見出し画像

[IT] Vol.35 | Ransomware Enters the "No Encryption" Era — AI Cuts Breach-to-Exploit Time to Just 4 Days

In 2026, ransomware attack tactics have shifted dramatically. Stealing data and threatening to expose it — without ever encrypting files — has become the dominant approach, and AI is dramatically accelerating attack speed. This article explains, in about 3 minutes, why the tactics have changed and how companies and individuals can prepare.

Background

Ransomware attacks used to center on encrypting a company's data to make it unusable, then demanding a ransom in exchange for restoring access. But starting in 2026, attacks that skip the "encryption" step entirely have become increasingly common.

This is the so-called "data-theft-only" variant of double extortion: attackers steal the data first, then threaten "pay up, or we expose it." Encryption is easy to detect and easy for companies to recover from using backups, making it a costly, high-risk step for attackers relative to the payoff. By specializing in theft alone, attackers can pull off extortion faster and with less risk. In just the first half of 2026 (January through June), 4,217 such attacks were recorded worldwide — an average of 23 per day.

Why Is This a Hot Topic Now?

What stands out is how dramatically AI has compressed the timeline of an entire attack.

The time between a vulnerability being discovered and actually being exploited has shrunk to as little as four days. There are also early signs of "agentic AI ransomware" — systems that autonomously handle everything from target selection to lateral movement within a victim's internal network.

On top of that, "device code phishing" — which abuses legitimate cloud authentication mechanisms — is spreading. Rather than forcibly "breaking in," this technique impersonates a legitimate procedure to "log in with legitimate credentials," making it hard to catch with conventional security measures. This has already surfaced in real incidents: in the attack on frozen-food giant Nichirei, a group claiming responsibility asserted on the dark web that it had stolen financial records and business partner documents.

What Happens Next?

The assumption that "no encryption means no danger" no longer holds. If anything, there's growing concern about cases where data is quietly exfiltrated and the victim only finds out later, through an extortion attempt or a leak.

Companies now need, in addition to intrusion-prevention measures, systems that can quickly detect suspicious authentication activity and data exfiltration. With AI accelerating the attacker's side, defenders are increasingly forced into a speed contest of their own.

What Do You Think?

Now that you know "steal data and threaten to expose it" has become the dominant tactic, do you think your own workplace's security measures are adequate? Do you feel confident you could spot an attack disguised as a legitimate login screen?

Editor's Note

Personally, the scariest part is that not encrypting anything makes the breach harder to notice. And when the technique isn't a break-in but an impersonation of a legitimate login procedure, it feels like something that could catch even a careful person off guard. If I were a company's security lead, I'd start by building systems to detect suspicious authentication and data exfiltration. It really does feel like defenders now have to operate with the same urgency as the attackers.


📂 Read more articles → note.com/news_translator


News Translator|Making complex news easy to understand. Follow for weekly bilingual news articles.

いいなと思ったら応援しよう!

この記事は noteマネー にピックアップされました

noteマネーのバナー