Zscaler Report Finds 275% Jump in Ransomware Data Theft
Attackers focused on employees with privileged roles and abused tools such as Microsoft Teams, the research found.
- By Danielle Naidu
- Oct 05, 2026
Ransomware data theft rose more than 275% last year, with attackers exfiltrating 896.2 terabytes of data, the Zscaler ThreatLabz 2026 Ransomware Report found.
The report is based on Zscaler telemetry and ThreatLabz analysis of ransomware activity from April 2025 through March 2026.
Blockchain transactions linked to ransomware payments totaled $328 million, while the average payment increased 5.3% to $431,995. Employees with manager-level titles and above represented 62% of victims. Zscaler interpreted that figure as evidence that attackers were focusing on people with privileged roles and organizational influence.
The report found attackers increasingly using trusted enterprise tools, including Microsoft Teams and Quick Assist, across several stages of an attack, including social engineering, movement within networks, data theft and file encryption.
The steepest growth came in freight and logistics, up 725%, and utilities, up 622%, though manufacturing and technology remained the most targeted industries. U.S. organizations accounted for just over half of observed activity, at 50.7%. ThreatLabz tracked 7,366 victims on ransomware leak sites, a 3% year-over-year decline, and identified 52 newly active groups during the period.
About the Author
Danielle Naidu is assistant editor for Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.