Estimated reading time: 6 minutes
Ransomware leak sites listed 7,366 victims over the past year. That is 3% fewer than the year before. But…
The data taken from those victims tells a different story. Among the 10 groups that leaked the most, combined exfiltration volume rose 275.8% to 896.2 terabytes. Several groups averaged more than a terabyte per victim. Those figures come from the Zscaler ThreatLabz 2026 Ransomware Report. It covers April 2025 to March 2026. The analysis draws on leak site data, Zscaler telemetry, and blockchain tracking of Bitcoin payments with TRM Labs.
Ransomware Data Exfiltration Becomes The Lever
Deepen Desai, Zscaler’s executive vice president of cybersecurity, described the shift. Extortion is moving away from file encryption, he said. It is moving toward “less visible, but more damaging data theft attacks.”
That shift changes what a claim looks like. The report puts it plainly: ransomware’s leverage “is growing by the terabyte.” Encryption stops operations and drives business interruption. Data theft drives notification, privacy liability, and regulatory exposure. A victim that restores cleanly from backup can still face all three.
The report does not settle why theft volumes jumped. It lists better tooling, including AI-assisted reconnaissance and data analysis, more efficient operations, and shifts in targeting as possible reasons.
Fewer Ransom Payments, A Bigger Tail
The payment data points the same way. Known ransom payments fell to 760, down 20.1% from 951. Total volume fell 15.8% to $327.8 million. The average payment rose 5.3% to $431,995.
The median barely moved. It sat at $154,700, against $155,000 a year earlier. A flat median alongside a rising average points to bigger payments at the top end.
Payments also concentrated. The top three groups took 47.5% of known payment volume, up from 31.1%. Akira alone received $73 million.
ThreatLabz notes the data captures final known payments only. Initial demands are not visible. It says the decline may be due in part to law enforcement action and the shutdown of several large groups.
Initial Access Through Trusted Tools
The report details an access playbook built on tools employees already trust.
Attackers first flood a target’s inbox with spam. They then call the employee on Microsoft Teams, posing as IT staff offering to fix the problem. The caller talks the employee into opening Microsoft Quick Assist or similar remote support software. From there, the attackers deploy malware and move through the network.
The sequence does not need to defeat MFA. The employee grants access. Ransomware data exfiltration follows from there.
Ransomware Targets Moved Up The Org Chart
ThreatLabz examined 351 victims at 334 organizations over one month. A single ransomware group accounted for all of them. It is known for initial access and large-scale data theft.
Of those victims, 62% held manager-level titles or above. Roughly three-quarters worked in finance, sales, operations, HR, or marketing. Those roles sit close to payments, customer records, and approvals.
The report says generative AI is also lowering friction for attackers. ThreatLabz observed a surge in new malware families. Some of that tooling appeared to be GenAI-built, it said.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
Where Ransomware Grew
Manufacturing again had the most victims, at 1,025, down 4%. Technology followed at 605, down 37%.
The steepest rises came elsewhere. Freight and logistics victims rose 725% to 132. Andrew Horkan of Cyber Tzar described that sector’s exposure on this week’s podcast. A hauler he works with lost £390,000 in the month after the Jaguar Land Rover attack.
Utilities rose 622% to 65 victims. ThreatLabz excluded utilities from its formal year-on-year comparison because the prior year had fewer than 10. Attacks on the sector reach the operational technology risks this publication has tracked.
Accounting rose 618%, business services 187% and legal 87%.
The United States accounted for 50.7% of victims. Canada followed at 4.8%, Germany at 4.3% and the United Kingdom at 4.1%. US counts were essentially flat. German victims rose 20.8%. UK victims fell 12%.
New Names, Old Playbooks
Nine of the top 15 groups by victim count were new to the rankings. ThreatLabz identified 52 newly active groups over the year.
It says the turnover may be due to law enforcement disruption, rebranding, and affiliates moving between operations. The playbooks persist as the brands change.
That matches what Matthew Butler of Travelers told the Cyber Insurance News podcast. Groups rarely start from nothing, he said. Operators carry their tactics from one brand name to the next.
FAQ – Ransomware Data Exfiltration
How much data did ransomware groups steal?
The top 10 ransomware groups by leak volume exfiltrated 896.2 terabytes between April 2025 and March 2026, up 275.8 percent year over year, according to Zscaler ThreatLabz.
Did the number of ransomware victims rise?
No. ThreatLabz counted 7,366 victims on leak sites, down 3 percent. The growth was in the volume of data taken, not the number of organizations listed.
What happened to ransom payments?
Known payments fell 20 percent to 760, and total volume fell 15.8 percent to 327.8 million dollars. The average rose 5.3 percent to 431,995 dollars while the median held at about 155,000 dollars.
How are attackers getting in?
One common playbook floods a target with spam, then calls them on Microsoft Teams posing as IT support and persuades them to open Quick Assist or similar remote support tools.
Which sectors saw the biggest increases?
Freight and logistics rose 725 percent to 132 victims, and utilities rose 622 percent to 65. Manufacturing still had the most victims at 1,025.
Why does data theft matter for cyber insurance?
Encryption mainly drives business interruption losses. Data theft drives notification, privacy liability and regulatory costs, which can arise even when a victim restores from backup.
Related Cyber Insurance Posts
- GPT-6 Astra Asked Permission. An Automated Reply Said Use Your Best “Judgement.”
- Cyber Insurance Market Size is Growing Fast But Cyber Insurance Rates Are Shrinking?(Opens in a new browser tab)
- Ransomware Statistics Q1 2026: Eight In Nine Attacks Never Become Public(Opens in a new browser tab)
- Zero Trust Security Could Prevent 31% of Cyber Attacks, Save $465B Globally(Opens in a new browser tab)
- Half Of This Year’s Manufacturing Ransomware Came From Groups That Did Not Exist Two Years Ago(Opens in a new browser tab)