Ransomware attacks are entering a new phase, with threat actors shifting from traditional file encryption to more complex and targeted extortion models. According to insights published by Cyber Resilience, attackers increasingly focus on data exfiltration and multi-layered extortion, placing reputational and regulatory pressure on victims rather than relying solely on operational disruption.
The now-standard “double extortion” model - encrypting systems while simultaneously stealing sensitive data - has in many cases evolved further. Some groups threaten customers or business partners directly or launch additional distributed denial-of-service (DDoS) attacks to intensify pressure. In parallel, so-called “encryption-less” attacks are gaining traction, where criminals skip encryption altogether and rely exclusively on the threat of data exposure.
Faster attacks, higher systemic exposure
The acceleration of attack cycles is another defining trend. Exploits are often deployed within hours of vulnerability disclosure, supported by automation and AI-enabled reconnaissance tools. Target selection has also become more strategic, with critical infrastructure, healthcare providers and financial institutions remaining prime objectives due to their low tolerance for downtime.
Supply-chain vulnerabilities continue to amplify systemic risk. By compromising a single service provider or software vendor, attackers can gain access to multiple organizations simultaneously - raising concerns not only for corporate risk managers but also for (re)insurers assessing accumulation exposure.
Underwriting and risk modelling under pressure
For cyber insurers, the evolving tactics translate into heightened severity risk and increased uncertainty in loss modelling. Data exfiltration without encryption may limit business interruption losses but significantly increase liability, regulatory fines and reputational damage claims. The growing sophistication of ransomware-as-a-service (RaaS) ecosystems further complicates threat assessment.
As a result, underwriting discipline, clearer policy wording and stricter cybersecurity requirements are becoming central to portfolio resilience. Insurers are also intensifying scrutiny of clients’ incident response capabilities, backup strategies, multi-factor authentication implementation and third-party risk management.
The overarching message is clear: ransomware is no longer merely a technical threat - it is a systemic and strategic risk. For insurers and reinsurers, understanding the rapidly shifting threat landscape will remain critical in balancing growth opportunities in the cyber line with prudent capital management and sustainable pricing.
You may get further insight in the cyber risks trends by visiting the Resilience blog.
Multi-Layered extortion redefines the cyber insurance landscape
26 February 2026 — Daniela GHETU
18419 views