When you think about a ransomware attack, the image that comes into your mind is maybe that of sudden paralysis of operations: the screens become black, files become renamed with some peculiar extensions, and alongside the demand for Bitcoin in exchange for data, you see the digital padlock. Encryption has always been one of the most common methods used in attacks, but with the evolution of technology and cybercrime as we know them today at mid-year 2026, the padlock has proved irrelevant. The most active and notorious criminals have decided to forget about encryption forever, and hackers like BianLian began employing a new system called "Data-Only" or "Encryption-Less" ransomware.
Here is why threat actors are leaving your operations running while quietly executing a devastating new form of extortion.
The Backup Defense and the Noise of Encryption
Oddly enough, moving away from encryption is due to the success of precautions taken. In recent years, businesses have greatly improved their backup systems. With unchangeable backups stored in the cloud and the use of automatic recovery systems in place, firms can frequently eliminate infected servers and restore their functions without needing to obtain a decryption key.
In addition, encrypting a whole company network is quite complicated and quite “noisy”. The method creates significant CPU increases and sets off instant alerts on modern Endpoint Detection and Response (EDR) systems. The criminals realized that if they tried to lock the door, they risked being detected before they were able to take the money.The Exfiltration Blitz: Silent and Deadly
Organizations such as BianLian have modified their approach by relying no longer on encryption. As a result, their current attacks revolve around information theft rather than encryption.
After infiltrating a system, these actors are found using legitimate IT means, including RClone, Azure Copy, or simple PowerShell scripts, to siphon hundreds of gigabytes of sensitive data away from the network. Since the threat group eliminates the use of encryption, their attacks result in neither encrypted files nor malfunctioned systems, with no warning bells going off.
This allows the cybercriminals to spend several months inside the victim network gathering the most valuable intellectual property.The Pure Extortion Play
If the operations are not locked, then what can possibly compel the companies to pay? Because you see, as we reach 2026, confidentiality matters much more than availability.
When an organization like BianLian comes into picture, it does not ask for money to unlock your system, but rather, asks for ransom not to release your information. This is a matter of psychological and regulatory pressure.
The Backup Fallacy: A faultless backup can restore systems, but it lacks the ability to retrieve data that has been stolen.
Regulatory Reality: Under strict regulations such as GDPR, HIPAA, and SEC rules, any violation of privacy is termed as a breach. In the event of a stolen patient profile or stolen proprietary data, the organization will incur severe penalties, lawsuits, and a loss of reputation—no matter what happened to the stolen files before.
The Mandate for Proactive Defense
The advent of data-only ransomware poses a significant challenge in the field of conventional incident response, as the system has already been infiltrated by the time the ransom note reaches the inbox of the concerned executive. In order to address such a form of ransom wear, companies need to change their emphasis from recovery to visibility of data flow in organizations. One can no longer afford to wait for alarm indications within their network.
DarkX — Using DarkX technology, companies are able to gain valuable insights needed to address data-only ransomware challenges through ongoing monitoring of criminal activity on the deep web, which enables it to determine whether corporate information has been stolen even before extortion of a company takes place.
For more research on cybersecurity, privacy, and emerging digital risks, visit:
IntelligenceX - IntelligenceX enables users to discover digital evidence in a privacy-friendly way.

Top comments (0)