Executive Snapshot
Ransomware response is increasingly a business-resilience problem, not only an encryption problem. Current government reporting, threat-intelligence monitoring, and incident research show continued ransomware pressure alongside data-theft-only extortion, identity-focused access, and public leak tactics. [1] [2] [3] [4] [5] Each source measures a different population, so the useful executive signal is the direction of pressure - not a single universal incident rate.
U.S. Reporting Still Shows Material Ransomware Activity
The FBI's 2025 IC3 Annual Report says IC3 received more than 3,600 ransomware complaints in 2025, with reported losses exceeding $32 million. The FBI explicitly notes that those losses do not normally include lost business, time, wages, files, equipment, or third-party remediation, and that reporting is incomplete. [1].
Monitored Leak-Site Activity Reached a 2026 High in August
NCC Group reported 1,073 ransomware attacks in August 2026, up 12% from July and the highest monthly figure it recorded in 2026 to that point. [2] This is threat-intelligence monitoring rather than a census of all ransomware incidents, but it shows sustained pressure across regions and sectors.
The United States Remains Prominent in Leak-Site Listings
Rapid7's Q2 2026 threat-landscape research recorded 881 U.S. ransomware leak-site listings in the quarter, roughly nine times Germany, the next country in its ranking. [3] Leak-site listings reflect extortion claims and should not be treated as verified breach counts, but they remain useful for understanding adversary publication behavior.
Data Theft Can Create Extortion Without Encryption
Mandiant reported that from January through May 2026, UNC3753 targeted dozens of U.S. professional, legal, and financial-services organizations in a data-theft extortion campaign using vishing and remote-access tools. [4] The observed activity shows why a ransomware program also needs controls for identity, remote access, sensitive-data access, and extortion response when no encryptor is deployed.
SaaS Identity Is Now Part of the Extortion Surface
Google Threat Intelligence Group's January 2026 reporting on ShinyHunters-branded activity describes credential harvesting, unauthorized MFA enrollment, SaaS data exfiltration, extortion emails, and reports of DDoS pressure. [5] The case demonstrates how access to trusted cloud identities can create several pressure vectors without following a traditional endpoint-encryption path.
CyberTech Intelligence Perspective
The strongest multi-extortion response starts with one verified fact pattern. Leaders need to know which identities are compromised, what data can be reached, which services are disrupted, what recovery options remain trustworthy, and which attacker claims are supported by evidence. That view reduces the risk of letting leak-site posts, ransom notes, or incomplete technical signals drive business decisions on their own.
Five Questions for the Next Leadership Review
-
Can we distinguish a ransomware complaint, an attacker leak-site claim, an internal incident, and a verified data-theft event in our reporting?
-
Which identities and SaaS platforms could give an attacker access to sensitive data without deploying ransomware?
-
Which critical services have a tested minimum viable operating state if systems must remain isolated during investigation?
-
Who owns the verified-facts register for encryption, data theft, disruption, recovery, and external disclosure?
-
Can leadership see when an assumption changes and which decision must be revisited?
Read the Deeper Evidence Model
Use these five questions as an executive scan. Then move to the CyberTech Intelligence Research Report for this campaign to compare current ransomware and extortion evidence, the multi-extortion framework, decision metrics, and readiness model with your own incident and recovery approach.
About CyberTech Intelligence
CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education, decision support, and claim-safe GTM planning.
Evidence and Citation Note
This newsletter uses government reporting, threat-intelligence monitoring, and incident research only within each source's stated scope. Complaints, leak-site listings, and observed intrusion cases are different evidence types and are not combined into a universal prevalence estimate. CyberTech Intelligence does not infer a current incident, data loss, resilience gap, project, or buying posture for any named organization without direct evidence.
References
- Federal Bureau of Investigation, “2025 IC3 Annual Report,” 2026. https://www.fbi.gov/file-repository/2025_ic3report.pdf (Accessed September 25, 2026. Relevance: U.S. complaint reporting on ransomware in 2025, including stated loss limitations and reporting caveats.)
- NCC Group, “Monthly Threat Pulse – Review of August,” September 2026. https://www.nccgroup.com/newsroom/ncc-group-monthly-threat-pulse-review-of-august/ (Accessed September 25, 2026. Relevance: NCC Group monthly threat-intelligence monitoring showing August 2026 ransomware activity, sector, region, and group patterns.)
- Rapid7 Labs, “Quarterly Threat Landscape Report: Q2 2026,” 2026. https://www.rapid7.com/research/report/quarterly-threat-landscape-report/ (Accessed September 25, 2026. Relevance: Q2 2026 vulnerability, identity, ransomware leak site, and sector observations, including 881 U.S. listed victims within the report's methodology.)
- Google Threat Intelligence Group / Mandiant, “Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms,” June 5, 2026. https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms (Accessed September 25, 2026. Relevance: observed U.S. data-theft extortion campaign using vishing and remote-access techniques without requiring a traditional encryptor.)
- Google Threat Intelligence Group / Mandiant, “Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft,” January 30, 2026. https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft (Accessed September 25, 2026. Relevance: observed SaaS data theft, identity compromise, extortion communication, and reported DDoS pressure.)