The ransomware playbook has quietly rewritten itself. By mid-2026, encryption is almost an afterthought: 96% of incidents in Q1 2026 involved data exfiltration, and attackers now spend weeks inside a network hunting down and destroying backup infrastructure before they ever trigger a payload. For UK IT leaders, that changes the entire risk calculus — a breach notification obligation can now be triggered before a single file is encrypted, and a six-figure backup investment can be worthless if it wasn't built to survive a targeted attacker. This piece sets out what actually changed, what it costs, and which controls genuinely blunt it.
View the data behind this chart
| Data exfiltration (Q1… | Backup compromise (2026) | Backup targeting (2025-26) | Data theft plus encryption… | VPN abuse initial access… | AI-assisted variants… | |
|---|---|---|---|---|---|---|
| Rate of incidents | %96 | %73 | %93 | %82 | %38 | %47 |
The Evolving UK Ransomware Landscape in Mid-2026
Ransomware incident volumes have tripled since 2024, according to Networkcraft's 2026 analysis — but the shape of an attack looks nothing like it did even two years ago. BlackFog's Q1 2026 data shows data exfiltration present in 96% of incidents, a rate that held steady after a sharp rise through 2025. Encryption, once the whole point of the attack, is now frequently just the final flourish on top of a data-theft operation.
The other defining shift is backup destruction. CrowdStrike puts backup compromise at 73% of 2026 incidents, while Veeam's broader 2025–2026 dataset finds backup systems specifically targeted in 93% of attacks — a wider window covering both years rather than a single 2026 aggregate. Read together, the two figures tell a consistent story: recovery infrastructure is no longer a passive afterthought for attackers, it's an active target they disable before deploying the payload.
Speed has collapsed too. Networkcraft reports average attack timelines compressing from days down to under an hour once the final phase begins, while Protection Associates separately finds attackers dwelling an average of 21 days inside a network beforehand, specifically to locate and neutralise recovery options. These are two different clocks — a long reconnaissance phase followed by a near-instant strike — and UK defenders need to design for both.

AI's Double-Edged Sword in the 2026 Kill Chain
CrowdStrike's 2026 tracking finds that 47% of newly discovered ransomware variants now incorporate AI-assisted features. In practice, CyFirma's May 2026 research describes this showing up as accelerated identity-focused attacks — MFA fatigue campaigns, credential theft, and cloud account abuse increasingly favoured over traditional malware delivery as the preferred route in.
The same research notes that newly disclosed vulnerabilities in internet-facing platforms are now weaponised within hours or days of disclosure, not weeks. For UK IT teams still running monthly patch cycles on VPN concentrators, firewalls, or remote-access gateways, that gap is exactly where attackers are getting in: DataEnforce's Q2 2026 figures show VPN credential abuse accounting for 38% of ransomware initial access.
On defence, the practical response is to compress your own decision cycle to match — faster detection engineering and identity-centric controls, rather than relying on perimeter tools that assume a slower attacker. A zero trust approach to remote access, treating every VPN session as untrusted until verified, directly targets the 38% VPN-abuse pathway.
Beyond Encryption: Multi-Extortion and the UK Compliance Fallout
Double extortion — encrypt and threaten to leak — is now, per DataEnforce, the baseline operational model for virtually every active ransomware-as-a-service platform, not an advanced add-on. Networkcraft's figures show data theft occurring alongside encryption in 82% of 2026 incidents, up from 54% in 2023, confirming this is now the default, not the exception.
For UK organisations this has a sharp legal edge. Under GDPR and the Data Protection Act 2018, exfiltration alone — even with no encryption at all — triggers the same breach notification clock as a full-blown ransomware incident. A business that assumes it's fine because backups restored cleanly can still be sitting on an unreported personal data breach, with fines of up to £17.5 million on the table.
The NCSC's 2026 guidance responds directly to this shift, explicitly mandating phishing-resistant MFA (hardware tokens or passkeys) on all remote access and air-gapped backup architecture — treating both as baseline expectations rather than best-practice extras.
The Professionalisation of Cybercrime: RaaS and Backup-Hunting
The 21-day average dwell period before deployment, identified by Protection Associates, isn't idle time. CyFirma describes attackers using this window to systematically identify, disable, corrupt or delete recovery mechanisms — turning what should be a quiet reconnaissance phase into a deliberate campaign against the victim's ability to recover without paying.
That patience pays off precisely because so many organisations still store backups in ways a determined intruder with weeks of privileged access can reach and destroy. Combined with the rapid weaponisation of newly disclosed vulnerabilities, and VPN credential abuse as a reliable front door, the initial-access economy has matured into a specialised, repeatable process rather than opportunistic hacking.
Cyber Strategy Institute also flags that hybrid ransomware — spanning on-premises systems, SaaS platforms and cloud control planes in a single attack — became normal in 2026, meaning the blast radius now regularly extends well beyond the file server that used to define a ransomware incident.
UK Sector Exposure: Who's Absorbing the Damage
Cyber Strategy Institute's 2026 reality report finds that critical sectors — healthcare, manufacturing and OT-heavy industrial environments — continue to absorb disproportionate damage despite generally higher security maturity than average. That combination of high value, complex legacy environments and operational-technology dependencies makes recovery both slower and more expensive when backups fail.
