Ransomware crews are treating endpoint defense shutdown as part of the job, which cuts off the one sensor many teams rely on to spot encryption early. The old playbook assumed EDR would stay alive long enough to warn and contain the attack; that assumption is getting weaker.
Halcyon’s Q2 2026 report says EDR-kill has moved from a niche skill to standard practice among leading ransomware groups, and The Gentlemen now adds EDR or antivirus shutdown to its attack chain. The same report says attacks are becoming faster, more automated, and harder to detect, with some groups moving from breach to deployment in under an hour.
The practical shift is toward resilience. If the endpoint sensor goes dark first, the real defense becomes clean backups, fast recovery, and other ways to keep visibility after the kill step.