Unit 42: extortion is moving beyond encryption, and backups do not cover it

AI Overview

The Unit 42 2026 Global Incident Response Report analysed more than 750 major cyber incidents in over 50 countries. Its finding that matters most for ransomware readiness is that encryption based extortion declined 15% from the year before, as attackers skip encryption and move straight to data theft and disruption. In the fastest cases, initial access to exfiltration took 72 minutes.

Juan Ricardo Palacio, Co-Founder of HelpRansomware

Juan Ricardo Palacio

Co-Founder and CEO for the Americas, HelpRansomware

Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.

72 minutes. That is how long the fastest attackers in Unit 42’s caseload needed to go from initial access to stealing data, four times faster than the year before. The interesting part is what they increasingly did not bother to do next: encrypt anything.

Palo Alto Networks Unit 42 analysed more than 750 major cyber incidents across every major industry in over 50 countries for its 2026 Global Incident Response Report, published in February 2026 and revisited by the team on 16 July 2026. The report records that encryption based extortion declined 15% from the year before, that identity weaknesses played a material role in nearly 90% of investigations, and that misconfigurations or coverage gaps materially enabled the attack in over 90% of cases.

Your backups do not cover the thing that is growing

Unit 42 reports that encryption based extortion declined 15% from the year before, because more attackers skip encryption and move straight to data theft and disruption. From the attacker’s side the report describes this as faster and quieter, and it removes the signals defenders once relied on to detect ransomware. A restore plan answers the encryption half of extortion. It does not answer the half that is growing.

What the report measured

The scope and headline findings, as published by Unit 42:

  • More than 750 major cyber incidents analysed, across every major industry, in over 50 countries.
  • In the fastest cases investigated, attackers needed just 72 minutes to move from initial access to data exfiltration, four times faster than the previous year.
  • Identity weaknesses played a material role in nearly 90% of investigations. The report describes attackers logging in with stolen credentials and tokens rather than breaking in.
  • In 23% of incidents, attackers leveraged third party SaaS applications. 87% of intrusions involved activity across multiple attack surfaces. Nearly 48% of incidents included browser based activity.
  • In over 90% of incidents, misconfigurations or gaps in security coverage materially enabled the attack. Unit 42 links this to tool sprawl, noting many organisations run 50 or more security products.

The 2026 Unit 42 report in numbers

750+
major cyber incidents analysed in over 50 countries
72 min
initial access to exfiltration in the fastest cases
90%
of investigations where identity weaknesses played a material role
15%
decline in encryption based extortion versus the year before

All figures come from the Unit 42 2026 Global Incident Response Report as published on the Palo Alto Networks blog by Sam Rubin on 17 February 2026. Figures circulating elsewhere that put a precise percentage on how many extortion cases involved encryption do not appear in this source and are not used here.

The sentence that should change a recovery plan

Encryption based extortion declined 15% from the year before, as more attackers skip encryption and move straight to data theft and disruption. From the attacker’s perspective, it’s faster, quieter and creates immediate pressure without the signals that defenders once relied on to detect ransomware attacks.

Unit 42, 2026 Global Incident Response Report

Where the response window went

The report’s timeline findings matter more than its volume findings. A plan that assumes hours to notice and escalate is calibrated against an adversary that no longer takes hours. For the wider pattern, see how a ransomware attack usually unfolds.

Initial access
Attackers most often log in rather than break in. Identity weaknesses played a material role in nearly 90% of Unit 42 investigations, using stolen credentials and tokens.
Expansion
Fragmented identity estates let the operator escalate privileges and move laterally without triggering traditional defences, according to the report.
Across surfaces
87% of intrusions involved activity across multiple attack surfaces: endpoints, networks, cloud, SaaS and identity, forcing defenders to watch all of them at once.
Through trusted paths
In 23% of incidents attackers leveraged third party SaaS applications, abusing trusted integrations and vendor tools to bypass the perimeter.
72 minutes
In the fastest cases investigated, that is the total elapsed time from initial access to data exfiltration, four times faster than the year before.

