Data Theft Extortion Is Booming! Hooray! Data Theft Extortion Is Booming! Hooray! The cybercriminal ecosystem is increasingly focusing on data theft and extortion rather than locking up victims' files. That criminals have stumbled across a new lucrative business model is a bittersweet win in the fight against disruptive, encrypting ransomware. Data theft extortion isn't great, but it doesn't leave widespread chaos in its wake like ransomware can. Silent Ransom, aka Luna Moth, is one group currently making big bucks from data theft extortion. Last week The Cyber Risk Insurer reported two law firms had paid substantial ransoms to the group this year: Goodwin Procter and WilmerHale, which paid $10 million and $18 million, respectively. Silent Ransom has been targeting law firms since 2023. It historically used phishing and convinced victims to install legitimate remote access software, which was then used to steal sensitive data. In the past year, however, they've brazenly sent people to compromise systems in person by posing as information technology (IT) support staff. Its data exfiltration process prioritizes speed over completeness. Google's Threat Intelligence Group (GTIG) says the groups' entire attack process, from initial target contact to data theft and extortion, is often completed within a single day. With ransom payments in the millions, that works out to a pretty good hourly rate. Another group that emerged in early 2026 was BlackFile, which now calls itself Redact. The group has also targeted similar organizations, but its data exfiltration is more comprehensive. Redact gains initial access using sophisticated high-volume voice phishing attacks (vishing) to steal credentials from victim organizations. It then uses these credentials to steal data from OneDrive and Sharepoint. It also pivots out to other software-as-a-service applications. GTIG says BlackFile spent April and May this year targeting enterprises in the real estate, health care, and insurance