For UK-regulated industries specifically, NIS 2 obligations now push health, finance and energy operators towards quarterly tested restore procedures rather than an annual tick-box exercise — a direct response to the fact that a backup nobody has actually tried to restore is not a control, it's a hope.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| VPN Access | 0 | 1 |
| Dwell & Recon | 1 | 20 |
| Backup Wipe | 21 | 1 |
| Encrypt & Exfil | 22 | 1 |
The Real Ransomware Paradox: Paying Doesn't Cap the Bill
DataEnforce puts the average ransom payment, when victims do pay, at $2.73 million in Q2 2026. Networkcraft separately puts the average total recovery cost — forensics, lost revenue, remediation, the lot — at $2.8 million, a figure that's risen 40% year-on-year since 2024. In GBP terms, that recovery cost equates to roughly £2.18 million, now a baseline budget line for mid-market UK firms rather than a tail-risk scenario.
The two numbers are close enough to make the point: paying the ransom does not meaningfully reduce the total bill, because the recovery cost captures everything the ransom payment doesn't — rebuilding systems, investigating scope, notifying regulators and customers, and lost trading time. With data already exfiltrated in the overwhelming majority of cases, paying also does nothing to guarantee that stolen data isn't sold, leaked, or used again regardless.
The proven alternative isn't a silver bullet, it's operational discipline: immutable, air-gapped backups that survive a 21-day intrusion, tested restores under NIS 2 cadence, and an incident response plan that assumes the worst has already happened before the ransom note appears.
Building Resilience: Strategic Defences and Board-Level Priorities
The controls that actually blunt this version of ransomware are the same ones the NCSC's 2026 guidance now expects as standard: the 3-2-1-1-0 backup rule (multiple copies, multiple media, one offsite, one immutable or air-gapped, zero recovery errors), phishing-resistant MFA everywhere remote access exists, and backup infrastructure managed as a production-critical system — patched, monitored and access-controlled — rather than a passive archive nobody logs into.
For boards, this is no longer purely a technical conversation. Given that 73–93% of incidents now involve backup compromise depending on how it's measured, the question directors should be asking isn't "do we have backups" but "have we proven, this quarter, that they survive an attacker who's already inside". Immutable cloud tiers such as logically isolated object storage, or immutable tape, are now standard procurement items rather than optional extras.
Practically, that means investing in robust backup and disaster recovery strategies, moving toward architectures that implement immutable backup as a default rather than an upgrade, and using tools to calculate the cost of downtime so the board is budgeting against the real £2.18 million-class exposure, not a theoretical one.
- •3-2-1-1-0 backup rule: multiple copies, multiple media, offsite, immutable, zero errors
- •Phishing-resistant MFA (hardware tokens/passkeys) on all remote access, not just admin accounts
- •Quarterly tested restores for NIS 2-regulated health, finance and energy operators
- •Backup infrastructure monitored and access-controlled as a production system
Case Study: A Mid-2026 UK Attack Scenario and Response
Picture a mid-market UK manufacturer. An attacker buys stolen VPN credentials — the initial-access route behind 38% of Q2 2026 intrusions — and logs in unnoticed. Over the next three weeks, roughly matching Protection Associates' 21-day average, they map the network, escalate privileges, and quietly locate the backup repository and its admin credentials.
Once ready, the final phase moves fast: within roughly an hour, backups are corrupted, files are encrypted, and terabytes of customer and design data are exfiltrated to an external server — consistent with the 82–96% exfiltration rates now standard across 2026 incidents. A ransom note demands a payment in the region of the $2.73 million Q2 2026 average, threatening to publish stolen data regardless of payment.
The correct UK response starts before the note even appears: because data was exfiltrated, the GDPR/DPA 2018 breach notification clock has already started, independent of whether backups restore cleanly. The immediate priorities are isolating affected systems, engaging incident response, notifying the ICO within the statutory window, and restoring from backups that were air-gapped precisely so a 21-day intruder couldn't reach them. Paying doesn't undo the exfiltration — the only genuine mitigation is having built recovery and disclosure processes that don't depend on the attacker's goodwill.
Sources
Every figure in this article traces to the sources below.
- •BlackFog — Q1 2026 data exfiltration rate
- •CrowdStrike — backup compromise, AI-assisted variants, incident growth
- •Veeam — backup targeting rate, attacker dwell time
- •DataEnforce — Q2 2026 ransom payment and VPN abuse figures
- •CyFirma — vulnerability weaponisation and identity-focused attacks
- •Cyber Strategy Institute — dwell time and sector impact analysis
View the data behind this chart
| Old Assumption | 2026 Reality | Effective Contro… | |
|---|---|---|---|
| Backup Resilience | Assumed safe copy | 73% backups hit | Air-gapped immutable |
| Remote Access | Password plus SMS code | 38% VPN cred abuse | Phishing-resistant MFA |
| Ransom Payment | Pay, restore, done | Data already stolen | Report to ICO fast |
| Recovery Timeline | Days to rebuild | Attack live in 1 hour | Test restores quarterly |
