Data Exfiltration Protection for Defense Contractors
Backups restore systems but not secrecy. A plain look at data exfiltration protection for defense contractors and SMBs facing extortion without encryption.
Your restore worked. Four hours, clean data, systems back up. And there is still a countdown clock on a leak site with your files sitting behind it.
That is the scenario most smaller organizations have never budgeted for. If you have been reading up on data exfiltration protection for defense contractors — or you just want to know whether your backups actually cover you — the short version is this: backups solve availability. They do not solve confidentiality. Those are two different problems, and a growing share of extortion activity now targets the second one.
Here is what the evidence supports, what it does not, and what to do about the gap.
Do backups protect against data exfiltration and extortion?
No. Backups protect you from losing access to your data. They do nothing about someone else having a copy of it.
That distinction used to be academic, because encryption and theft usually traveled together. It is less academic now. Insurer Resilience reported that 65% of the extortion-related claims it handled in the second half of 2025 involved no data encryption at all, up from 49% in the first half of the year. By the end of 2025, Resilience said, only 13% of attacks relied on encryption alone, while data theft — on its own or paired with encryption — accounted for 87% of ransomware claims (reported by Infosecurity Magazine, June 2026).
Those are insurer-handled claims, not the whole threat landscape. But claims data is what your own insurer and your own board will be looking at, and it points in one direction: for a majority of these incidents, a perfect restore leaves the extortion completely intact.
What is exfiltration-only ransomware, and how is it different?
Exfiltration-only extortion skips the encryption step entirely. The attacker gets in, quietly stages and copies data, leaves, and then demands payment to keep that data off a leak site.
It is different in three ways that matter operationally.
It is quieter. There is no ransom note on every screen, no locked file shares, no obvious moment of impact. You may find out weeks later from a post on a leak site or a call from a customer.
It is faster to execute. There is no need to build and deploy reliable encryption tooling across a heterogeneous environment.
It has produced specialists. Analyst1 documented a group calling itself the “Coinbase Cartel” appearing around September 2025 and positioning itself explicitly as a data-exfiltration-only extortion crew, deliberately distancing itself from traditional ransomware.
Delivery tends to be opportunistic rather than targeted. Acronis threat research identified CVE-2024-55956, an unauthorized file-write flaw in Cleo managed file transfer software, as the vulnerability Cl0p exploited to infiltrate systems and exfiltrate data. Managed file transfer is exactly where contract deliverables, customer records and regulated data tend to sit — the systems whose whole job is moving files across your boundary.
The trend is also moving quickly rather than drifting. IT Brew reported that At-Bay Security tracked a 450% increase in exfiltration-only attacks from Q3 to Q4 2025, though At-Bay declined to release the absolute totals behind that percentage, so read it as direction rather than magnitude.
Is the shift away from encryption actually settled?
No, and you should be skeptical of anyone who tells you it is. Cybersecurity Insiders reported in February 2026 that some operators are recalibrating in the opposite direction — back toward encryption and away from large-scale exfiltration. Analyst1, citing a mid-2025 Sophos report, noted encryption was used in only 50% of attacks, the lowest rate across six years of that survey; that figure comes to us secondhand rather than from the Sophos report directly, so treat it as directional too.
The durable point is not “ransomware stopped encrypting.” It is that the tactic mix oscillates and the exposure does not. You have to be able to survive both an availability loss and a confidentiality loss. A defense built for only one of them fails roughly half the time, and you do not get to choose which half shows up.
Should you pay a ransom if there is no encryption, only stolen data?
Most victims have already answered this with their wallets. Coveware data, reported via CybersecurityNews, shows only 23% of ransomware victims paid in Q3 2025 — and the rate dropped to 19% for data theft incidents with no encryption component.
The logic is straightforward. With encryption, payment buys a decryption key you can test. With exfiltration only, payment buys a promise to delete data you cannot verify was deleted, from people whose business model is lying to you. There is nothing to test.
