Ransomware Leverage is Growing by the Terabyte: Takeaways from ThreatLabz 2026 Ransomware Report
Zscaler ThreatLabz reports top ransomware groups' exfiltrated data volume jumped 276% year-over-year to 896 TB despite payments falling to $327.8M.
The ThreatLabz 2026 ransomware report found combined exfiltration among the top 10 groups by leak volume rose 275.8% year over year to 896.2 TB, while 7,366 victims appeared on leak sites, down only 3%. 62% of victims held manager-level titles or above and roughly 75% worked in finance, sales, operations, HR, or marketing. Initial access increasingly combines spam bombing, Microsoft Teams vishing, and abuse of legitimate remote support tools like Quick Assist. Known payments fell 15.8% to $327.8M but the average payment rose 5.3% to $431,995, with 52 newly active groups identified.
- Exfiltration among top 10 groups grew 275.8% to 896.2 TB year over year.
- 62% of victims held manager-level titles or above; 75% in business functions.
- Initial access combines spam bombing, Teams vishing, and Quick Assist abuse.
- 52 newly active groups; 60% of top-15 rankings are new.
- Payments fell 15.8% to $327.8M but average payment rose to $431,995.
Full article513 words · extracted from zscaler.com · click to collapse
5 key takeaways for security teams in 2026
Terabyte-scale data theft is now the center of gravity in ransomware
The biggest ransomware story this year isn’t a spike in victim counts, it’s the scale of data theft. Among the top 10 ransomware groups by reported data leak volume, combined exfiltration volume increased 275.8% year over year to 896.2 TB; more than seven times the volume recorded during the 2023–2024 reporting period (123.8 TB).
This is a clear leverage shift. When attackers can steal multiple terabytes from a single organization, extortion pressure grows even if the total number of victims stays relatively flat. For defenders, this raises the stakes on post-compromise containment: preventing lateral movement and stopping exfiltration quickly is now as critical as preventing encryption.
Ransomware threat actors are targeting employees with privileged roles and business influence
Ransomware groups are also now targeting “high-impact” business users, not just technical admins. And these intrusions are increasingly starting with something that looks routine: a support interaction, a Teams message, or an IT-themed request from a seemingly credible source. ThreatLabz uncovered that 62% of victims held manager-level titles or above, roles that often carry broad operational access and organizational trust.
Additionally, research shows that roughly 75% of victims worked in finance, sales, operations, HR, and marketing, functions tied to business-critical processes and high-value data. The takeaway is clear: the “high-risk user” profile often includes employees with influence, workflow access, and data proximity, not only those with explicit IT privilege.
Trusted enterprise tools are being turned into the initial access pathway
Threat actors are increasingly combining spam bombing with Microsoft Teams vishing and then steering victims toward legitimate remote support and remote access tooling (such as Quick Assist and in some cases other common remote support utilities). From there, attackers deploy tooling that enables reconnaissance, persistence, lateral movement, data theft, and encryption.
This technique succeeds because it blends into normal operations. Security teams should treat collaboration and remote support workflows as part of the ransomware attack surface, and apply policy, visibility, and detection accordingly.
Victim counts remain high, but the ransomware landscape is reshuffling fast
Publicly disclosed ransomware victim counts remained elevated: 7,366 victims were listed on leak sites, down only 3% year over year. But the groups driving that activity changed significantly: 60% of the top 15 groups by victim volume were new to the rankings, with ThreatLabz identifying 52 newly active groups over the last year.
Disruptions, shutdowns, and rebrands can change the names on leak sites while affiliates carry proven access techniques and tooling into new operations. Defenders need durable controls that focus on behaviors and tactics, not just group names.
Even with lower total payments, the cost of a successful extortion remains high
Known payment volume declined 15.8% year over year to $327.8M and the number of recorded payments fell 20.1%, but the average payment increased 5.3% to $431,995. The takeaway for defenders is the same: reducing the likelihood of any “paid incident” depends on disrupting initial access early and limiting post-compromise opportunities for data theft and other tactics that increase negotiating pressure.