Security1 distinct publisher3 min readUpdated
Tom Uren and James Wilson say the cybercrime ecosystem is moving to data-theft extortion. For reputation-sensitive organisations, that puts the dominant loss outside recovery planning.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Tom Uren and James Wilson used the August 13, 2026 edition of Srsly Risky Biz to argue that the cybercrime ecosystem is shifting toward data theft extortion: stealing sensitive data and then extracting a ransom by threatening to leak it [1][2]. According to the two, for organisations whose reputation is very important to them, a leak is a bigger threat than having their files locked up [3].
That is a claim about leverage, and leverage is what determines which of your controls is load bearing. Encryption-era extortion handed defenders a tractable engineering problem. If you invested in immutable copies, offline copies, tested restores and a time-to-restore target, you bought down a specific loss: denial of access to your own systems. Those investments remain worth having. They do not touch confidentiality. Where the criminal's only lever is threatened disclosure, a successful restore leaves the attacker's position intact, so recovery capability stops covering the dominant loss scenario for reputation-sensitive organisations [5].
The practical consequence is a measurement gap. A recovery programme reports on artefacts you control: how fast you came back, how clean the copy was, how often the drill ran. A data-theft programme has to report on things you mostly do not control after the fact: what left, who has it, and what happens when it is published. There is no equivalent of a restore for that. The nearest substitutes all sit before the incident, which is why prevention and design questions get more expensive to defer, not less.
That is the frame for the episode's second thread. Uren and Wilson also argue that the rise of AI makes it worth reinvigorating CISA's Secure by Design initiative [4]. Read alongside the extortion shift, those two segments point the same direction: if the loss you care about cannot be undone, the money moves upstream of the incident.
A caution on how much weight to put on a single episode. The published description carries no figures for incident volumes, payment rates or ransom sizes [6], and no named-victim examples. So this is a directional read of the ecosystem from two people who follow it closely, not a dataset. Treat it as a prompt to look at your own incident record rather than as a number to build a budget on.
Three things to watch. First, whether extortion crews keep bothering with an encryption payload at all, or drop it as unnecessary noise once the threatened leak alone gets paid. Second, whether the Secure by Design push gets renewed political attention and resourcing, or stays a document [4]. Third, and closest to home, whether your own exercise programme has a scenario in which nothing is encrypted, nothing is unavailable, and the only decisions on the table are legal, regulatory and communications ones. If every tabletop you have run ends with a restore, you have been rehearsing the wrong incident.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
In the Risky Bulletin Podcast episode 'Srsly Risky Biz: Data extortion is booming. Hooray!', dated August 13, 2026 and published by risky.biz, Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion.
Data theft extortion is described as stealing sensitive data and extracting ransoms from victims by threatening to leak it.
For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.
Uren and Wilson also discuss how the rise of AI makes it worth reinvigorating CISA's Secure by Design initiative.
The published episode description contains no figures for incident volumes, ransom payment rates or ransom amounts, and no named victim organisations.
If the extortion lever is threatened disclosure of stolen data rather than denial of access, then backup and restore capability does not address the dominant loss scenario for organisations whose reputation is their primary exposure.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source assertion, no data
The entire cluster rests on one four-sentence podcast episode blurb from a single publisher. The core claims are the presenters' characterisations, not measurements: no incident counts, no payment or ransom figures, no named victims, no methodology, and no corroborating source.
No adoption signal in supplied sources
The supplied material records no releases, deployments, benchmarks, disclosed incidents, pricing or licence changes, or usage data. Attacker-behaviour prevalence and defender-practice change would both be needed to score adoption, and neither is present.
Framing outruns the stated evidence
The episode is titled 'Data extortion is booming. Hooray!' and the cluster headline extends this into a claim about restore drills mispricing risk, yet the supplied text offers no volumes, trend series, or cases - and says nothing about backup or recovery planning. The direction of the claim is plausible and internally consistent, so the overstatement is one of certainty and scope rather than of substance.
No disclosed sponsorship or interest
The body includes a bare 'Presented by' line with no named sponsor, and the supplied material discloses no commercial relationships, vendor ties, or funding for the publisher or presenters. Inferring an incentive structure from a podcast format alone would be guesswork.
Low - one thin source, no corroboration
Confidence is limited by a single publisher, a summary-length body, absent quantification, and no adoption signal. What can be said with confidence is only that the presenters made these characterisations on this date; the underlying trend and its programme implications remain unverified here.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
invest
A $5,615 Receipt Gap and a $100,000 Car: Amalgamated's Expense Fight Heads to Discovery1 distinct publisher
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 13, 2026