Zscaler ThreatLabz 2026 Ransomware Report finds AI‑assisted attacks drive 275% rise in data theft | #ransomware | #cybercrime


Zscaler’s ThreatLabz 2026 Ransomware Report shows ransomware activity increased by more than 275% year‑on‑year, driven by AI‑assisted tooling, resulting in the theft of 896 terabytes of data and $328 million in blockchain‑based extortion payments.

According to Zscaler’s ThreatLabz 2026 Ransomware Report, ransomware activity is increasingly shifting from disruptive encryption towards large-scale data theft, with artificial intelligence helping attackers accelerate operations. Zscaler describes generative AI as an accelerator of ransomware operations rather than a replacement for established attack techniques. The report offers guidance on disrupting ransomware across the attack lifecycle. It also examines the current threat landscape in depth, including exfiltration trends, victim targeting, evolving attacker tradecraft and extortion economics.

Covering ransomware activity observed between April 2025 and March 2026, the report finds that the volume of data stolen in ransomware incidents increased by more than 275% year on year, reaching 896.2 terabytes, while blockchain transactions associated with ransomware payments reached $328 million and the average ransom payment rose 5.3% to $431.995. Attackers increasingly targeted employees with privileged roles and business influence, with managers and above accounting for 62% of victims.

Manufacturing and technology remained the most targeted sectors, while freight and logistics (+725%) and utilities (+622%) recorded the fastest growth. The United States accounted for 50.7% of observed ransomware activity, while ThreatLabz identified 7.366 victims listed on ransomware leak sites, only a 3% decline from the previous year.

At the same time, the ecosystem continued to expand and fragment, with 52 newly active ransomware groups identified during the reporting period and nine of the 15 largest groups by victim volume being new to the rankings.

The report identifies a broader evolution in ransomware tradecraft. Attackers are also abusing trusted enterprise applications, including Microsoft Teams and Quick Assist, for social engineering, lateral movement, data theft and file encryption, as well as greater use of scripting languages including JavaScript, PowerShell and Python to develop tooling and blend malicious activity with legitimate processes.

The role of AI is significant because it can reduce the time and effort required across multiple stages of an attack. ThreatLabz’s separate 2026 AI Security Report, based on nearly one trillion AI/ML transactions observed across the Zscaler Zero Trust Exchange during 2025, found that enterprise AI activity increased 83% year on year and involved more than 3.400 applications.

Why does it matter?

The ThreatLabz findings illustrate a broader transformation of ransomware from a predominantly encryption-driven disruption model towards an intelligence- and data-driven extortion model, with AI contributing to the efficiency of the attack chain. This convergence means that AI is becoming both an enterprise productivity layer and an operational accelerator for threat actors.

In ransomware campaigns, the strategic effect may therefore be less about creating entirely new attack techniques than increasing the scale, speed and adaptability with which existing techniques can be executed.

The shift towards data theft also changes the economics and operational logic of extortion. Encryption remains disruptive, but stealing sensitive information can provide attackers with leverage even where organisations maintain reliable backups or can restore affected systems. Zscaler reports that attackers are increasingly focusing on intellectual property, customer information and other sensitive data, while trusted workplace applications can provide additional pathways for lateral movement and exfiltration.

This creates a broader defensive challenge: organisations must not only prevent initial compromise but also limit identity-based access, control lateral movement and detect abnormal data transfers. Zscaler’s findings on AI adoption reinforce the importance of visibility, as enterprises increasingly operate large and distributed AI environments in which data flows through both dedicated AI applications and embedded AI functionality.

The reported 275% increase in stolen data should therefore be understood not simply as an increase in ransomware volume, but as evidence of greater attacker capacity to identify, access and extract valuable information at scale.

For law enforcement, judiciary and policymakers, fighting against cybercrime, the challenge is consequently moving beyond ransomware protection alone towards controlling identities, data access, enterprise applications and AI-enabled activity across the entire digital environment.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.