Cybersecurity Shift: Ransomware Hackers Increasingly Favor Data Theft Over Encryption
A recent report highlights a significant shift in ransomware tactics, with cybercriminals increasingly focusing on data theft and extortion rather than traditional file encryption. This change comes as manufacturers bolster their cybersecurity defenses, making it more difficult for attackers to successfully encrypt data.
The report, focusing on the manufacturing and production sectors, reveals a notable decrease in successful encryption attacks.
- Encryption rates in ransomware attacks against manufacturers have plummeted to just 40% this year.
- This marks a significant decline from 74% in the previous year and represents the lowest rate in the past five years.
- While companies are becoming more adept at preventing encryption, attackers are adapting by prioritizing data exfiltration as a means of leverage.
The Rise of Extortion-Only Attacks
Extortion-only attacks, where data is stolen but not encrypted, are becoming increasingly prevalent.
- These attacks have surged to 10% of all ransomware incidents, a substantial increase from 3% the previous year.
- Data theft is now a key pressure tactic, with 39% of manufacturers experiencing encryption also reporting data exfiltration. This is one of the highest rates across all sectors surveyed.
Despite Improved Detection, Ransom Payments Persist
Despite advancements in early attack detection, a significant portion of affected manufacturers continue to pay ransom demands.
- 51% of organizations that experienced data encryption paid the ransom.
- The median ransom payment was $1 million, compared to median demands of $1.2 million.
Manufacturers Intercepting Attacks Earlier
On a positive note, manufacturers are showing increased effectiveness in intercepting attacks before they cause widespread damage.
- 50% of organizations reported stopping attacks before any data could be encrypted.
- This is more than double the 24% reported in the previous year.
The Impact on Manufacturing Operations
The manufacturing sector is particularly vulnerable to ransomware attacks due to its reliance on interconnected systems.
- Even brief periods of downtime can halt production and disrupt entire supply chains.
- Attackers are aware of this vulnerability and exploit the pressure it creates.
- Despite the decrease in encryption rates, the median ransom payment remains high at $1 million, highlighting the significant financial impact of these attacks.
Internal Weaknesses Expose Manufacturers to Breaches
The report identifies several internal weaknesses that contribute to manufacturers’ vulnerability to cyberattacks.
- 42% of respondents cited a lack of in-house cybersecurity expertise as a contributing factor.
- 41% pointed to unknown security gaps in their systems.
- Another 41% acknowledged inadequate protective measures.
- On average, manufacturers identified three internal weaknesses that led to successful attacks.
Recovery Costs and Staff Stress
While recovery costs are improving, the pressure on internal teams is increasing.
- The average cost of recovery, excluding ransom payments, has decreased by 24% to $1.3 million.
- 58% of organizations recovered within one week of an attack, compared to 44% the previous year.
- However, 47% reported increased staff stress following an encryption incident.
- 27% said the attack contributed to leadership changes within their organization.
Prominent Ransomware Groups Targeting Manufacturing
Several ransomware groups have been actively targeting the manufacturing sector.
- In the past year, 99 ransomware groups have been identified targeting manufacturing.
- The most active groups include GOLD SAHARA (Akira), GOLD FEATHER (Qilin), and GOLD ENCORE (PLAY).
- In over half of the incidents investigated by emergency response teams, attackers both stole and encrypted data, highlighting the growing trend of double-extortion tactics.
Recommendations for Reducing Cyber Risk
To mitigate cyber risks, manufacturers are advised to implement the following measures:
- Address root-cause vulnerabilities in their systems.
- Strengthen endpoint protection to prevent initial breaches.
- Regularly test incident-response plans to ensure preparedness.
- Maintain reliable data backups to facilitate recovery.
- Adopt round-the-clock monitoring, particularly through managed detection and response (MDR) providers.

















