{"id":360928,"date":"2026-02-18T00:10:00","date_gmt":"2026-02-18T08:10:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=410768"},"modified":"2026-02-18T00:29:21","modified_gmt":"2026-02-18T08:29:21","slug":"cybercriminals-are-changing-tactics-data-exfiltration-and-extortion-on-the-rise","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/cybercriminals-are-changing-tactics-data-exfiltration-and-extortion-on-the-rise\/","title":{"rendered":"Cybercriminals are changing tactics: Data exfiltration and extortion on the rise"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A recent report from Arctic Wolf highlights a significant shift in the tactics of cyber attackers, who <strong>have begun to abandon encryption in favor of data exfiltration and extortion.<\/strong> This shift has emerged as a response to the pursuit of better economic returns, contributing to a new wave of attacks where ransomware is no longer the sole focus. In fact, ransomware accounted for 44% of the response incidents during the analyzed period.<\/p>\n\n\n<h2 class=\"wp-block-heading\">New strategies of criminals<\/h2>\n\n\n<p class=\"wp-block-paragraph\">The manufacturing sector has become the most affected, followed by law firms, schools, financial institutions, and health organizations. These sectors account for the majority of attacks, reflecting <strong>the growing impact of cyber threats on key industries of the economy<\/strong>. Furthermore, ransomware gangs have adopted affiliate models, allowing for greater interconnection between different groups, making them more competitive and harder to stop.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The report indicates that police interactions have weakened groups like LockBit, ALPHV\/BlackCat, and BlackSuit, suggesting that law enforcement efforts have had some effect on their operability. However, <strong>other types of attacks, such as business email compromise, have proliferated, representing 26% of the cases investigated<\/strong> by Arctic Wolf. Most of these attacks have targeted financial and legal organizations, with a notable use of email phishing as the initial access method in 85% of the compared cases.<\/p>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2026\/02\/cyber-22.jpg\" alt=\"\" class=\"wp-image-410770\"\/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">In addition, <strong>attackers have shown a particular preference for compromising remote access tools,<\/strong> such as Remote Desktop Protocol and remote management software, which account for two-thirds of cases unrelated to BEC, a significant increase compared to previous years. This shift in tactics underscores the adaptability and operational maturity of cybercriminals in a constantly evolving technological landscape.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent report from Arctic Wolf highlights a significant shift in the tactics of cyber attackers, who have begun to abandon encryption in favor of data exfiltration and extortion. This turn has emerged as a response to the pursuit of better economic returns, contributing to a new wave of attacks where ransomware is no longer the only approach. In fact, ransomware accounted for 44% of response incidents during the analyzed period. New strategies from criminals The manufacturing sector has become the most affected, followed by [&hellip;]<\/p>\n","protected":false},"author":9317,"featured_media":360929,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[22350,16260,5605,1627],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-360928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-arctic-wolf","tag-ciberamenazas","tag-ciberseguridad","tag-malware"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/360928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9317"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=360928"}],"version-history":[{"count":2,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/360928\/revisions"}],"predecessor-version":[{"id":360937,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/360928\/revisions\/360937"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/360929"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=360928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=360928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=360928"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=360928"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=360928"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=360928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}