Skip to content

Security1 publisher3 min readPublished

The ransom is for silence now, and your restore drill does not price that

Tom Uren and James Wilson say the cybercrime ecosystem is moving to data-theft extortion. For reputation-sensitive organisations, that puts the dominant loss outside recovery planning.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying The ransom is for silence now, and your restore drill does not price that
Generated illustration

What happened

  • In the Risky Bulletin Podcast episode 'Srsly Risky Biz: Data extortion is booming. Hooray!', dated August 13, 2026 and published by risky.biz, Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion.
  • Data theft extortion is described as stealing sensitive data and extracting ransoms from victims by threatening to leak it.
  • For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.
  • Uren and Wilson also discuss how the rise of AI makes it worth reinvigorating CISA's Secure by Design initiative.
  • If the extortion lever is threatened disclosure of stolen data rather than denial of access, then backup and restore capability does not address the dominant loss scenario for organisations whose reputation is their primary exposure.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Tom Uren and James Wilson used the August 13, 2026 edition of Srsly Risky Biz to argue that the cybercrime ecosystem is shifting toward data theft extortion: stealing sensitive data and then extracting a ransom by threatening to leak it [1][2]. According to the two, for organisations whose reputation is very important to them, a leak is a bigger threat than having their files locked up [3].

That is a claim about leverage, and leverage is what determines which of your controls is load bearing. Encryption-era extortion handed defenders a tractable engineering problem. If you invested in immutable copies, offline copies, tested restores and a time-to-restore target, you bought down a specific loss: denial of access to your own systems. Those investments remain worth having. They do not touch confidentiality. Where the criminal's only lever is threatened disclosure, a successful restore leaves the attacker's position intact, so recovery capability stops covering the dominant loss scenario for reputation-sensitive organisations [5].

The practical consequence is a measurement gap. A recovery programme reports on artefacts you control: how fast you came back, how clean the copy was, how often the drill ran. A data-theft programme has to report on things you mostly do not control after the fact: what left, who has it, and what happens when it is published. There is no equivalent of a restore for that. The nearest substitutes all sit before the incident, which is why prevention and design questions get more expensive to defer, not less.

That is the frame for the episode's second thread. Uren and Wilson also argue that the rise of AI makes it worth reinvigorating CISA's Secure by Design initiative [4]. Read alongside the extortion shift, those two segments point the same direction: if the loss you care about cannot be undone, the money moves upstream of the incident.

A caution on how much weight to put on a single episode. The published description carries no figures for incident volumes, payment rates or ransom sizes [6], and no named-victim examples. So this is a directional read of the ecosystem from two people who follow it closely, not a dataset. Treat it as a prompt to look at your own incident record rather than as a number to build a budget on.

Three things to watch. First, whether extortion crews keep bothering with an encryption payload at all, or drop it as unnecessary noise once the threatened leak alone gets paid. Second, whether the Secure by Design push gets renewed political attention and resourcing, or stays a document [4]. Third, and closest to home, whether your own exercise programme has a scenario in which nothing is encrypted, nothing is unavailable, and the only decisions on the table are legal, regulatory and communications ones. If every tabletop you have run ends with a restore, you have been rehearsing the wrong incident.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories