Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims
Zscaler ThreatLabz reports ransomware data theft claims surged 275%, with Babuk2, INC Ransom, and Pear claiming 30TB, 20TB, and 16TB thefts.
Zscaler ThreatLabz's report found ransomware data theft claims surged 275% despite fewer campaigns, with government, healthcare, and education tied to the largest claims. Babuk2 claimed to have stolen 30 TB from a government organization, INC Ransom claimed 20 TB from a large healthcare provider, and the new Pear group claimed 16 TB from a U.S. university. One healthcare victim paid a $2 million ransom via extortion without encryption after spam bombing and IT-themed impersonation gave attackers initial access. Utilities saw victim counts jump 622% to 65 organizations.
- Ransomware data theft claims up 275% year over year
- Babuk2 claimed 30 TB stolen from a government organization
- Healthcare victim paid $2 million ransom without any encryption
- Utilities victims rose 622% to 65 organizations
- Fewer campaigns overall, but damage per campaign grew larger
Full article303 words · extracted from zscaler.com · click to collapse
Some of the largest data theft claims involved government, education, and healthcare
Based on activity visible on ransomware leak sites, organizations in these sectors were tied to some of the largest data theft incidents observed during this reporting period.
Government. Ransomware attacks targeting government organizations declined 27% year over year, and the sector ranked ninth overall. Despite the decrease, government organizations were tied to the largest data theft claim in the ThreatLabz dataset: Babuk2 claimed to have stolen 30 TB of data from a government organization.
Healthcare. Healthcare ransomware activity declined 24% year over year, but the sector remained one of the most targeted industries overall, ranking fourth. INC Ransom claimed to have stolen 20 TB of data from a large healthcare organization, one of the largest claims in the dataset. In a separate incident, attackers used spam bombing and IT-themed impersonation to gain initial access, then pursued extortion without encrypting systems. The victim paid a $2 million ransom even though files were never encrypted.
Education. Ransomware activity targeting education declined 17% year over year, with the sector ranking eleventh. Pear, a relatively new ransomware group, claimed to have stolen 16 TB of data from a U.S. university. ShinyHunters, first observed in 2025, also drew attention for an extortion campaign targeting the education sector.
Utilities. While utilities had too few victims (10) in the prior year to include in the formal year-over-year comparison, the sector rose sharply by 622% to 65 victim organizations. As the Ransomware Report notes, ransomware attacks on sectors that support essential services carry implications beyond their absolute victim counts, with ripple effects through supply chains and dependent operations.
While overall attack volume against government, healthcare, and education decreased year over year, the scale of individual data theft incidents grew. The campaigns are fewer. The damage per campaign is larger.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.zscaler.com/blogs/security-research/ransomware-data-theft-surged-275-2026-schools-hospitals-and-government