours, at a pace nobody's tools were set to notice. Nothing needed to be encrypted. The data was the product all along.
What the heck does this mean
A data extortion attack is theft followed by a threat. The attacker copies your files and demands payment not to publish them. No encryption, no locked screens, often no malware at all. The absence of drama is the point: it does not trip the defenses built for ransomware.
Double extortion is the older combination: encrypt the files and steal them, so a good backup only solves half the problem. Extortion without encryption drops the first half because the second half was doing the work.
A data leak site is where the threat is carried out. Criminal groups run public websites listing victims, with samples, countdown timers and, eventually, the full archive. Your customers, competitors and journalists can read it.
Exfiltration is the copying-out. It uses your own tools, a stolen cloud login, a sync client, a file-transfer service, and looks like a busy afternoon.
The reframing owners need: the ransom note used to be the moment of discovery. Now it arrives weeks after the theft, with your own contracts attached. It is the invoice.
The numbers that matter
Data-theft incidents jumped from 2% to 22% of incident response cases, according to the Arctic Wolf 2026 Threat Report. That is an eleven-fold rise in one year. Theft without encryption has gone from a footnote to more than one case in five.
77% of ransomware victims did not pay, and professional negotiation cut demands by 67% on average, in the same Arctic Wolf 2026 report. The attacker's opening number is a starting position, and the people who deal with these cases every week know it.
64% of closed claims were resolved with no out-of-pocket loss to the policyholder, per the Coalition 2026 Cyber Claims Report. The businesses that had a plan and an insurer usually came through without writing a check. The ones that deleted the email did not have that option.
What to do this week
- Find your crown jewels and put them somewhere narrower. Contracts, client lists, pricing, personal data: they should live in a restricted folder with named access, not on a shared drive every salesperson can download in full. (CIS 3 Data Protection)
- Turn on data loss prevention on your cloud platform, at least in monitor mode, so a download of 4,000 files or a bulk export from the CRM produces an alert the same hour. (CIS 3 Data Protection)
- Get a baseline of normal outbound traffic and set an alert when it is exceeded. Nineteen days of chunked downloads during business hours is visible if anyone has defined what a normal day looks like. (CIS 13 Network Monitoring and Defense)
- Add the extortion email to your incident plan, with a rule that nobody replies and nobody deletes. The first three calls, in order: the insurer's hotline, the lawyer, the IT provider. (CIS 17 Incident Response Management)
- Review who can sign in to the cloud drive and from where, and revoke every stale session. The salesperson's login was valid for 19 days after it was stolen. (CIS 5 Account Management)
- Decide now who talks to customers if the worst happens, and draft the first message while nobody is angry. A shipper's general counsel on a Tuesday call is not the moment to start writing. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment looks for the conditions this attack needs: the shared drive with everything in it, the cloud login with no session limit, and nobody watching what leaves the building. The Cyber Hygiene Test takes three minutes and shows the first gaps. To go through your data map with a person, book 15 minutes with an engineer and bring the list of folders you would least like to see on a leak site.
Questions people ask
Is data extortion a reportable breach? If the attacker has your customers' or employees' personal data, yes, in almost every jurisdiction that has a breach law, and the fact that nothing was encrypted makes no difference. The trigger is that someone unauthorized obtained the data. Which regulator, which clock and which people you must tell depends on where you operate and what kind of data it was, and that is a question for your lawyer in the first day, not the last.
Should we respond to the extortion email? Not by yourself, and not right away. Do not reply, do not click the link, and do not delete the message; it is evidence. Call your insurer's hotline and your lawyer first. If a response is warranted, it is made by an experienced negotiator with a strategy, whose first goals are to slow the clock and confirm what was actually taken. An owner replying from a personal phone at midnight gives the attacker everything they need.
How do attackers steal data without anyone noticing? They use the same tools your staff use. A stolen login opens the cloud drive or the file server; a file-sync client or a cloud storage upload moves the data out over ordinary web traffic; and the transfer runs at a pace that looks like a normal day. Without a baseline of what normal outbound traffic looks like, and an alert when it is exceeded, there is nothing to see. The theft is invisible because nobody was watching for it.
The locked screen was always the distraction. The file that quietly left on a Tuesday afternoon was the attack, and it still is.
Questions people ask
Is data extortion a reportable breach?
If the attacker has your customers' or employees' personal data, yes, in almost every jurisdiction that has a breach law, and the fact that nothing was encrypted makes no difference. The trigger is that someone unauthorized obtained the data. Which regulator, which clock and which people you must tell depends on where you operate and what kind of data it was, and that is a question for your lawyer in the first day, not the last.
Should we respond to the extortion email?
Not by yourself, and not right away. Do not reply, do not click the link, and do not delete the message; it is evidence. Call your insurer's hotline and your lawyer first. If a response is warranted, it is made by an experienced negotiator with a strategy, whose first goals are to slow the clock and confirm what was actually taken. An owner replying from a personal phone at midnight gives the attacker everything they need.
How do attackers steal data without anyone noticing?
They use the same tools your staff use. A stolen login opens the cloud drive or the file server; a file-sync client or a cloud storage upload moves the data out over ordinary web traffic; and the transfer runs at a pace that looks like a normal day. Without a baseline of what normal outbound traffic looks like, and an alert when it is exceeded, there is nothing to see. The theft is invisible because nobody was watching for it.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Deepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director
Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.
ThreatsBusiness Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank
Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.
ThreatsYour Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review
A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.
