Breaking News

49% of Ransomware Victims Detect Attacks Only After Data Is Already Gone

Written by Maria-Diandra Opre | Aug 19, 2026, 12:00:00 PM

Ransomware is becoming harder to detect at the stage where intervention still matters. ExtraHop’s 2026 Global Threat Landscape Report shows that nearly half of victims (49%) discovered an attack only after data had already been stolen (ExtraHop, 2026). Meanwhile, attackers remained inside enterprise networks for an average of almost two and a half weeks before detection, long enough to map systems, escalate access, and turn stolen data into leverage.

That delay is becoming more dangerous as AI changes the speed of cyber operations.. Ransomware groups are applying AI where it pays off most: reconnaissance, phishing, credential abuse and lateral movement. Enterprises are also adding AI to security operations, but too much of the SOC still depends on manual triage, fragmented alerts and incomplete network context. That visibility gap gives attackers room to work.

ExtraHop found that 55% of respondents see AI agents, agentic infrastructure and generative AI applications as among their biggest cybersecurity risks. AI is now shaping both sides of ransomware risk. It expands the attack surface through AI agents, generative applications, and agentic infrastructure, while also raising expectations for faster defense.

“Artificial intelligence has matured from a boardroom buzzword to the operational core of the modern enterprise,” ExtraHop reported. “But this massive wave of adoption has revealed a stark reality: the technology driving business growth is also fundamentally rewriting corporate risk.”

So far, 85% of respondents experienced a security incident, data exposure, or near miss in which an AI system was the root cause. These included AI-enhanced external attacks, compromised AI identities, session theft, shadow AI exposure, and third-party breaches involving vendor AI systems.

The risks are spreading across several layers of the business: AI-enhanced external attacks, compromised AI identities, session theft, shadow AI exposure and third-party vendor incidents involving integrated AI systems.

AI security is very hard to contain because it does not reside neatly within a single platform. It moves through APIs, identities, SaaS tools, vendor environments, data pipelines and employee workflows. Every new AI integration can improve productivity, but it can also create another route for exposure.

LockBit and RansomHub were the two most detected threat groups in enterprise networks for the second year in a row. ExtraHop notes that groups such as RansomHub are using AI to increase the speed and volume of attacks, while some state-linked groups appear to use AI more selectively.

The average ransom payment fell from US$3.6 million in 2025 to US$2.8 million, but the share of victims paying rose from 70% to 83%. Downtime averaged almost 30 hours per incident. That suggests ransomware groups may be trading larger individual payouts for more frequent payments. For victims, the pressure is simple: when systems are down, data is exposed, and business operations are frozen, paying can begin to look like the fastest route back to control.

Attackers are harder to spot because they increasingly behave like legitimate users. They use encrypted channels, valid privileged accounts and workflows that resemble normal business activity. ExtraHop’s respondents cited all three as reasons critical alerts were missed or delayed.

That is why network visibility matters. Security teams need to see how systems communicate, where data moves and how behavior changes inside the environment. AI can help interpret that activity, but it needs reliable context to make useful decisions.

Too many companies are still learning about ransomware after the damage has already begun.