When organizations do pay, the amounts are not small: Coveware reported an average ransom payment of roughly $600,000 in Q4 2025, up from about $325,000 a year earlier (reported via Cybersecurity Insiders, February 2026). Both figures reach us through secondary reporting rather than Coveware’s own publication, so treat them as ballpark. The takeaway holds either way — the money is better spent on the control than on the negotiation.
Does a data theft incident have to be reported under DFARS 252.204-7012?
If you are in the defense industrial base, yes — an exfiltration-only incident is still a reportable cyber incident. Backups do not remove the obligation.
Compliance analysts including ISI Defense and Secureframe describe the clause as requiring contractors to report incidents affecting covered defense information to DIBNet within 72 hours of discovery, and to preserve forensic images and relevant monitoring data for at least 90 days. Those figures come from vendor analysis rather than the clause text, so confirm the current wording of DFARS 252.204-7012 on acquisition.gov before you build a process around them — and confirm which revision of NIST SP 800-171 your contracts currently invoke, because that detail changes and getting it wrong is the fastest way to lose credibility with an assessor.
One more thing worth knowing: at least one vendor legal analysis (episki) argues that missing the 72-hour window is a contractual breach in its own right, independent of how good your security posture was. That is an interpretation, not a court holding or a DoD statement — but it is a reasonable way to think about your risk. The reporting failure and the incident are separate problems.
If you are not a defense contractor, the mechanics differ but the shape does not. Your customer contracts, your insurer and your sector regulator all want to know what left and when.
How do I prove what data was stolen after an attack?
With logs you collected before the attack. There is no way to reconstruct this after the fact.
That is the part smaller organizations consistently underinvest in. Answering “what left, when, and whose data was in it” inside a 72-hour window requires egress and boundary monitoring, audit logging with enough retention and detail to be useful, and identity records that show whose credentials did what. If you cannot answer those questions, your report becomes a guess — and your remediation becomes a guess too.
How do smaller organizations prevent data exfiltration?
Not with one product. The controls that actually bite against exfiltration-only extortion are:
- Egress and boundary monitoring — someone watching what leaves, not only what arrives.
- Data loss prevention on your sensitive repositories, including CUI stores if you hold them.
- Identity and privileged access controls, because bulk data access almost always runs through a credential.
- Patch velocity on edge appliances and file transfer platforms — the Cleo pattern, applied to whatever you run.
- Behavioral detection that flags staging and bulk archive creation rather than waiting for known malware.
- Audit logging good enough to answer the 72-hour question.
None of these is exotic. What they have in common is that they operate before the data leaves, which is the only window where you have leverage.
Speed matters too, because the other side is getting faster. Acronis’s Cyberthreats Report H2 2025: From exploits to malicious AI, published in February 2026, documents threat actors using AI to scale attacks, automate reconnaissance and optimize extortion strategy — including a group Acronis calls GLOBAL GROUP running AI-driven systems to manage ransom negotiations across multiple victims at once. Meanwhile, incident response at a lot of small organizations is one person, during business hours, on a Tuesday. That mismatch is the argument for 24/7 monitoring rather than a tool you check on Monday morning.
So what is backup for now?
Backup keeps its job. It just stops being the whole answer.
Its role in an exfiltration world is threefold: operational recovery when there is an availability loss, forensic evidence preservation that supports retention duties like the 90-day expectation above, and a clean known-good state to rebuild from once you understand what happened. That is one control in a two-halves strategy — not the strategy.
palmiq is an Acronis Platinum partner, in the top 1% globally, and we run a 24/7 SOC with a 15-minute response SLA on critical issues. Across our MDR and EDR services we neutralize 1,200+ threats a month at a 99.9% threat neutralization rate. What we will not tell you is that any product prevents all exfiltration or makes you compliant — certification comes from an assessment, not a purchase order. And if you handle CUI, confirm data residency, support access and authorization status for the specific deployment before it touches regulated data. That answer depends on how the platform is deployed, and it is worth getting in writing.
If you want a straight read on whether Acronis fits alongside what you already run — and where the gaps are between your backup and your detection — join our session: Is Acronis a fit for your stack?