Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Ransomware is evolving — and so are the stakes.

  1. Home   »  
  2. Ransomware is evolving — and so are the stakes.

Ransomware is evolving — and so are the stakes.

August 25, 2025September 22, 2026 admincybersecurity

Ransomware is no longer just about encrypting files. Leading groups now steal sensitive data first, encrypt systems second, and then use the threat of publishing that data to pressure victims into paying. Some skip encryption altogether and rely on theft and blackmail alone.

That shift changes the defensive math. For years the standard advice was that good, tested backups would let you recover without paying. Backups still matter, but they do nothing about stolen data. When the leverage is the threat of exposing customer records, employee files or confidential contracts, recovery from backup does not end the crisis. Resilience now has to include preventing and detecting data theft, not only restoring systems.

Two groups that illustrate the shift

Akira has been one of the most active ransomware operations since it appeared in March 2023. A joint US and international advisory in April 2024 reported that it had affected more than 250 organizations and collected roughly 42 million dollars in ransom proceeds. Akira typically gains access through VPNs and remote-access appliances without multi-factor authentication or with unpatched vulnerabilities. In July and August 2025 it was linked to a surge of intrusions through SonicWall SSL VPN devices, which SonicWall attributed to an older, already-patched flaw (CVE-2024-40766) on devices where credentials had not been reset after upgrading. Akira steals data before encryption and runs a leak site to pressure victims.

Dire Wolf is a newer group that emerged in May 2025. Within its first weeks, researchers at Trustwave SpiderLabs counted 16 victims across 11 countries, mainly in manufacturing and technology, with the United States and Thailand most affected. Its ransomware is written in Go, disables Windows event logging and recovery options, and is customized for each victim. The group follows a double-extortion model, giving victims a deadline before publishing stolen data, with reported demands around 500,000 dollars.

Neither group relies on novel techniques. Their success comes from exploiting ordinary weaknesses at scale: exposed remote access, missing MFA, slow patching and limited monitoring.

A typical intrusion follows a familiar sequence. The attacker logs in through a VPN or remote desktop service using stolen or guessed credentials, explores the network with legitimate administrative tools, collects credentials with higher privileges, copies sensitive files to an external server, and only then deploys ransomware, often overnight or on a weekend. Each stage is an opportunity for detection, which is why the defensive plan below maps to each one.

Why backups alone are no longer enough

Encryption-only ransomware was a business continuity problem. Double extortion is also a data breach. That brings consequences that backups cannot address:

  • Regulatory obligations. Stolen personal, health or financial data can trigger breach notification duties under state laws, HIPAA, or sector regulators, regardless of whether you pay.
  • Customer and partner trust. Published contracts, pricing or client data can damage relationships long after systems are restored.
  • Repeat pressure. Paying does not guarantee deletion. Stolen data can be resold, reused or leaked later.
  • Supply chain exposure. Manufacturers and service providers often hold partner data, so a single incident can spread harm across a supply chain.

There are signs that victims are pushing back. Blockchain analysis firm Chainalysis estimated that ransomware payments fell by about 35 percent in 2024, to roughly 814 million dollars, as more organizations refused to pay. Refusing is far easier when you can show exactly what data was taken and have a plan for handling it.

A resilience strategy for modern extortion

Effective defense addresses each stage of the attack: getting in, moving around, stealing data and encrypting systems.

  1. Close the front door. Require phishing-resistant MFA on all VPN, remote desktop and cloud administrator access. Patch internet-facing devices within days, and reset credentials after major firmware upgrades, as the SonicWall incidents showed.
  2. Limit lateral movement with Zero Trust. Segment networks, remove standing administrator rights, and restrict which systems can talk to backup servers and domain controllers.
  3. Know where sensitive data lives. Classify and inventory it. You cannot protect, or later assess the exposure of, data you have not mapped.
  4. Deploy data loss prevention and egress monitoring. Alert on unusual volumes of data leaving the network, especially to file-sharing and cloud storage services attackers commonly use for exfiltration.
  5. Monitor for defense evasion. Treat disabled event logs, deleted shadow copies and stopped security services as high-priority alerts, since groups like Dire Wolf do exactly this.
  6. Keep immutable, offline backups. They remain essential for recovery, and should be isolated so attackers cannot delete them.
  7. Share and consume threat intelligence. Follow CISA #StopRansomware advisories and industry information-sharing groups for current attacker techniques.
  8. Train staff and rehearse. Run awareness training and tabletop exercises that include legal, communications and leadership, not just IT.

Ransomware as a business and geopolitical risk

Ransomware is no longer only an IT problem. Attacks on hospitals, manufacturers, municipalities and critical suppliers have disrupted patient care, production lines and public services. Some groups operate from jurisdictions that do not cooperate with Western law enforcement, and governments increasingly treat major ransomware campaigns as a national security issue. For business leaders, that means ransomware belongs on the risk register alongside supply disruptions and regulatory exposure, with board-level oversight and an incident response plan that has been tested. Our article on double-extortion ransomware targeting multinationals and governments explores this in more depth, and our guide to stricter patch deadlines covers the patching discipline that closes the most common entry points.

Update (September 2026): In November 2025 CISA and partner agencies updated their Akira advisory, reporting that the group had collected roughly 244 million dollars in ransom proceeds as of late September 2025, a sign of how effective ordinary initial-access weaknesses remain.

Frequently asked questions

Should we pay a ransom if our data is stolen?

That is a business and legal decision, but payment does not guarantee the data will be deleted or not leaked later. Consult legal counsel and law enforcement, and check sanctions restrictions before any payment. Preparation that reduces your dependence on paying is the better investment.

What is double extortion?

It is a tactic in which attackers steal data before encrypting systems, then demand payment both to restore access and to prevent publication of the stolen information.

Are small and mid-sized businesses really targeted?

Yes. Groups such as Akira routinely hit smaller organizations because they are more likely to have exposed remote access without MFA and fewer resources for monitoring.

Prepare for the next wave

Delana Technologies helps organizations reduce ransomware risk end to end, from securing remote access and deploying data loss prevention to building and testing incident response plans. Explore our cybersecurity and compliance services, call 239.414.5126 or contact us.


Sources: CISA and partners, #StopRansomware: Akira Ransomware advisory AA24-109A (April 2024, updated November 2025); Trustwave SpiderLabs research on Dire Wolf, as reported by Dark Reading (2025); SonicWall advisories on Gen 7 SSL VPN activity and CVE-2024-40766 (August 2025); Chainalysis 2025 Crypto Crime Report on ransomware payments.

Post navigation

Previous: Security in 2025 demands more than firewalls and passwords.
Next: Espionage in the digital era is hiding in plain sight.

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC