Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Emerging from the shadows: Navigating the dynamics of the cyber extortion economy

May 31, 2026 | Threat Intelligence Research

Shift in Data Extortion Tactics: A Decline in Ransomware Encryption

TL;DR
Recent research from Unit 42 indicates a significant reduction in the use of ransomware encryption to pressure victims for payments, as attackers increasingly favor direct data theft and extortion techniques. This trend highlights an emerging threat landscape shaped by evolving attacker tactics and regulatory environments.

Main Analysis
Unit 42 has observed a marked decline in the use of encryption in extortion-related incidents, with only 78% of cases involving encryption in 2025, down from levels surpassing 90% in previous years. Supporting this trend, Google reported a rise in data theft and extortion incidents from 2% in 2020 to 15% in 2025, while Resilience noted an increase in pure extortion incidents, particularly among mid-sized organizations. This shift may be attributed to enhanced recovery and backup capabilities, the growing maturity of endpoint defenses, and regulatory frameworks that impose stringent compliance requirements, thereby incentivizing organizations to pay extortion demands to avoid hefty penalties and reputational damage.

Prominent threat actors such as Bling Libra and Hazy Scorpius exemplify this transition, focusing on direct data theft rather than relying on ransomware. Specifically, organizations within Professional Services, Healthcare, and Consumer Services have become primary targets, with mid-sized businesses representing 64% of victims. Sectors like Construction, which have seen a 44% year-over-year increase in data-only extortion incidents, signify a shift in attacker focus, facilitated by the lucrative nature of the data they handle.

The current extortion landscape is heavily influenced by regulatory frameworks, which are leveraged by attackers to expedite negotiations with organizations under pressure. The urgency to comply with mandates such as the SEC’s disclosure requirements and GDPR’s reporting timelines accelerates the likelihood that organizations will acquiesce to extortion demands to mitigate potential financial repercussions.

Defensive Context
This evolving threat landscape primarily impacts organizations that manage sensitive data, particularly in highly regulated sectors. Mid-sized firms in industries such as Professional Services and Healthcare should be particularly vigilant given their significant representation among extortion targets. Conversely, smaller organizations with less sensitive operational data may not face the same level of risk.

Why This Matters
As extortion tactics evolve, defenders must recognize the amplified risk these new methods present. The regulatory pressures now in play empower attackers to exploit compliance timelines, creating a high-stakes environment for organizations that may face severe consequences for data breaches.

Defender Considerations
Monitoring for abnormal data egress activities and implementing data loss prevention controls are critical. Organizations should audit OAuth token grants and enforce stringent identity verification measures, especially for SaaS applications. Additionally, awareness of operations conducted by prominent extortion groups will aid in formulating targeted defenses.

Indicators of Compromise (IOCs)
No specific IOCs were mentioned in the article.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles