Spotlight: Ransomware — exfiltration versus encryption

Extortion remained the predominant cyber threat in our dataset in 2025, so we undertook a focused analysis comparing incidents involving ransomware encryption with those involving data‑theft‑only extortion claims. In 2021, ransomware was deployed in 70% of the extortion claims we recorded. By 2025, that proportion had fallen to 24%.

This shift likely reflects several dynamics: encrypting systems is more time‑consuming, while data theft is quicker and harder to detect. Widespread, improved backup practices have reduced the effectiveness of pure encryption tactics, and can accelerate data recovery. Threat actors increasingly favour data‑theft and cyber extortion because it remains financially attractive. Although payment rates are trending down, organisations still sometimes pay, depending on the nature of the stolen data (e.g. if it’s sensitive information), the nuances of the incident, and potential reputational harm.

AI’s impact on cyber risk

As the generative AI adoption expands across industries, so does the potential cyber threat associated with new types of cyberattacks, such as the use of deep fakes and the growing relevance of real time access controls for critical workflows.

AI-enabled attacks threaten to change the face of the risk landscape, highlighting the importance of ensuring appropriate steps are taken to best manage the risk, such as:

Regularly conducting AI-specific fraud training for all employees.
Sufficiently vetting unusual requests via secure channels of communication.
Mandating the proper verification protocols for all high-risk requests, irrespective of source or seniority.
Ensuring a sufficient incident response plan is in place and escalations considered, should an impersonation attempt take place.