Zscaler: Ransomware Data Theft Surged as Payments Fell
ThreatLabz says top ransomware groups stole 896.2 TB, up 275.8% year over year, while known payments fell to $327.8 million.
Zscaler ThreatLabz’s 2026 Ransomware Report says the top 10 groups by leak volume exfiltrated 896.2 TB between April 2025 and March 2026, a 275.8% year-over-year increase, while a companion note called that volume “over seven times” the prior period—closer to 3.8 times, not seven. Leak-site victims totaled 7,366, down only 3%, though a later write-up said data-theft claims rose about 275% despite fewer campaigns. Known payments fell 15.8% to $327.8 million and the average payment rose 5.3% to $431,995. Initial access increasingly pairs spam bombing with Microsoft Teams help-desk impersonation and remote tools such as Quick Assist, AnyDesk, and TeamViewer. Role figures differ slightly: one report said 62% of victims were manager-level or above and roughly 75% worked in finance, sales, operations, HR, or marketing, while another tied the 62% figure to 351 analyzed victims. Named large claims include Babuk2 at 30 TB from government, INC Ransom at 20 TB from healthcare, and Pear at 16 TB from a U.S. university; utilities victims rose 622% to 65, a healthcare organization paid $2 million solely to stop publication, 52 groups were newly active, and Payouts King was described exfiltrating data over SFTP with RMM tools and shadow credentials.
- Top 10 groups by leak volume exfiltrated 896.2 TB from April 2025 to March 2026, up 275.8% year over year; one note also called it “over seven times” the prior period, which conflicts with that percentage.
- Leak-site victims totaled 7,366, down 3%; a later write-up said theft claims rose about 275% despite fewer campaigns.
- Known payments fell 15.8% to $327.8 million, while the average payment rose 5.3% to $431,995.
- Initial access combines spam bombing, Microsoft Teams help-desk vishing, and remote tools including Quick Assist, AnyDesk, and TeamViewer.
- One account said 62% of victims were manager-level or above and roughly 75% worked in finance, sales, operations, HR, or marketing; another tied the 62% figure to 351 analyzed victims.
- Babuk2 claimed 30 TB from a government organization, INC Ransom 20 TB from a healthcare provider, and Pear 16 TB from a U.S. university.
- Utilities victims rose 622% to 65 organizations; one healthcare victim paid $2 million to prevent publication, with no encryption.
- 52 newly active groups were identified and 60% of top-15 rankings were new; Rhysida and Embargo averaged at least 1 TB per victim, and Payouts King was linked to former Black Basta affiliates.
Coverage timelineoldest first · each row is one article
- · 1d agoRansomware Leverage is Growing by the Terabyte: Takeaways from ThreatLabz 2026 Ransomware Report
Zscaler ThreatLabz· 60
Zscaler ThreatLabz reports top ransomware groups' exfiltrated data volume jumped 276% year-over-year to 896 TB despite payments falling to $327.8M.
- · 8h agoFrom Access to Exfiltration: What Defenders Need to Know
Zscaler ThreatLabz· 52
Zscaler ThreatLabz reports ransomware data theft surged 275.8% to 896.2TB, with exfiltration-focused extortion outpacing encryption-centric defenses.
- · 6h ago