STOCK TITAN

New Zscaler Report Reveals AI-Assisted Attackers Move to Massive Data Theft, Executive Targeting, and Millions in Extortion Payments

ThreatLabz identified 52 newly active ransomware groups over the last year, with nine newcomers among the top 15 by victim volume.

(Neutral)

Sentiment and the balance of points

Rhea-AI Sentiment reads the wording of the document, how positive or negative its language is on a 1 to 5 scale. The balance of points shown with the takes weighs what the document actually discloses, so the two can disagree, for example when a trial that missed its main goal is described in upbeat language.

Tags
AI

Zscaler (ZS) released its ThreatLabz 2026 Ransomware Report, examining data theft, ransom payments and employee targeting in AI-assisted attacks. The research covers April 2025 through March 2026. Ransomware data theft increased more than 275% year over year to 896.2 terabytes, while the average ransom payment rose 5.3% to $431,995. Manager-level employees and above accounted for 62% of victims in attacks.

Manufacturing and technology remained the most targeted industries. Freight and logistics recorded 725% year-over-year growth in ransomware activity, followed by utilities at 622%. U.S. organizations accounted for 50.7% of observed activity. ThreatLabz tracked 7,366 victims listed on ransomware leak sites, a 3% year-over-year decline. Zscaler said attackers are using generative AI to accelerate operations and increasingly favoring data theft over file encryption.

Loading...
Loading translation...

News Explained

ThreatLabz says blockchain transactions associated with ransomware payments reached $328 million during its April 2025 through March 2026 study period.

Key Figures

Ransomware data theft increase: More than 275% year over year Data exfiltrated: 896.2 terabytes Ransomware payments: $328 million +4 more
Ransomware data theft increase
More than 275% year over year
ThreatLabz 2026 Ransomware Report
Data exfiltrated
896.2 terabytes
Report findings
Ransomware payments
$328 million
Blockchain transactions associated with ransomware payments
Average ransom payment
$431,995
Increased 5.3% year over year
Average ransom payment increase
5.3% year over year
Report findings
Victims with manager-level titles and above
62%
Share of victims in attacks
Victims listed on ransomware leak sites
7,366
ThreatLabz tracked victims; volume was down 3% year over year

Key Terms

genai, data exfiltration, social engineering
3 terms
genai technical
"They are using GenAI to speed up operations"
Generative AI (genai) is a type of artificial intelligence designed to create new content, such as text, images, or music, that resembles human-produced work. It matters to investors because it has the potential to transform industries by automating tasks, enhancing creativity, and enabling new products and services, which can influence company performance and market opportunities.
data exfiltration technical
"preventing data exfiltration"
Data exfiltration is the unauthorized copying or removal of sensitive information from an organization’s systems, like someone sneaking files out of a locked office. It matters to investors because stolen data can lead to direct financial loss, regulatory fines, legal liability, damage to customer trust, and operational disruption — all of which can reduce revenue and share value and create unpredictable costs for the company.
social engineering technical
"enable social engineering, lateral movement, data theft, and file encryption"
Social engineering is the practice of manipulating people into revealing confidential information, granting access, or taking actions that compromise security, often by posing as a trusted person or using urgent, persuasive stories. For investors it matters because these scams can lead to direct financial loss, theft of sensitive corporate data, disrupted operations, or damage to a company’s reputation — similar to a con artist who tricks a business into handing over its keys.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

New Zscaler ThreatLabz 2026 Ransomware Report finds attackers stole nearly 900 terabytes of data, increasingly targeted employees with privileged roles, and used GenAI to accelerate operations

SAN JOSE, Calif., Sept. 30, 2026 (GLOBE NEWSWIRE) -- Zscaler, Inc. (NASDAQ: ZS), the cybersecurity platform for the AI era, today released new findings from the Zscaler ThreatLabz 2026 Ransomware Report, showing that ransomware is on the rise, and is being aided by AI, increasing by more than 275% since last year, while costing companies more than $328 million in payments to hacking groups. Zscaler’s research revealed that nearly 900 terabytes of data – the equivalent to 90 times the print collection at the Library of Congress – were stolen over the course of a year. The AI-driven increase in ransomware is targeting nearly two-thirds of senior-level executives, and threat actors are increasingly using trusted workplace tools, including Microsoft Teams, to enable data theft and lateral movement within an organization’s environment.

Key findings from the ThreatLabz 2026 Ransomware Report reveal:

  • Ransomware data theft increased more than 275% year over year, reaching 896.2 terabytes of exfiltrated data
  • Blockchain transactions associated with ransomware payments reached $328 million
  • The average ransom payment rose 5.3% year over year to $431,995
  • Manager-level titles and above accounted for 62% of victims in attacks, highlighting a focus on employees with privileged roles and business influence
  • Threat actors are increasingly abusing trusted enterprise tools, including Microsoft Teams and Quick Assist, to enable social engineering, lateral movement, data theft, and file encryption

"Successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging data theft attacks," said Deepen Desai, Executive Vice President of Cybersecurity at Zscaler. "They are using GenAI to speed up operations, and focusing on stealing more of an organization’s intellectual property, customer information, and other sensitive data to drive payment. Security teams need to stop these attacks early by reducing initial access opportunities, limiting lateral movement, and preventing data exfiltration."

Additional findings in the Zscaler ThreatLabz 2026 Ransomware Report include:

  • Manufacturing and technology remained the most targeted industries while freight & logistics (+725%), and utilities (+622%) saw the fastest year-over-year growth.
  • The United States remained the top ransomware target with U.S. organizations accounting for 50.7% of observed activity, far ahead of Canada (4.8%), Germany (4.3%), and the U.K. (4.1%).
  • Script-based tooling is playing a larger role in ransomware as JavaScript, PowerShell, Python, and other scripting languages are helping attackers develop new tooling faster and blend in with legitimate activity.
  • Ransomware victim volumes remain persistent amid major ecosystem churn: ThreatLabz tracked 7,366 victims listed on ransomware leak sites, representing only a 3% YoY decline. Qilin, Akira and INC Ransom accounted for 34% of disclosed victims.
  • The ransomware landscape is seeing significant expansion, showing nine of the top 15 groups by victim volume were new to the rankings, and ThreatLabz identified 52 newly active groups over the last year.

The Zscaler ThreatLabz 2026 Ransomware Report provides guidance on how to disrupt ransomware across the attack lifecycle and examines the current threat landscape in depth, including exfiltration trends, victim targeting, evolving attacker tradecraft, and extortion economics.

To learn more, read the full report here: https://www.zscaler.com/campaign/threatlabz-ransomware-report

Methodology
The report is based on Zscaler telemetry and ThreatLabz analysis and examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns. Together, the findings show a threat landscape where attackers are increasing leverage through stolen data, targeting business-influential employees, and improving operational efficiency with AI-assisted tooling and abuse of legitimate enterprise platforms.

About Zscaler
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™ ️platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 200+ public data centers globally and thousands of private sites at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.

Media Contact
Nick Gonzalez, Director of Global Public Relations, press@zscaler.com


FAQ

AI-generated questions and answers. How Rhea-AI works. Not financial advice.

What data and period underpin Zscaler’s 2026 Ransomware Report?

The report uses Zscaler telemetry and ThreatLabz analysis to examine ransomware activity from April 2025 through March 2026. Its scope includes groups and affiliates, victim targeting, attack techniques, data theft and payment patterns.

Keep reading