Ransomware gangs steal 896 terabytes, Zscaler says | #ransomware | #cybercrime

Zscaler has published research showing ransomware attackers exfiltrated 896.2 terabytes of data over a year, a 275.8% increase year on year.
The findings point to a shift in ransomware tactics away from disruption through encryption alone and towards the theft of large volumes of data for extortion. Average ransom payments rose 5.3% from a year earlier to more than £327,000, while blockchain transactions linked to ransomware payments reached $328 million.
The analysis covered ransomware activity from April 2025 to March 2026. It drew on company telemetry and ThreatLabz analysis of ransomware samples, victim targeting, attack techniques, data theft and payment patterns.
One of the report’s central findings was the focus on senior staff. According to Zscaler, 62% of victims held manager-level titles or above, and 75% of those targeted worked in finance, sales and human resources.
The data suggests attackers are prioritising employees with access to sensitive information and internal systems, as well as those with influence over payments, data access and business processes.
Target sectors
Manufacturing and technology recorded the highest numbers of ransomware victim organisations during the period, with 1,025 and 605 respectively. Freight and logistics and utilities posted the fastest year-on-year growth in victim numbers.
The United States remained the largest target market, accounting for 50.7% of observed ransomware activity. Canada, Germany and the UK followed at much lower levels, with the UK representing 4.1%.
Overall victim volumes remained relatively steady despite changes in the criminal groups involved. ThreatLabz tracked 7,366 victims listed on ransomware leak sites, down 3% from the previous year.
At the same time, the makeup of the leading groups changed sharply. Sixty percent of the top 15 ransomware groups by victim volume were newly active, while researchers identified 52 newly active groups during the year.
Qilin, Akira and INC Ransom accounted for 34% of disclosed victims. That concentration suggests a handful of groups continued to drive a significant share of publicly identified attacks even as new entrants appeared across the market.
Tooling shift
The report also highlighted the growing use of scripting languages in ransomware operations. JavaScript, PowerShell and Python were all cited as playing a prominent role in attacks.
Attackers are also increasingly abusing widely used workplace tools, including Microsoft Teams and Quick Assist, for social engineering, lateral movement, data theft and file encryption.
The pattern reflects a broader trend in cyber crime towards using legitimate software and familiar channels to reduce suspicion. By blending malicious activity into routine workplace communications and administration tools, attackers can make detection harder.
Artificial intelligence also featured in the report’s assessment of current attacker methods. Zscaler said generative AI was helping threat actors speed up operations and develop new tooling more quickly.
That combination of greater automation, more adaptable criminal groups and rising volumes of stolen data has increased pressure on victims. Rather than relying solely on locking files and halting operations, attackers can use stolen data itself as leverage in negotiations.
Deepen Desai, Executive Vice President of Cybersecurity at Zscaler, said the trend marked a significant change in extortion tactics.
“Successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging, data theft attacks,” said Deepen Desai, Executive Vice President of Cybersecurity at Zscaler.
“They are using GenAI to speed up operations and focusing on stealing more of an organisation’s intellectual property, customer information and other sensitive data to drive payment. Security teams need to stop these attacks early by reducing initial access opportunities, limiting lateral movement and preventing data exfiltration,” he said.


