Encryption is now optional: the fortnight extortion went pure-exfiltration
Three enterprises extorted through Salesforce in seven days, none of them encrypted. Microsoft's largest Patch Tuesday of 2026 lands with a SharePoint zero-day already being exploited. And CISA's Known Exploited Vulnerabilities catalog grows by eight entries in a week.
Executive summary
- SaaS misconfiguration is the enterprise attack surface of 2026. Three Salesforce-centric extortion incidents in one week share a root cause the legacy SIEM was never built to see: misconfigured trust, over-permissioned connected apps and anomalous API volumes.
- Encryption is now optional for the attacker. Pure data-theft extortion bypasses encryptor-focused detection entirely; behavioural signals such as privileged access, bulk exfiltration and token abuse are the tell.
- The patch-to-exploit window has collapsed. A SharePoint flaw went from patch release to the CISA KEV list on the same day. Waiting for the post-mortem means defending a week behind the threat.
Key findings
Microsoft patches 167 flaws; SharePoint zero-day under active exploitation
April's Patch Tuesday included a SharePoint Server spoofing flaw (CVE-2026-32201) already exploited in the wild and added to CISA KEV the same day, alongside a 9.8-CVSS Windows IKE remote-code-execution bug and a wormable TCP/IP flaw on IPv6+IPSec systems. Enterprise SharePoint estates in regulated sectors are the immediate priority.
Three SaaS extortion incidents in one week, no encryption used
An extortion crew exfiltrated 13.5 million records from one enterprise via a Salesforce environment misconfiguration and threatened 30 million records at a second; a third organisation was listed on an extortion leak site by an actor that operates without any encryption payload. The behavioural pattern: dormant OAuth tokens, over-scoped connected apps and anomalous bulk-export API volumes.
Qilin ransomware compresses initial-access-to-encryption to minutes
SOC telemetry reporting flags Qilin among the fastest-moving crews this month, with encryption starting minutes after endpoint compromise. Vulnerable internet-facing endpoints remain the primary access vector. At this speed, containment has to happen at machine speed, before a human picks up the queue.
Travel-sector breach exposes reservation data
A major booking platform confirmed compromise of customer reservation data including names, addresses and booking details. Travel-adjacent incidents carry elevated third-party risk for any enterprise with corporate-travel and supply-chain exposure.
The broader pattern
- Legacy detection content does not fire on SaaS identity abuse. Rules built around Windows logs and network flow are blind to connected-app scope changes and Data Loader API anomalies.
- If your detections key on encryptor signatures, the playbook is already outdated. Exfiltration-only extortion produces no encryption event to catch.
- KEV additions are a same-day operational trigger, not a monthly review item: patch, hunt retroactively, and confirm detection coverage the day an entry lands.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Patch CVE-2026-32201 on all SharePoint estates now. It is exploited and on KEV; treat exposure as presumed until hunted.
Audit Salesforce (and equivalent SaaS) connected-app scopes and dormant OAuth tokens. Revoke anything unused; alert on new scope grants as first-class events.
Baseline SaaS API volume per identity, per app, per hour. Bulk-export anomalies are the earliest reliable exfiltration signal.
Verify your detection content covers exfiltration-only extortion. If every ransomware detection assumes an encryptor, close that gap this week.
Wire KEV additions into a same-day patch-and-hunt workflow. Eight entries landed in one week; the window between patch and exploitation has collapsed.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Blacklight's agents baseline every identity and connected app across your SaaS, cloud and endpoint estate, so an over-scoped OAuth grant or an anomalous bulk export is investigated and contained in minutes, encryptor or not. KEV entries are correlated against your actual assets the day they land, with the reasoning trail shown for every verdict.
Sources & methodology
Primary public sources this issue: Microsoft Security Response Center (April 2026 Patch Tuesday release notes) · CISA Known Exploited Vulnerabilities catalog (entries of 13–16 April 2026) · NVD (CVE-2026-32201 and related) · vendor SOC telemetry reporting (April 2026) · public breach disclosures and leak-site monitoring, 12–19 April 2026 · MITRE ATT&CK v15 for technique mapping.