ZscalerThreat ResearchRansomwareAI

Ransomware Stopped Caring About Your Files. It Wants Your Data, and Your Executives.

October 2, 2026 · Brian Deitch

Zscaler ThreatLabz published its 2026 Ransomware Report on September 30, covering ransomware activity from April 2025 through March 2026. I'm a couple of days late on this one. Standard disclosure: I work at Zscaler, so read the enthusiasm as informed, not neutral.

The headline number is the one that should change how you think about ransomware: data theft is up more than 275% year over year, to 896.2 terabytes of exfiltrated data. Nearly 900 terabytes stolen in a year. The release compares that to 90 times the print collection of the Library of Congress, which is a fun visual right up until it's your customer database in there.

The Lock Screen Is Optional Now

For years the mental model of ransomware was simple: they encrypt your files, you pay for the key. Have good backups, and you have a fighting chance.

That model is going stale. The report says attackers are moving away from loud, disruptive encryption toward quiet theft. They don't need to break your systems if they already have a copy of your intellectual property, your customer records, and anything else you'd hate to see on a leak site. Backups don't help you when the threat is publication, not deletion.

"Successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging data theft attacks. They are using GenAI to speed up operations, and focusing on stealing more of an organizations' intellectual property, customer information, and other sensitive data to drive payment."

— Deepen Desai, Executive Vice President of Cybersecurity, Zscaler

Note the GenAI part. Attackers are using it to move faster, which is the same theme I keep running into: the attackers got an AI upgrade, and a lot of defenses are still running at human speed.

Fewer Victims, Bigger Hauls

Here's the counterintuitive bit. ThreatLabz tracked 7,366 victims listed on ransomware leak sites, a 3% decline year over year. So fewer victims, but way more data stolen. That's not ransomware fading. That's ransomware getting more selective and taking a lot more from each target.

The money backs that up. Blockchain transactions tied to ransomware payments hit $328 million, and the average ransom payment rose 5.3% to $431,995.

They're Going After the Corner Office

The stat I'd put in front of any executive team: manager-level titles and above accounted for 62% of victims. Senior people have the most access, the most sensitive data, and usually the most exceptions to security policy. Attackers have noticed.

They're also hiding in tools you trust. The report calls out abuse of Microsoft Teams and Quick Assist, which is a nasty combination with executive targeting. A message in Teams from "IT support" offering to help fix something, followed by a remote session, doesn't look like an attack. It looks like Tuesday.

Who's Getting Hit

Manufacturing and technology remained the most targeted industries, but the growth is happening elsewhere: freight and logistics up 725%, utilities up 622%. Those are industries where downtime hurts in the physical world, which makes them attractive targets.

The United States accounted for 50.7% of observed activity, followed by Canada at 4.8%, Germany at 4.3%, and the U.K. at 4.1%.

And the crews keep changing. Qilin, Akira, and INC Ransom accounted for 34% of disclosed victims, but nine of the top 15 groups by victim volume were new to the rankings, and ThreatLabz identified 52 newly active groups over the last year. Tracking ransomware by gang name is like playing whack-a-mole where the moles keep rebranding.

Bottom Line

If ransomware is now mostly a data theft problem, then "we have good backups" is no longer a ransomware strategy. Desai's prescription in the release is the right one: stop attacks early by reducing initial access opportunities, limiting lateral movement, and preventing data exfiltration. That's zero trust in one sentence. Don't put users on the network, don't let a compromised account wander, and watch what leaves. Turn off the lights on the attack surface and the 900 terabytes get a lot harder to steal.

Full release: New Zscaler Report Reveals AI-Assisted Attackers Move to Massive Data Theft, Executive Targeting, and Millions in Extortion Payments

zscalerthreatlabzransomwaredata-theftextortiongenaimicrosoft-teams
All postsDiscuss on LinkedIn