The report’s headline percentages

What actually recurs across 750 investigations

Unit 42 2026 Global Incident Response Report, Palo Alto Networks, February 2026

Bar chart of Unit 42 2026 report findings: identity weaknesses material in nearly 90% of investigations, misconfigurations enabling 90% of attacks, 87% multi surface intrusions, 48% browser based activity, 23% leveraging third party SaaS.

📊 Read it this way: these are recurrence rates across more than 750 investigations, not severity scores. The two tallest bars are both about the defender’s own environment, not the attacker’s sophistication.

What this changes in a ransomware plan

The controls below follow the specific findings above, rather than ransomware advice in general. Each addresses something the report measured.

Control Which finding it answers Gap it closes
Identity and access tightening Identity weaknesses material in nearly 90% of investigations Stolen credentials treated as an endpoint problem
Data exfiltration detection Encryption based extortion declined 15%; attackers move straight to data theft Detection tuned to the encryption event that may never come
Third party SaaS inventory 23% of incidents leveraged third party SaaS applications Trusted integrations exempt from the scrutiny given to core infrastructure
Cross surface visibility 87% of intrusions spanned multiple attack surfaces Signals stitched together manually while the clock runs
Configuration review over tool purchase Over 90% of incidents materially enabled by misconfiguration or coverage gaps, amid 50 or more products per organisation Buying a product to fix a coverage problem the sprawl created

The failure modes this report exposes

Each of the following follows from a measured finding rather than from a general concern about ransomware.

  • ⛔ Equating recovery with restore. If the operator never encrypted, there is nothing to restore and the stolen copy is still gone.
  • ⛔ Measuring readiness in hours when the fastest documented chain from access to exfiltration ran in 72 minutes.
  • ⛔ Treating identity as an IT hygiene topic rather than the primary attack vehicle in nearly 90% of investigations.
  • ⛔ Exempting vendor integrations and SaaS from scrutiny while 23% of incidents ran through them.
  • ⛔ Answering a coverage gap with another product, when tool sprawl of 50 or more products is part of what the report links to the 90% misconfiguration figure.

Restoring files does not undo a data theft

When extortion moves away from encryption, backup stops being the answer and becomes only part of it. Unit 42 records that attackers increasingly skip encryption entirely and go straight to data theft and disruption. A clean restore returns your operations. It does not return the copy the operator took, and it does not remove the leverage that copy gives them.

Where the report says to start

Unit 42 distils more than 750 frontline investigations into three priorities. They are listed here in the report’s own order. For the full checklist, see our guide on preventing a ransomware attack.

  • ✅ Reduce exposure. Secure the full application ecosystem and treat trusted connections, third party integrations, unmanaged SaaS and everyday browser activity with the same scrutiny as core infrastructure.
  • ✅ Reduce the area of impact. Tighten identity and access management and remove unnecessary trust, which limits how far an attacker can move once inside.
  • ✅ Increase response speed. Build the visibility to see across environments and the ability to detect, identify and prioritise fast enough to contain before the adversary finishes.
  • ✅ Audit for misconfiguration and coverage gaps before adding tooling, given that they materially enabled the attack in over 90% of investigated incidents.
  • ✅ Extend detection to data movement, not only to file encryption, so that an extortion attempt without encryption is still visible.

The methodology is the useful part

Because the report is drawn from Unit 42’s own incident response engagements rather than from survey responses, its percentages describe what responders found on the ground across more than 750 investigations. That makes it usable as a benchmark for your own assumptions. It is also the starting point for recovering encrypted files when encryption is part of the case.


Sources

Juan Ricardo Palacio, Co-Founder of HelpRansomware

Juan Ricardo Palacio

Co-Founder and CEO for the Americas, HelpRansomware

Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.

📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.

📅 Last updated: 17 July 2026

Leave a Comment

Your email address will not be published. Required fields are marked *