Skip to main content
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemunderground-data-leakbusiness-email-compromise

Ransomware and Cyber-Extortion Trends: Shift to Data Theft and Evolving RaaS Ecosystem

Updated 2mo agoFirst seen Mar 6, 20266 sources

Cyber insurance and threat reporting indicate ransomware operators are increasingly leaning on data theft and extortion as organizations improve backup and recovery. Coalition’s 2025 claims data (across 100,000+ policyholders) shows business email compromise (BEC) and funds transfer fraud (FTF) dominated claims volume, while ransomware represented a smaller share but featured sharply higher initial demands (average just over $1.0M, with some as high as $16M) even as average loss severity declined—consistent with improved restoration and response reducing the leverage of pure encryption-only attacks.

In parallel, the broader ransomware ecosystem continues to reorganize rather than shrink despite sustained law-enforcement disruption of major RaaS brands (e.g., LockBit/Hive/ALPHV), with reporting citing high victim-post volumes across dozens of active operations. Halcyon reported a tactical shift among pro-Iranian/pro-Palestinian-aligned operators away from Sicarii toward BQTLock (Baqiyat 313 Locker), including promotion of “free” RaaS access via Telegram and targeting focused on the UAE, US, and Israel. Separately, ShinyHunters claimed a major theft from AI merchant-data platform Woflow (alleging internal data, PII, and transaction/order details) but provided no sample for verification at the time of reporting, while a separate SC Media piece used the SoundCloud incident (reported exposure of data tied to ~29.8M accounts) to highlight incident-response and crisis-management considerations rather than new technical findings.

Share:
Ransomware and Cyber-Extortion Trends: Shift to Data Theft and Evolving RaaS Ecosystem
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 31, 20262mo ago

Leak Bazaar advertises service to monetize ransomware-stolen data

A newly advertised dark-web service called Leak Bazaar proposed processing data stolen by ransomware gangs into structured, searchable intelligence for sale or more targeted extortion. Researchers said the model could increase pressure on victims and enable follow-on crimes, though its practicality remained unproven.

New criminal service plans to monetize data stolen by ransomware gangs | The Record from Recorded Future News
Mar 6, 20263mo ago

Coalition reports ransomware losses fall as data theft pressure rises

Coalition published 2025 cyber insurance claims findings showing ransomware accounted for 21% of claims, with frequency flat and average loss severity down, even as initial ransom demands rose sharply. The report said improved backup recovery was reducing impact, but dual-extortion and data theft remained prevalent, with VPNs the most frequently targeted technology in confirmed ransomware intrusions.

Mar 5, 20263mo ago

ShinyHunters claims breach of Woflow and sets leak deadline

ShinyHunters allegedly claimed it had compromised Woflow and stolen hundreds of millions of corporate and customer records, including internal data, PII, and transaction details. The group threatened to leak the data on March 6, while Woflow had not responded publicly and no sample was provided to verify the claim.

Sicarii affiliates are redirected to BQTlock RaaS

After Sicarii's administrator said the group could not handle a surge in affiliate requests, operators were redirected to the Baqiyat 313 Locker (BQTlock) RaaS platform. Halcyon said BQTlock was being promoted via Telegram, including free access for hacktivists targeting the 'Zionist entity.'

Feb 25, 20263mo ago

Pro-Iranian operators are urged to use Sicarii despite defects

In late February 2026, pro-Iranian ransomware operators were pushed to use Sicarii more broadly even though the malware reportedly had defects that made decryption impossible. This marked an attempted expansion of Sicarii before operators were later redirected elsewhere.

Jul 1, 202511mo ago

BQTlock begins targeting organizations in UAE, US, and Israel

Halcyon reported that the pro-Iran-aligned BQTlock ransomware operation had been targeting organizations in the UAE, the United States, and Israel since July 2025. The group was described as combining political messaging with double-extortion tactics.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.