We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Threats

Threats

Data Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.

A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The countdown timer nobody took seriously

The owner of a 50-person logistics brokerage gets an email on a Thursday with the subject line "Your customer contracts." The body is short and correctly spelled. It says the company's files have been copied, it names three of his largest shipper clients, and it links to a page with a countdown clock reading four days. Attached are two PDFs. He opens one. It is a signed rate agreement with a client from the previous spring, complete with the client's signature.

Nothing on his network is locked. The systems all work. His IT provider says there is no malware on any machine. So the owner does what many owners do: he decides it is a scam built from a document that leaked somewhere, and he deletes the email.

On Tuesday one of the three shippers calls. The shipper has received an email too, with its own contract attached, and a note explaining that its logistics provider "has chosen not to protect your data." The shipper's general counsel is on the call. So is its procurement lead. Nobody on the call is asking whether it happened. They want to know what the brokerage intends to do about it, and by when.

The owner learns, over the following week, that the attacker had used a salesperson's cloud login for 19 days and downloaded the shared drive in ordinary-looking chunks, during business hours, at a pace nobody's tools were set to notice. Nothing needed to be encrypted. The data was the product all along.

What the heck does this mean

A data extortion attack is theft followed by a threat. The attacker copies your files and demands payment not to publish them. No encryption, no locked screens, often no malware at all. The absence of drama is the point: it does not trip the defenses built for ransomware.

Double extortion is the older combination: encrypt the files and steal them, so a good backup only solves half the problem. Extortion without encryption drops the first half because the second half was doing the work.

A data leak site is where the threat is carried out. Criminal groups run public websites listing victims, with samples, countdown timers and, eventually, the full archive. Your customers, competitors and journalists can read it.

Exfiltration is the copying-out. It uses your own tools, a stolen cloud login, a sync client, a file-transfer service, and looks like a busy afternoon.

The reframing owners need: the ransom note used to be the moment of discovery. Now it arrives weeks after the theft, with your own contracts attached. It is the invoice.

The numbers that matter

Data-theft incidents jumped from 2% to 22% of incident response cases, according to the Arctic Wolf 2026 Threat Report. That is an eleven-fold rise in one year. Theft without encryption has gone from a footnote to more than one case in five.

77% of ransomware victims did not pay, and professional negotiation cut demands by 67% on average, in the same Arctic Wolf 2026 report. The attacker's opening number is a starting position, and the people who deal with these cases every week know it.

64% of closed claims were resolved with no out-of-pocket loss to the policyholder, per the Coalition 2026 Cyber Claims Report. The businesses that had a plan and an insurer usually came through without writing a check. The ones that deleted the email did not have that option.

What to do this week

  1. Find your crown jewels and put them somewhere narrower. Contracts, client lists, pricing, personal data: they should live in a restricted folder with named access, not on a shared drive every salesperson can download in full. (CIS 3 Data Protection)
  2. Turn on data loss prevention on your cloud platform, at least in monitor mode, so a download of 4,000 files or a bulk export from the CRM produces an alert the same hour. (CIS 3 Data Protection)
  3. Get a baseline of normal outbound traffic and set an alert when it is exceeded. Nineteen days of chunked downloads during business hours is visible if anyone has defined what a normal day looks like. (CIS 13 Network Monitoring and Defense)
  4. Add the extortion email to your incident plan, with a rule that nobody replies and nobody deletes. The first three calls, in order: the insurer's hotline, the lawyer, the IT provider. (CIS 17 Incident Response Management)
  5. Review who can sign in to the cloud drive and from where, and revoke every stale session. The salesperson's login was valid for 19 days after it was stolen. (CIS 5 Account Management)
  6. Decide now who talks to customers if the worst happens, and draft the first message while nobody is angry. A shipper's general counsel on a Tuesday call is not the moment to start writing. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment looks for the conditions this attack needs: the shared drive with everything in it, the cloud login with no session limit, and nobody watching what leaves the building. The Cyber Hygiene Test takes three minutes and shows the first gaps. To go through your data map with a person, book 15 minutes with an engineer and bring the list of folders you would least like to see on a leak site.

Questions people ask

Is data extortion a reportable breach? If the attacker has your customers' or employees' personal data, yes, in almost every jurisdiction that has a breach law, and the fact that nothing was encrypted makes no difference. The trigger is that someone unauthorized obtained the data. Which regulator, which clock and which people you must tell depends on where you operate and what kind of data it was, and that is a question for your lawyer in the first day, not the last.

Should we respond to the extortion email? Not by yourself, and not right away. Do not reply, do not click the link, and do not delete the message; it is evidence. Call your insurer's hotline and your lawyer first. If a response is warranted, it is made by an experienced negotiator with a strategy, whose first goals are to slow the clock and confirm what was actually taken. An owner replying from a personal phone at midnight gives the attacker everything they need.

How do attackers steal data without anyone noticing? They use the same tools your staff use. A stolen login opens the cloud drive or the file server; a file-sync client or a cloud storage upload moves the data out over ordinary web traffic; and the transfer runs at a pace that looks like a normal day. Without a baseline of what normal outbound traffic looks like, and an alert when it is exceeded, there is nothing to see. The theft is invisible because nobody was watching for it.

The locked screen was always the distraction. The file that quietly left on a Tuesday afternoon was the attack, and it still is.

Questions people ask

Is data extortion a reportable breach?

If the attacker has your customers' or employees' personal data, yes, in almost every jurisdiction that has a breach law, and the fact that nothing was encrypted makes no difference. The trigger is that someone unauthorized obtained the data. Which regulator, which clock and which people you must tell depends on where you operate and what kind of data it was, and that is a question for your lawyer in the first day, not the last.

Should we respond to the extortion email?

Not by yourself, and not right away. Do not reply, do not click the link, and do not delete the message; it is evidence. Call your insurer's hotline and your lawyer first. If a response is warranted, it is made by an experienced negotiator with a strategy, whose first goals are to slow the clock and confirm what was actually taken. An owner replying from a personal phone at midnight gives the attacker everything they need.

How do attackers steal data without anyone noticing?

They use the same tools your staff use. A stolen login opens the cloud drive or the file server; a file-sync client or a cloud storage upload moves the data out over ordinary web traffic; and the transfer runs at a pace that looks like a normal day. Without a baseline of what normal outbound traffic looks like, and an alert when it is exceeded, there is nothing to see. The theft is invisible because nobody was watching for it.

Controls this post maps to

CIS 3 Data ProtectionCIS 13 Network Monitoring and DefenseCIS 17 Incident Response Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.