The Unit 42 2026 Global Incident Response Report analysed more than 750 major cyber incidents in over 50 countries. Its finding that matters most for ransomware readiness is that encryption based extortion declined 15% from the year before, as attackers skip encryption and move straight to data theft and disruption. In the fastest cases, initial access to exfiltration took 72 minutes.
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.
72 minutes. That is how long the fastest attackers in Unit 42’s caseload needed to go from initial access to stealing data, four times faster than the year before. The interesting part is what they increasingly did not bother to do next: encrypt anything.
Palo Alto Networks Unit 42 analysed more than 750 major cyber incidents across every major industry in over 50 countries for its 2026 Global Incident Response Report, published in February 2026 and revisited by the team on 16 July 2026. The report records that encryption based extortion declined 15% from the year before, that identity weaknesses played a material role in nearly 90% of investigations, and that misconfigurations or coverage gaps materially enabled the attack in over 90% of cases.
Your backups do not cover the thing that is growing
Unit 42 reports that encryption based extortion declined 15% from the year before, because more attackers skip encryption and move straight to data theft and disruption. From the attacker’s side the report describes this as faster and quieter, and it removes the signals defenders once relied on to detect ransomware. A restore plan answers the encryption half of extortion. It does not answer the half that is growing.
What the report measured
The scope and headline findings, as published by Unit 42:
- More than 750 major cyber incidents analysed, across every major industry, in over 50 countries.
- In the fastest cases investigated, attackers needed just 72 minutes to move from initial access to data exfiltration, four times faster than the previous year.
- Identity weaknesses played a material role in nearly 90% of investigations. The report describes attackers logging in with stolen credentials and tokens rather than breaking in.
- In 23% of incidents, attackers leveraged third party SaaS applications. 87% of intrusions involved activity across multiple attack surfaces. Nearly 48% of incidents included browser based activity.
- In over 90% of incidents, misconfigurations or gaps in security coverage materially enabled the attack. Unit 42 links this to tool sprawl, noting many organisations run 50 or more security products.
The 2026 Unit 42 report in numbers
All figures come from the Unit 42 2026 Global Incident Response Report as published on the Palo Alto Networks blog by Sam Rubin on 17 February 2026. Figures circulating elsewhere that put a precise percentage on how many extortion cases involved encryption do not appear in this source and are not used here.
The sentence that should change a recovery plan
Encryption based extortion declined 15% from the year before, as more attackers skip encryption and move straight to data theft and disruption. From the attacker’s perspective, it’s faster, quieter and creates immediate pressure without the signals that defenders once relied on to detect ransomware attacks.
Where the response window went
The report’s timeline findings matter more than its volume findings. A plan that assumes hours to notice and escalate is calibrated against an adversary that no longer takes hours. For the wider pattern, see how a ransomware attack usually unfolds.
The report’s headline percentages
What actually recurs across 750 investigations
Unit 42 2026 Global Incident Response Report, Palo Alto Networks, February 2026
What this changes in a ransomware plan
The controls below follow the specific findings above, rather than ransomware advice in general. Each addresses something the report measured.
| Control | Which finding it answers | Gap it closes |
|---|---|---|
| Identity and access tightening | Identity weaknesses material in nearly 90% of investigations | Stolen credentials treated as an endpoint problem |
| Data exfiltration detection | Encryption based extortion declined 15%; attackers move straight to data theft | Detection tuned to the encryption event that may never come |
| Third party SaaS inventory | 23% of incidents leveraged third party SaaS applications | Trusted integrations exempt from the scrutiny given to core infrastructure |
| Cross surface visibility | 87% of intrusions spanned multiple attack surfaces | Signals stitched together manually while the clock runs |
| Configuration review over tool purchase | Over 90% of incidents materially enabled by misconfiguration or coverage gaps, amid 50 or more products per organisation | Buying a product to fix a coverage problem the sprawl created |
The failure modes this report exposes
Each of the following follows from a measured finding rather than from a general concern about ransomware.
- ⛔ Equating recovery with restore. If the operator never encrypted, there is nothing to restore and the stolen copy is still gone.
- ⛔ Measuring readiness in hours when the fastest documented chain from access to exfiltration ran in 72 minutes.
- ⛔ Treating identity as an IT hygiene topic rather than the primary attack vehicle in nearly 90% of investigations.
- ⛔ Exempting vendor integrations and SaaS from scrutiny while 23% of incidents ran through them.
- ⛔ Answering a coverage gap with another product, when tool sprawl of 50 or more products is part of what the report links to the 90% misconfiguration figure.
Restoring files does not undo a data theft
When extortion moves away from encryption, backup stops being the answer and becomes only part of it. Unit 42 records that attackers increasingly skip encryption entirely and go straight to data theft and disruption. A clean restore returns your operations. It does not return the copy the operator took, and it does not remove the leverage that copy gives them.
Where the report says to start
Unit 42 distils more than 750 frontline investigations into three priorities. They are listed here in the report’s own order. For the full checklist, see our guide on preventing a ransomware attack.
- ✅ Reduce exposure. Secure the full application ecosystem and treat trusted connections, third party integrations, unmanaged SaaS and everyday browser activity with the same scrutiny as core infrastructure.
- ✅ Reduce the area of impact. Tighten identity and access management and remove unnecessary trust, which limits how far an attacker can move once inside.
- ✅ Increase response speed. Build the visibility to see across environments and the ability to detect, identify and prioritise fast enough to contain before the adversary finishes.
- ✅ Audit for misconfiguration and coverage gaps before adding tooling, given that they materially enabled the attack in over 90% of investigated incidents.
- ✅ Extend detection to data movement, not only to file encryption, so that an extortion attempt without encryption is still visible.
The methodology is the useful part
Because the report is drawn from Unit 42’s own incident response engagements rather than from survey responses, its percentages describe what responders found on the ground across more than 750 investigations. That makes it usable as a benchmark for your own assumptions. It is also the starting point for recovering encrypted files when encryption is part of the case.
Sources
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.
📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.
📅 Last updated: 17 July 2026



