For years ransomware followed a predictable playbook:
break in, encrypt the network, and negotiate a payment for the decryption key.
But if you read the NegIQ-234™ dataset from NegotiatorIQ, which analyzes over 11,000 ransomware negotiation messages across 234 incidents, one thing becomes obvious:
1️⃣Encryption negotiations take a lot of time.
2️⃣Victims demand proof the decryption key works.
3️⃣Attackers must decrypt sample files.
There are delays, technical issues, and constant back-and-forth.
It’s a messy and slow negotiation process.
Criminal groups figured this out.
Why go through all that trouble?
Instead, many are shifting to a “smash-and-grab” model:
Break in → steal sensitive data → threaten to publish it.
No encryption.
No decryption proof.
No technical validation.
Just extortion.
This shift also changes one of the core assumptions behind ransomware defense.
For years, organizations were told the most important control was 𝗯𝗮𝗰𝗸𝘂𝗽𝘀. If systems were encrypted, you could restore operations and avoid paying the ransom. And that strategy worked—when encryption was the attacker’s leverage.
But in a smash-and-grab attack, backups don’t solve the problem. The systems can be restored, yet the data may already be in the hands of criminals.
The leverage becomes reputation, legal exposure, and regulatory risk, not system availability.
Which is why many organizations are starting to rethink parts of their security stack. Controls focused on protecting the data itself—things like data classification, monitoring large outbound transfers, and Data Loss Prevention (DLP)—are getting renewed attention.
In other words, the question is shifting from:
“Can we recover the systems?”
to
“Can we stop the data from leaving in the first place?”
Cybercrime didn’t just evolve.
It simplified the business model.


