Ransomware gangs spent 2026 doubling down on a strategy that insurers and researchers have warned about for years: steal the data first, encrypt it second, and squeeze victims from both directions. A headline circulating Thursday from Security Boulevard put a number on just how fast that shift has moved, reporting that ransomware-linked data theft “surged 275%” in 2026, with schools, hospitals, and government agencies logging some of the largest insurance claims of the year. The outlet’s report did not disclose the comparison period, sample size, or methodology behind that figure, so it should be read as a reported claim rather than an independently verified statistic. But the underlying trend it points to is corroborated by a stack of separate 2026 data from Verizon, Coalition, and Comparitech, and it lines up with a pattern tech-insider.org has tracked across a string of 2026 incidents, including the Luminis Health cyberattack and the Pentagon personnel records breach.
What is not in dispute is the direction of travel. Verizon’s 2026 Data Breach Investigations Report found ransomware involved in 48% of breaches it analyzed, up from 44% a year earlier. Coalition, a cyber insurer that underwrites thousands of small and mid-size businesses, reported that 70% of the ransomware claims it processed in 2026 involved both encryption and data exfiltration together, a combination known as double extortion. And Comparitech, which has tracked ransomware incidents since 2018, logged 4,217 confirmed and claimed attacks in the first half of 2026 alone, an 11% jump over the second half of 2025. Schools, hospitals, and local governments sit at the center of nearly all of it, because they tend to run older infrastructure, carry cyber insurance that attackers know will pay out, and cannot afford extended downtime the way a retailer or manufacturer can.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What the 275% ransomware data theft figure actually claims
The Security Boulevard headline is specific but thin on sourcing details in the publicly available version of the story: it asserts a 275% surge in ransomware data theft during 2026 and names schools, hospitals, and government agencies as the categories filing the largest claims. Readers searching for the original dataset behind that percentage will not find a linked report, baseline year, or definition of “data theft” in the excerpt currently circulating. That does not make the underlying concern invalid. It means the number needs a health warning before it gets repeated as fact across the industry, the same caution that applies to any statistic that goes viral faster than its methodology.
What can be verified independently is that the component trends feeding a figure like that are real and measurable. Coalition’s 2026 Cyber Claims Report found that initial ransom demands climbed 47% year over year to an average above $1 million, even as 86% of the businesses it covers refused to pay. Comparitech’s Q1 2026 ransomware roundup separately estimated that more than 454 terabytes of data were stolen across the attacks it tracked in just the first three months of the year. Stack those figures side by side and a triple-digit percentage increase in the volume of stolen data over a prior comparison period is plausible, even if the exact 275% figure cannot be traced to a public primary source at the time of writing.
Why schools, hospitals, and government agencies keep filing the biggest claims
Three sectors keep showing up at the top of ransomware claims data for structural reasons that have not changed much since 2023, and 2026 has only sharpened them. School districts run on lean IT budgets stretched across aging Windows fleets and third-party vendor software that nobody has patched in years. Hospitals cannot take systems offline mid-shift without risking patient safety, which makes them more likely to negotiate rather than rebuild from backups. Local and state government agencies hold exactly the kind of personally identifiable information, from foster care files to military personnel records, that fetches a premium on dark web marketplaces even if the ransom itself never gets paid.
Comparitech’s H1 2026 breakdown illustrates how unevenly the pain lands across these categories. Attacks on governments and businesses rose 12% during the first half of 2026 compared with the second half of 2025, and confirmed healthcare attacks rose 4%, while confirmed education attacks actually fell 13% over the same window. That is a reminder that attack volume and claim severity are not the same thing: a sector can see fewer confirmed attacks and still produce the costliest claims, because a single breach at a hospital system or state court network exposes far more sensitive records than a breach at a mid-size retailer. The Arizona court system breach that exposed roughly 150,000 foster care files earlier in 2026 is exactly that kind of outsized-impact, lower-frequency event.
Verizon DBIR 2026: ransomware now touches nearly half of all breaches
Verizon’s annual Data Breach Investigations Report remains the most widely cited benchmark in the industry because it aggregates incident data contributed by dozens of partner organizations rather than relying on a single vendor’s book of business. The 2026 edition found ransomware present in 48% of the breaches it analyzed, up from 44% in the 2025 report. That four-point jump across a single year, on a dataset spanning tens of thousands of incidents, is itself a meaningful signal that ransomware is not plateauing even as law enforcement take-down operations against individual gangs have multiplied.
Verizon’s healthcare-specific snapshot for 2026 reinforced the same message for that sector: human-element failures, including social engineering, phishing, and stolen credentials, combined with unpatched software vulnerabilities remain the dominant entry points attackers use before deploying ransomware or exfiltrating data. None of that is new, but the persistence of the same root causes year after year is itself notable. It suggests that the 2026 surge is less about novel attack techniques and more about attackers scaling proven playbooks against a target pool that has not closed the gaps those playbooks exploit.
Coalition’s 2026 claims data: bigger demands, more refusals to pay
Coalition’s 2026 Cyber Claims Report gives the clearest look yet into how the economics of ransomware have shifted from the insurer’s side of the table. Initial ransom demands rose 47% year over year to an average exceeding $1 million, a jump Coalition attributes in part to attackers now pricing demands against the volume of exfiltrated data rather than just the difficulty of decryption. At the same time, 86% of the businesses Coalition covers refused to pay the demand outright, a sign that years of law enforcement guidance against payment, combined with better backup practices, are taking hold even as ransom asks get larger.
The number that matters most for understanding why “data theft” specifically is surging sits in Coalition’s double-extortion figure: 70% of the ransomware events in its 2026 claims data involved both encryption and data exfiltration together. That combination typically doubles the cost of an incident, because the victim organization has to fund both recovery (restoring encrypted systems) and breach response (notifying affected individuals, offering credit monitoring, and in many cases defending regulatory inquiries) at the same time. It also explains why refusing to pay the ransom no longer ends the threat: attackers who already copied the data before encrypting anything can still threaten to leak it regardless of whether a decryption key changes hands.
Comparitech’s quarter-by-quarter tracking shows an uneven but elevated 2026
Comparitech’s rolling ransomware trackers give the most granular public view of how attack volume has moved month to month through 2026. The firm counted 2,200 total ransomware attacks in Q1 2026, including 193 it was able to confirm through victim notifications or leak-site claims, and estimated that attackers stole more than 454 terabytes of data across those incidents. The average ransom demand in Q1 2026 came in around $480,000, up from roughly $381,000 in Q4 2025, a jump of about 26% in a single quarter.
Momentum did not hold in a straight line. April 2026 saw a sharp pullback, with Comparitech recording 628 attacks, a nearly 22% month-over-month decline and the lowest monthly total in six months, following a March peak of 801 attacks. Even in that slower month, the firm estimated almost 125 terabytes of data were stolen. That volatility is a useful corrective to any single headline percentage: ransomware activity in 2026 has moved in bursts tied to specific gang campaigns and law enforcement disruptions, not a smooth upward curve, even though the full-year trend line still points higher than 2025.
Which ransomware groups drove the Q1 2026 numbers
Comparitech’s Q1 2026 roundup identified Qilin as the most frequently claimed ransomware group of the quarter, linked to 353 attack claims, ahead of The Gentlemen with 202 claims and Akira with 201. Healthcare-sector attacks in Q1 2026 totaled 120, down 14% from 140 in Q4 2025, while education-sector attacks totaled 53, down 23% from 69 the prior quarter. Those sector-level declines in Q1 sit in tension with the sector-level increases Comparitech later reported for H1 as a whole, underscoring how much quarter-to-quarter noise sits underneath any annual percentage figure, including the 275% headline this story is built around.
Inside two 2026 incidents: a hospital in India and a school district in Illinois
BlackFog’s State of Ransomware report for June 2026 documented 102 publicly disclosed ransomware attacks across 21 countries that month, with healthcare the single most targeted sector at 30 incidents, ahead of services at 15 and education at 14. Two incidents from that report illustrate exactly the dynamic driving claims costs higher. At Chandrapur Cancer Care Foundation Hospital in India, attackers encrypted the hospital’s database and demanded 1.23 bitcoin, worth roughly $90,000 at the time, for a decryption key. Separately, an attack on Evanston Township High School District 202 in Illinois disrupted internet access, telephone systems, and broader school infrastructure, forcing the cancellation of summer programs while the district worked to restore operations.
Neither incident on its own moves a national statistic. Together with hundreds of similar cases tracked across 2026, including the McMinnville breach that sent leaked records circulating on the dark web, they illustrate why insurers keep flagging schools and hospitals specifically: the operational disruption is immediate and highly visible, the data exposed is sensitive by default, and the victim organizations rarely have the cybersecurity staffing to detect an intrusion before data has already left the network.
Double extortion has become the default, not the exception
The single most important shift underneath the 2026 numbers is not attack volume, it is tactics. Coalition’s finding that 70% of its ransomware claims now involve both encryption and exfiltration confirms what threat researchers have argued for several years: pure encryption-only ransomware, the kind that made headlines in 2017 with WannaCry, is now a minority tactic. Groups like Qilin, Akira, and newer entrants such as The Gentlemen build data theft into the attack chain from the start, because stolen data gives them leverage even against organizations with strong backups that can restore encrypted systems without paying anyone.
That shift also explains why insurance claims data, rather than simple attack counts, has become the preferred lens for measuring ransomware’s real-world cost. A ransomware roundup counting “attacks” treats a failed intrusion attempt the same as a catastrophic data theft event. A claims report counts dollars paid out for incident response, legal defense, regulatory fines, and credit monitoring, which is a far better proxy for how much damage data theft specifically is doing to schools, hospitals, and government agencies, even when the headline attack-count statistic moves in the opposite direction. Pure data-theft extortion crews outside the traditional ransomware model, including the group profiled in tech-insider.org’s look at ShinyHunters, have shown the same leverage works even without encrypting a single file.
Historical context: how we got from WannaCry to double extortion
Ransomware as a mass-market threat traces back to the 2017 WannaCry and NotPetya outbreaks, which were pure encryption plays: lock the files, demand bitcoin, no data theft involved. The Maze gang is widely credited with popularizing double extortion starting in late 2019, publishing stolen files from victims who refused to pay. By 2021 and 2022, ransomware-as-a-service platforms had turned that playbook into a commodity product that low-skill affiliates could rent, which is part of why attack volume kept climbing even as individual gangs like Conti and REvil were disrupted or rebranded.
The 2025-to-2026 transition tracked by Chainalysis adds another data point to that arc: the research firm found ransomware leak events reached nearly 8,000 in 2025, a 50% jump from 2024 and the highest total since it began systematically tracking dark web extortion sites, according to figures compiled by Axis Intelligence. Read together with Verizon’s 48% breach-involvement figure and Coalition’s 70% double-extortion rate for 2026, the trajectory is consistent even if the exact percentage in any single headline varies: ransomware groups have converged on data theft as a near-universal feature of the attack, not an occasional add-on.
Market impact: cyber insurance pricing and the public-sector insurance gap
Rising claims severity feeds directly back into what organizations pay for cyber insurance, and schools and local governments are the segment least able to absorb premium increases. Coalition’s 47% jump in average initial ransom demands, combined with the near-universal presence of data exfiltration in claims, gives underwriters a clear reason to tighten terms specifically around sublimits for data breach response costs, the line item that double extortion inflates the most. Several public-sector entities have already responded by self-insuring at the state level or pooling risk across multiple districts, a trend likely to accelerate if claims costs keep climbing through the back half of 2026. Settlements tied to earlier healthcare breaches, such as the $2.3 million Labcorp settlement Wisconsin joined, show how long the financial tail of a single data theft incident can stretch well past the initial headline.
There is a parallel effect on the broader cybersecurity vendor market. Rising claims costs are one of the clearest demand signals for extended detection and response platforms, managed detection services, and dark web monitoring tools aimed specifically at catching data exfiltration before a ransom note ever appears. Vendors selling into K-12 and healthcare IT budgets, historically the most price-sensitive segments of the security market, are likely to see continued budget growth through 2027 as boards treat ransomware insurance premiums as a line item that is only going to get more expensive without upfront investment in prevention.
Competitive comparison: how the major trackers measure ransomware differently
Part of why a figure like “275% surge” is hard to independently verify is that no two major trackers measure ransomware the same way, and that inconsistency is itself worth understanding before citing any single statistic as definitive.
| Tracker | What it measures | 2026 headline figure | Primary limitation |
|---|---|---|---|
| Verizon DBIR | Ransomware’s share of all analyzed breaches | 48% of breaches, up from 44% | Relies on partner-contributed incident data, not a full market census |
| Coalition | Insurance claims filed by its own policyholders | 70% double extortion, demands up 47% | Limited to Coalition’s own book of insured businesses |
| Comparitech | Publicly confirmed and claimed attacks by sector | 4,217 attacks in H1 2026, up 11% | Depends on leak-site claims, which gangs can exaggerate |
| BlackFog | Monthly publicly disclosed attacks by country/sector | 102 attacks in June 2026 across 21 countries | Counts only publicly disclosed incidents, likely undercounts total volume |
| Chainalysis / Axis Intelligence | Dark web leak-site extortion events | Nearly 8,000 leak events in 2025, up 50% | Tracks leak-site activity, not confirmed data theft volume |
Each methodology captures a real slice of the problem, but none of them captures the whole picture, and none of the five independently confirms a specific 275% increase in data theft for 2026. That is the core caveat worth repeating: the direction every tracker agrees on is up, sharply, but the exact percentage attached to any single headline deserves scrutiny before it gets repeated as settled fact.
Ransomware activity by sector and quarter in 2026
| Period | Government/Business attacks | Healthcare attacks | Education attacks | Source |
|---|---|---|---|---|
| Q1 2026 | Included in 2,200 total tracked attacks | 120 (down 14% QoQ) | 53 (down 23% QoQ) | Comparitech Q1 2026 roundup |
| H1 2026 (confirmed) | 319 business, 83 government | 49 | 33 | Comparitech H1 2026 roundup |
| April 2026 | 27 business, 8 government | 4 | 4 | Comparitech April 2026 roundup |
| June 2026 | Services: 15 | 30 (top target globally) | 14 | BlackFog State of Ransomware, June 2026 |
The pattern that emerges across every period is healthcare’s persistent position near the top of attack counts even as education fluctuates quarter to quarter. Combined with Coalition’s claims severity data, it reinforces why a hospital-specific incident, like the extended system outage covered in Luminis Health’s 28-day MyChart restoration, tends to generate outsized claims relative to its position in a raw attack-count table.
What security teams at schools, hospitals, and agencies should prioritize now
With double extortion now the dominant model rather than the exception, the practical defense priority has shifted away from pure ransomware-recovery planning and toward data exfiltration detection. Immutable, offline backups still matter for recovering encrypted systems quickly, but they do nothing to stop a gang from threatening to publish stolen files regardless of whether the victim restores from backup. Security teams at resource-constrained public-sector organizations are increasingly being advised to prioritize network egress monitoring and anomalous data-transfer detection ahead of, or alongside, backup investment, since that is the control point that actually interrupts a double-extortion attack before the theft half of it completes.
Identity-related entry points remain the common thread across nearly every major 2026 incident this site has covered, from stolen credentials to exploited vendor software, which is why the response increasingly starts with access hygiene rather than endpoint tooling alone. Organizations weighing where to spend limited security budgets in the final quarter of 2026 are better served closing the credential and patching gaps that let attackers in in the first place than adding another detection layer on top of an already-porous perimeter.
Predictions: where ransomware data theft trends head through 2027
Based on the trajectory across Verizon, Coalition, Comparitech, and BlackFog’s 2026 data, several developments look likely heading into 2027.
- Double extortion will keep climbing as a share of total ransomware incidents, likely surpassing Coalition’s current 70% figure within the next reporting cycle, as encryption-only attacks lose economic appeal against organizations with solid backups.
- Cyber insurance premiums for school districts and municipal governments will keep rising faster than the broader market, pushing more public-sector entities toward state-level risk pools rather than individual commercial policies.
- Average ransom demands will likely continue growing even as the share of victims who pay keeps falling, since attackers are pricing demands against stolen data volume rather than negotiating leverage alone.
- Expect continued quarter-to-quarter volatility in raw attack counts, similar to the swing between March 2026’s 801 attacks and April’s 628, driven by individual law enforcement takedowns rather than a smooth trend line.
- Healthcare will remain the most consistently targeted sector across 2027 reporting periods, given its combination of sensitive data, operational urgency, and historically under-resourced IT security teams relative to its attack surface.
The bottom line on the 275% figure
The Security Boulevard headline captures something real: ransomware data theft aimed at schools, hospitals, and government agencies has gotten measurably worse through 2026 by every metric independent trackers publish. Whether the specific number is 275% or some other figure closer to Coalition’s 47% ransom-demand growth or Comparitech’s 11% half-over-half attack growth, the direction is not in question. What remains unverified is the exact percentage and the methodology behind it, which is exactly the kind of detail worth demanding before repeating a viral statistic as established fact, even when the underlying concern it points to is legitimate and well documented elsewhere.
Frequently asked questions
Is the 275% ransomware data theft surge figure confirmed by multiple sources?
No. The figure traces to a Security Boulevard headline that does not disclose its underlying methodology, comparison period, or sample size in the publicly available version of the report. Independent data from Verizon, Coalition, and Comparitech confirms the broader trend of rising ransomware-related data theft in 2026 but does not independently validate the specific 275% number.
What percentage of breaches involved ransomware in 2026?
Verizon’s 2026 Data Breach Investigations Report found ransomware present in 48% of analyzed breaches, up from 44% in the prior year’s report.
What is double extortion ransomware?
Double extortion combines data encryption with data theft, letting attackers demand payment twice: once for a decryption key and again to prevent the stolen data from being published. Coalition’s 2026 Cyber Claims Report found 70% of the ransomware events in its claims data involved this combination.
How much are ransomware gangs demanding on average in 2026?
Coalition reported that average initial ransom demands rose 47% year over year to more than $1 million in 2026. Comparitech separately found the average demand in Q1 2026 was around $480,000, up from about $381,000 in Q4 2025.
Why are schools and hospitals targeted so often?
Both sectors tend to run under-resourced, aging IT infrastructure, hold large volumes of sensitive personal data, and face intense pressure to restore operations quickly rather than negotiate at length, which attackers use as leverage.
Do most organizations pay the ransom?
No. Coalition reported that 86% of the businesses it covers refused to pay ransomware demands in 2026, even as the size of those demands kept rising.
Which ransomware groups were most active in early 2026?
Comparitech’s Q1 2026 roundup identified Qilin as the most frequently claimed group, with 353 attack claims, ahead of The Gentlemen with 202 and Akira with 201.
How much data has been stolen in ransomware attacks in 2026?
Comparitech estimated more than 454 terabytes were stolen across the attacks it tracked in Q1 2026 alone, and roughly 125 terabytes more in April 2026, illustrating the scale of data theft even in a single-digit-week window.
Related
Related Coverage
Click Here For The Original Source.
