Ransomware data theft nearly quadruples, Zscaler finds

Published

Ransomware gangs did not hit many more organisations last year. They took far more from each one. Zscaler's ThreatLabz team says combined exfiltration volume among the ten ransomware groups with the largest reported data leak volume rose 275.8% year over year to 896.2 TB, more than seven times the 123.8 TB recorded in the 2023 to 2024 reporting period.

The figures come from the ThreatLabz 2026 Ransomware Report, which covers April 2025 through March 2026 and is summarised in a post by Diana Shtil, Deepen Desai, Brett Stone-Gross and Rajdeepsinh Dodia. The shift matters because it moves where defenders win or lose. When a single intrusion can walk out with terabytes, extortion pressure rises even if victim counts stay flat.

Victim counts barely moved, but the names did

Leak sites listed 7,366 victims over the period, down only 3% on the year before. The crews behind them changed sharply, though: 60% of the top 15 groups by victim volume were new to the rankings, and ThreatLabz identified 52 newly active groups over the year. The researchers put the churn down to disruptions, shutdowns and rebrands that change the names on leak sites while affiliates carry proven access techniques and tooling into new operations. Their advice follows from that: build controls around behaviours and tactics, not group names.

Fewer payments, bigger cheques

Known ransom payment volume fell 15.8% to $327.8 million, and the number of recorded payments dropped 20.1%. The average payment, however, rose 5.3% to $431,995. ThreatLabz reads that as attackers extracting more from the victims that do pay.

The way in looks like a help desk call

On initial access, the report describes a repeatable playbook. Attackers spam bomb a target's inbox, contact them over Microsoft Teams posing as IT support, and steer them into legitimate remote support tools such as Quick Assist. From there they deploy tooling for reconnaissance, persistence, lateral movement, data theft and encryption. It is a pattern IntelFusions has tracked repeatedly, including fake Teams IT support calls that ended in ransomware.

The people picked are not only administrators. ThreatLabz found that 62% of victims held manager-level titles or above, and roughly 75% worked in finance, sales, operations, HR and marketing, functions tied to business-critical processes and high-value data. We covered a related ThreatLabz finding in August, in our report on crews targeting managers.

Stop the exfiltration, not just the encryption

The practical message is that containment after a break-in now matters as much as preventing encryption. ThreatLabz recommends treating collaboration and remote support workflows as part of the ransomware attack surface, applying policy, visibility and detection to them, and prioritising controls that limit lateral movement and stop data leaving quickly. For most organisations that starts with limiting which remote support tools can run and who can start a session, scrutinising Teams contact from outside the organisation, and alerting on unusually large outbound transfers.

Headline victim counts have held roughly steady, which makes it easy to miss that the damage per victim is climbing. Measured in terabytes rather than names on a leak site, ransomware is getting worse.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions