Ransomware has changed its business model. Zscaler's ThreatLabz 2026 Ransomware Report, released today, finds that attackers exfiltrated 896.2 terabytes of data over the past year — a more than 275% increase year over year — with GenAI accelerating operations and nearly two-thirds of victims holding manager titles or above.

The headline number — roughly 900 terabytes, or 90 times the print collection of the Library of Congress — marks a shift in where the leverage sits. Encryption that disrupts business is giving way to quiet data theft that extorts with intellectual property, customer information, and other sensitive files.

From encryption to extortion#

"Successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging data theft attacks," said Deepen Desai, Zscaler's executive vice president of cybersecurity. "They are using GenAI to speed up operations, and focusing on stealing more of an organization's intellectual property, customer information, and other sensitive data to drive payment."

The report also documents how attackers are abusing trusted enterprise tools — including Microsoft Teams and Quick Assist — to enable social engineering, lateral movement, data theft, and file encryption. The software employees use every day is now the delivery mechanism.

Illustration of an executive office desk at night with a laptop screen locked by ransomware
Illustration: AI Frontier Post (AI-generated).

The economics: $328 million in payments#

The money is real even as the tactics evolve. Blockchain transactions associated with ransomware payments reached $328 million, and the average ransom payment rose 5.3% year over year to $431,995.

Victim volumes stayed persistent despite major ecosystem churn: ThreatLabz tracked 7,366 victims listed on ransomware leak sites, representing only a 3% year-over-year decline. Qilin, Akira and INC Ransom accounted for 34% of disclosed victims.

Executives in the crosshairs#

The targeting is deliberately top-down. Manager-level titles and above accounted for 62% of victims in the attacks Zscaler analyzed — employees with privileged roles and business influence, exactly the people most likely to hold the credentials and the data worth stealing.

Geographically, the United States remained the top ransomware target with 50.7% of observed activity, far ahead of Canada (4.8%), Germany (4.3%), and the U.K. (4.1%). Manufacturing and technology remained the most targeted industries, while freight & logistics (+725%) and utilities (+622%) saw the fastest year-over-year growth.

Illustration of a data center at night with streams of data being siphoned out of server cabinets
Illustration: AI Frontier Post (AI-generated).

GenAI as the accelerant#

AI shows up on both sides of this fight. Zscaler says attackers are using GenAI to speed up operations — and scripting languages (JavaScript, PowerShell, Python) are helping them develop new tooling faster while blending in with legitimate activity.

One caveat: this is a vendor-commissioned report. Zscaler sells zero-trust security, so its findings come from its own telemetry and ThreatLabz analysis, examining ransomware activity from April 2025 through March 2026. The trends are real — the AI-assisted data-theft pivot matches what other threat researchers have been documenting — but the exact percentages reflect Zscaler's vantage point, not the whole internet.

What to watch#

The ransomware landscape is churning fast: nine of the top 15 groups by victim volume were new to the rankings, and ThreatLabz identified 52 newly active groups over the last year. The old names may be gone, but the victim count barely budged.

The practical takeaway is in Desai's advice to security teams: reduce initial access opportunities, limit lateral movement, and prevent data exfiltration — because once the data is out, the extortion doesn't need encryption at all.