Data exfiltration grows as an extortion tactic

Sophisticated groups are abandoning widespread encryption and targeting sensitive data, exploiting human errors and supply chain vulnerabilities.

 


Ransomware is evolving rapidly. The latest Coveware by Veeam® report for the second quarter of 2025 reveals a sharp increase in targeted social engineering attacks and a record surge in ransom payments, driven by more aggressive data exfiltration tactics.

Bill Siegel, CEO of Coveware by Veeam, offers the following analysis:

“The second quarter of 2025 marks a turning point in ransomware, as targeted social engineering and data exfiltration have become the new playbook. Attackers are no longer just after your backups—they are going after your people, your processes, and the reputation of your data. Organizations must prioritize employee awareness, strengthen identity controls, and treat exfiltration as an urgent risk, not a secondary concern.”

Key Findings from the Report.

Social Engineering as the Primary Threat:
Three major ransomware groups—Scattered Spider, Silent Ransom, and Shiny Hunters—led the quarter by deploying targeted attacks using impersonation techniques against help desks, employees, and service providers. These groups have shifted away from opportunistic mass attacks in favor of precise incursions.

Ransom Payments Hit Record Highs:
Average and median ransom payments soared to $1.13 million (+104% vs. Q1 2025) and $400,000 (+100% vs. Q1 2025), respectively. This increase is largely attributed to large enterprises paying after data exfiltration incidents, although the overall payment rate remained steady at 26%.

Exfiltration Replaces Encryption:
Data exfiltration was present in 74% of cases, with campaigns prioritizing data theft over system encryption. Multi-extortion tactics and deferred threats are on the rise, keeping organizations under pressure long after the initial attack.

Most Affected Sectors:
Professional services (19.7%), healthcare (13.7%), and consumer services (13.7%) were the hardest hit. Mid-sized companies (between 11 and 1,000 employees) accounted for 64% of victims, representing an ideal target due to less mature defenses.

The Human Factor Remains Vulnerable:
Credential compromise, phishing, and exploitation of remote services continue to be common initial vectors. Attackers bypass technical controls through social engineering and exploit vulnerabilities in widely used platforms such as Ivanti, Fortinet, and VMware. Lone wolf attacks with generic, unbranded kits are increasing.

New Threat Landscape:
The most common ransomware variants this quarter were Akira (19%), Qilin (13%), and Lone Wolf (9%). Silent Ransom and Shiny Hunters appeared in the top five for the first time.

Field Analysis.

The report is built on firsthand data collected during real-time incident response. Coveware employs proprietary forensic tools—such as Recon Scanner—and thoroughly documents tactics, attack vectors, threat actor behavior, and negotiation outcomes.

This approach enables practical intelligence grounded in experience, providing an up-to-date perspective on a constantly evolving threat environment.


Share:
Hosting Web
Most Read