We can see this by the fact that just a few years ago they would take down the same types of companies they are hitting now and ask for a ridiculously low sum of like $10k, but now they are asking for a much more reasonable, but still low $1M. Nothing changed about who they were attacking, they just slowly realized that they underestimated how much companies would pay for their "services" by a factor of 100x. That is a classic mark of a business amateur who has no idea just how much money is involved in B2B deals.
But to your underlying question, yeah, it is probably ransomware.
I still see things attacks on open SMTP ports to relay spam email, installing crypto mining software on PCs and servers, scanning for insecure VoIP phone systems and racking up long-distance phone bills..
The ransomware attacks makes a lot of headlines I think because it's somewhat easy to sensationalize without a lot of explanation of boring IT stuff, but there are still plenty of other things happening regularly to compromise insecure systems.
2) Terrorism. Really, I consider this the same as warfare, just coming from "terrorists" instead of "countries". With this broader base of attackers, I think there are groups that would be willing to do so. The only question is if they have the technical know-how. Given how cheap these ransoms can be ($4.4 mill for the pipeline hack), and the fact that a payed randsom probably a good profit margin, in terms of raw funding, these hacks seem within the range of terrorist groups.
And now Bloomberg is reporting it was a ransomware attack -- "It’s unclear exactly how many plants globally have been affected by the ransomware attack as Sao Paulo-based JBS has yet to release those details."