From Hostage to Blackmail: Why Your Ransomware Playbook Needs a Rewrite
For a decade, ransomware worked like a kidnapping. Someone broke into your house, took your data hostage behind a wall of encryption, and left a note demanding payment for the key. The entire discipline of incident response grew up around that one scenario: isolate the infected machines, call the insurer, restore from backup if you could, negotiate if you couldn't. It was a good playbook. For that crime.
That crime is no longer the only one being committed against you, and in a growing share of cases, it isn't being committed at all.
The kidnapper became a blackmailer
The newer version skips the hostage-taking. The attacker doesn't lock your files; they quietly copy them, leave, and then tell you they'll publish or sell what they took unless you pay. Nothing is encrypted; systems keep running; backups are irrelevant because nothing was destroyed. What's held over you isn't access to your own data; it's what happens to a copy that's no longer only yours.
The numbers back up how far this has moved. In Coveware's Q2 2026 cyber-extortion report, lateral movement and data exfiltration were tied as the most-observed attacker tactics, each present in 76% of cases, a rate on par with encryption itself. Group-IB's 2026 review notes that exfiltration was present in 83% of Q1 2026 cases and describes groups like Hunters International rebranding entirely around it: "encryption became optional, refusal became irrelevant." ShinyHunters is the starkest example: no encryption at all, just a leak site that functions as the product, reportedly built on 3.65 TB of data taken from Instructure, affecting an estimated 275 million accounts. Silent Ransom (Luna Moth) skips malware entirely, using voice phishing and physical infiltration to walk out with your data.
If you're still running the kidnapping playbook against a blackmailer, you're defending the wrong crime.
But this is an arms race, not a one-way street
Here's the part a fear-driven headline would skip, and the part that actually matters for rebuilding your defenses: pure blackmail is turning out to be a worse business model than criminals hoped.
Victims have learned an uncomfortable truth: paying a blackmailer buys nothing enforceable, no key to hand over, no proof of deletion, no guarantee it won't resurface next year. So they've largely stopped paying. Coveware's own numbers show the exfiltration-only payment rate falling to a record low of 15% in Q2 2026. Victims of the MOVEit breach paid at under 2.5%; Cleo and Oracle EBS victims almost never paid at all. Across the industry, the overall ransom payment rate has slid from roughly 76% in 2019 to somewhere between a fifth and a quarter of victims today: Securelist's 2026 review puts it near 28%, while a 2025 Sophos study cited by SANS puts it at 20%. Different studies, same direction: down, sharply, from three-quarters of victims paying in 2019 (treat the figure as directionally solid, not precise).
That collapse is why SecurityWeek reports that Coveware now expects some groups to pivot back toward encryption: a hostage you can visibly return is still worth more to a criminal than a threat nobody believes will pay off. Meanwhile, the average payment involving encryption jumped 176% quarter-over-quarter to $1.88 million in Q2 2026, even as the median payment fell. In other words, some attackers are doubling down on pure blackmail, some are retreating back to kidnapping, and a fair number, like The Gentlemen (2026's most active group by victim count), do both depending on the target.
The practical consequence is that your playbook can't specialize. You need one that assumes either crime or both at once on any given Tuesday.
What actually has to change
A playbook built for hostage-taking optimizes for restoration. A playbook built for blackmail has to optimize for control of information, and the two require genuinely different first moves. Detection has to move upstream. Encryption is loud by design; it throws alerts the moment it starts. Exfiltration is quiet: it looks like unusual lateral movement, staged files, and increased outbound data volume, all of which must be caught before the theft, not after. By the time you notice a leak site listing, the window of opportunity has already closed.
The opening move changes too. Attackers increasingly walk in on stolen, valid credentials rather than deploying malware, which means isolating an infected host, the reflexive first step in the old playbook, often isolates nothing useful. Identity containment has to come first: knowing exactly which accounts, tokens, and sessions to kill, and in what order, before you do anything else.
Here's exactly how much of the problem backups still solve, and it isn't the whole thing. A properly maintained backup strategy is genuinely effective against the hostage half: SANS's July 2026 review cites a 97% recovery rate for encrypted data when organizations actually follow the 3-2-1-1-0 rule (three copies, two media types, one offsite, one immutable and air-gapped, zero errors on a tested restore, the "tested" part being where most quietly fail). But SANS also reports that encryption is only in place in around 50% of cases today, which means even a flawless backup strategy addresses at most half of the current threat. For the other half, built on the threat to leak or sell your data rather than lock it, a perfect backup changes nothing. You can't restore your way out of blackmail. Treating backups as the finish line is, in Sygnia's blunter phrase, "backup-only thinking", still the most common mistake security teams make. Once you accept that, the response has to shift from isolate-and-restore toward forensic scoping, legal assessment, and a negotiation posture decided before the attacker makes contact, not improvised under pressure.
And in Europe, the regulatory clock now belongs in the playbook itself, not handled afterward. An encryption-only incident with no data exfiltration triggers NIS2 alone: a 24-hour early warning, a 72-hour initial notice, and a 30-day final report. The moment personal data is confirmed exfiltrated, GDPR runs in parallel: a separate 72-hour notice to the data protection authority, plus notice to affected individuals "without undue delay" if the risk is high. Two regulators, two clocks, and the facts filed must match across both. If legal isn't in the room from hour one, the compliance response becomes its own crisis, layered on top of the original.
What to rewrite this quarter
None of this requires waiting for a bigger budget cycle. It requires deciding a few things now, on paper, before you need them:
Name who has authority to negotiate and pay, and under what conditions, so that the decision isn't made for the first time mid-incident.
Run a tabletop exercise built specifically around an exfiltration-only scenario, with security, legal, and communications in the same room, not the usual encryption-and-restore drill.
Invest in egress and data-loss monitoring with the same seriousness you've given endpoint detection, and seed your environment with free canary tokens around the credentials and data stores an intruder would touch first, so staging trips an alarm before the data leaves, not after it's listed for sale.
Line up outside counsel and an IR retainer now, and make sure they know your environment before the day you actually need them.
The attackers have diversified their crime. The honest answer isn't a single new playbook to replace the old one. It's a playbook that covers both the kidnapping and the blackmail, because right now, you can't be sure in advance which one is coming through the door.
