Blog post

The Rise of Pure Data-Theft Extortion: Why Encryption Is No Longer the Point

June 2026 marked a shift from ransomware to pure data-theft extortion. Breaches at One Medical, NAIC, and Novo Nordisk show that encryption is no longer the weapon — data exfiltration is.

June 2026 was a brutal month for data security — and not in the way most organisations prepare for.

The biggest breaches of the month had one thing in common: nothing was encrypted. Attackers simply stole data, then demanded payment not to unlock it, but to not publish it. This is pure data-theft extortion, or “pay-or-leak”, and it is rapidly replacing ransomware as the dominant threat model.

What Changed

Ransomware traditionally worked by encrypting files and demanding payment for the decryption key. Defenders responded with offline backups, faster containment, and immutable storage — making encryption-based attacks harder to profit from.

Attackers adapted. Now they skip encryption entirely. They exfiltrate data over days or weeks, then threaten to leak it publicly unless the victim pays. Backups and containment do nothing when data is already gone.

June 2026 Case Studies

One Medical (Amazon) — ShinyHunters claimed 8.8 TB of legacy patient records after breaching a third-party file storage provider. The data included medical histories and personal identifiers.

National Association of Insurance Commissioners (NAIC) — 3.1 TB exfiltrated via an Oracle PeopleSoft zero-day, affecting all 50 state insurance departments. Regulators’ own data was the breach vector.

Novo Nordisk — A single exposed developer credential led to the loss of clinical trial data, proprietary source code, and AI models. One token, catastrophic damage.

Madison Square Garden — 26 million records published after the company refused to pay. The leaked dataset included facial recognition surveillance data — a privacy and legal exposure on top of the breach itself.

DentaQuest — 2.6 million people’s data leaked, including Medicaid IDs. Healthcare continues to be the most targeted sector.

Why This Matters for Defenders

The playbook for pure data-theft extortion is different from ransomware response:

  • Backups do not help. The data is already stolen — restoring from backup does not undo the leak threat.
  • Fast containment does not help. By the time you detect the intrusion, the data is already on the attacker’s infrastructure.
  • The only variable is data usability. Whether stolen data can be exploited depends on decisions made long before the breach — encryption at rest, access controls, data classification, and monitoring of unusual data access patterns.

What to Do Differently

Security thinking needs to shift from perimeter defence to data-layer protection.

  1. Encrypt data at rest and in transit — not just for compliance, but so that exfiltrated data is unusable. This sounds obvious, but few organisations do it consistently across legacy systems.

  2. Monitor data access patterns, not just network traffic. A user downloading 8.8 TB of records is an abnormal event that should trigger alerts regardless of authentication status.

  3. Classify and minimise legacy data. Most of June’s exposures lived in systems and third-party repositories that victims had stopped actively managing. Automated discovery and periodic data sweeps reduce the blast radius.

  4. Assume breach and design for it. If an attacker gains valid credentials, how much data can they actually reach? Zero-trust architectures and just-in-time access limit the surface.

The Bigger Picture

Pure data-theft extortion represents a maturity shift in the cybercrime economy. Ransomware required operational complexity: deploying encryption across a network, managing decryption keys, negotiating payment infrastructure. Data-theft extortion is simpler — steal, threaten, collect — and harder to defend against with traditional tools.

As PKWARE’s June analysis put it: “The extortion model is now theft, not encryption.” Defenders who haven’t updated their incident response plans since the ransomware era need to catch up.

Related What I Do

These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.

Continue reading

Based on shared categories first, then the strongest overlap in tags.