Skip to content

Cyber Threat Landscape 2026: Ransomware and Data Theft Merge into a Single Attack Form

Bottom line: According to a Riedel Networks report, ransomware attacks are now accompanied by targeted data theft prior to encryption in 63.6 percent of cases, increasing extortion pressure and third-party risks for companies.

A report by Riedel Networks, based on an analysis of more than 180 security incidents from the first half of 2026, shows that ransomware attacks are now almost always accompanied by targeted data theft. For CISOs, this means that pure backup strategies are no longer sufficient to mitigate risk.

The share of ransomware among the incidents examined rose to 76.1 percent in the first half of 2026, compared with 32.5 percent in the second half of 2025. However, more significant than the sheer increase in frequency is the change in attackers’ approach: in 63.6 percent of ransomware cases, confidential data was deliberately copied before encryption—sometimes amounting to several hundred gigabytes or even terabytes. Encryption is thus increasingly serving as just one of several pressure levers in the extortion process. Screenshots as proof of access, short payment deadlines, and publication on leak sites further increase the pressure to act on affected organizations.

By industry, manufacturing remains the most affected sector, accounting for around 32 percent of cases, slightly down from 34.6 percent in the previous half-year. Healthcare and social services follow with around eleven percent, and logistics and transport with around nine percent. This means that sectors with complex supply chains, critical operations, and sensitive data holdings are particularly affected. The report also points to a growing dependency on external IT and business partners: IT service providers, software vendors, logistics companies, billing agencies, or facility service providers increasingly serve as entry points through which impacts can spread across the entire value chain.

According to Riedel Networks’ assessment, criminal actors are increasingly relying on AI-assisted phishing and social engineering to prepare attacks, allowing them to tailor approaches more individually and quickly to target groups. Around 91 percent of recorded incidents are attributed to financially motivated actors, up from 86.95 percent in the second half of 2025. State-backed actors, while less frequently represented, are gaining visibility according to the report and are increasingly using everyday communication platforms for espionage activities.

For CISOs, this creates a need to systematically incorporate third-party and supply-chain risks into their own resilience concepts, since attacks no longer necessarily have to hit the target company directly. In addition, incident response plans should explicitly account for the combination of encryption and data exfiltration—for example, through monitoring for unusual large-scale data outflows and prepared communication strategies for cases involving leak-site publications.


Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: