Zscaler, Inc. (NASDAQ: ZS), the cybersecurity platform for the AI era, has published new findings from its Zscaler ThreatLabz 2026 Ransomware Report. The research shows that ransomware activity increased by more than 275% year over year, with attacks increasingly leveraging AI and generating more than $328 million in payments to hacking groups.
Over a 12-month period, researchers recorded nearly 900 terabytes of stolen data, equivalent to approximately 90 times the print collection of the Library of Congress. AI-assisted ransomware campaigns are increasingly targeting senior-level executives, with nearly two-thirds of victims holding management positions or higher. Threat actors are also exploiting trusted workplace applications, including Microsoft Teams, to facilitate data theft and lateral movement within corporate environments.
Key findings from the ThreatLabz 2026 Ransomware Report include:
- Ransomware data theft surged: Exfiltrated data increased by more than 275% year over year, reaching 896.2 terabytes.
- Extortion payments exceeded $328 million: Blockchain transactions associated with ransomware payments reached $328 million.
- Average ransom payments increased: The average payment climbed 5.3% year over year to $431,995.
- Executives and privileged employees faced increased targeting: Employees with manager-level titles or higher accounted for 62% of ransomware victims, underscoring attackers’ focus on individuals with elevated privileges and business influence.
- Legitimate enterprise tools became attack vectors: Threat actors increasingly abused trusted applications, including Microsoft Teams and Quick Assist, to conduct social engineering, move laterally, steal data, and encrypt files.
“Successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging data theft attacks,” said Deepen Desai, Executive Vice President of Cybersecurity at Zscaler. “They are using GenAI to speed up operations, and focusing on stealing more of an organizations’ intellectual property, customer information, and other sensitive data to drive payment. Security teams need to stop these attacks early by reducing initial access opportunities, limiting lateral movement, and preventing data exfiltration.”
Additional findings from the Zscaler ThreatLabz 2026 Ransomware Report highlight several developments in the threat landscape:
- Freight and logistics and utilities experienced sharp increases: Manufacturing and technology remained the most frequently targeted industries, while attacks against freight and logistics organizations grew 725% year over year and those targeting utilities increased 622%.
- The United States remained the leading ransomware target: U.S. organizations accounted for 50.7% of observed activity, substantially exceeding Canada’s 4.8%, Germany’s 4.3%, and the U.K.’s 4.1%.
- Script-based tooling gained prominence: Attackers increasingly relied on JavaScript, PowerShell, Python, and other scripting languages to accelerate the development of new tools and make malicious activity harder to distinguish from legitimate operations.
- Victim numbers remained high despite changes among ransomware groups: ThreatLabz tracked 7,366 victims listed on ransomware leak sites, representing a year-over-year decline of just 3%. Qilin, Akira, and INC Ransom accounted for 34% of disclosed victims.
- New ransomware groups continued to emerge: Nine of the 15 leading groups ranked by victim volume were new to the rankings, while ThreatLabz identified 52 newly active groups over the past year.
The Zscaler ThreatLabz 2026 Ransomware Report examines the evolving ransomware threat landscape and provides recommendations for disrupting attacks throughout the attack lifecycle. It covers data exfiltration trends, victim targeting, changes in attacker techniques, and the economics of ransomware extortion.
Read the full report: https://www.zscaler.com/campaign/threatlabz-ransomware-report
Methodology
The report draws on Zscaler telemetry and ThreatLabz analysis of ransomware activity between April 2025 and March 2026. It examines ransomware groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns. The findings point to a threat environment in which attackers are increasing their leverage through data theft, targeting employees with significant business influence, and improving operational efficiency through AI-assisted tooling and the abuse of legitimate enterprise platforms.
About Zscaler
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust ExchangeTM ️platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 200+ public data centers globally and thousands of private sites at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
Media Contact
Yvette Bankole, Account Executive, We. Communications: ybankole@wecommunications.com
Join our LinkedIn group Information Security Community!
