Security

Ransomware Crews Stole 896 Terabytes in a Year, and 62% of Their Victims Held Manager Titles or Above

Zscaler's ThreatLabz tracked a 275.8% jump in stolen data across the ten biggest ransomware groups while the victim count slipped 3%. Arctic Wolf and Coveware both report that crews are increasingly skipping encryption and selling silence instead.

October 1, 2026 · Security
Server racks in a dim server room with blue and green indicator lights and a cabinet edge glowing red

Key Takeaways

  • Zscaler's ThreatLabz found the ten largest ransomware groups exfiltrated 896.2 terabytes between April 2025 and March 2026, up 275.8% from 123.8 terabytes the year before.
  • Of the 7,366 victims named on leak sites, 62% held manager-level titles or above, and roughly 75% of the targeted individuals worked in finance, sales, operations, HR, or marketing.
  • Arctic Wolf reports that data-extortion-only cases rose from 2% to 22% of its incident-response caseload in a year, an elevenfold jump, as some crews abandon encryption entirely.
  • Total ransom payments fell 15.8% to about $328 million, yet the average payment rose 5.3% to $431,995, which suggests fewer victims are paying but those who do are paying more.

For two decades the ransomware playbook was simple: lock the files, demand payment, and let the backup team decide whether to negotiate. The numbers published at the end of September suggest that playbook is being retired by the people who wrote it. The data volume leaving victim networks grew sevenfold in a year, while the number of victims named on leak sites actually slipped. Attackers are not hitting more companies. They are taking far more from each one, and a restored backup does nothing to un-steal it.

The Volume Grew Sevenfold While the Victim Count Barely Moved

Zscaler's ThreatLabz 2026 Ransomware Report, released September 30, covers April 2025 through March 2026 and counts 7,366 victims disclosed on leak sites, a 3% decline year over year. Across the ten groups that published the most data, exfiltration reached 896.2 terabytes, a 275.8% increase on the 123.8 terabytes recorded in the previous reporting period. The market also churned: ThreatLabz identified 52 newly active groups, and nine of the top 15 by victim volume were new to the rankings, even though Qilin, Akira, and INC Ransom together still account for 34% of disclosed victims.

The economics moved in an odd direction. Zscaler's own breakdown shows total payment volume down 15.8% to roughly $328 million and the number of payments down 20.1%, while the average payment climbed 5.3% to $431,995. Read together, the figures describe an extortion business that is more selective and more data-hungry, with the threat of publication carrying more of the weight that encryption used to carry.

The Way In Is a Phone Call on Teams, Not a Malware Attachment

The same report describes who is being targeted and how. Some 62% of named victims held manager-level titles or above, and about three quarters worked in finance, sales, operations, HR, or marketing, the functions that hold contracts, payroll, customer lists, and deal terms. The documented pathway starts with spam bombing that floods an inbox, followed by a Microsoft Teams call from someone posing as helpful IT support, who then steers the victim toward a legitimate remote support tool such as Quick Assist. From there, JavaScript, PowerShell, and Python tooling handles reconnaissance, persistence, and lateral movement, with attackers using generative AI to speed up the work.

An independent source points the same way. Coveware's second-quarter 2026 report, published September 22, names help desk impersonation as the primary attack vector, with intruders posing as internal IT staff or contractors to talk employees into granting access or resetting multi-factor authentication. Command-and-control activity appeared in 69% of its cases, up 11 points from the first quarter. Nothing in that chain looks like malware at the front door. It looks like a normal support request.

Encryption Became Optional, Which Breaks the Recovery Plan

Arctic Wolf's 2026 threat report, published February 17, put a number on the shift: data-extortion-only incidents rose elevenfold between November 2024 and November 2025, from 2% to 22% of its incident-response cases, while classic ransomware still made up 44%. Arctic Wolf noted that some threat actors have started abandoning encryption altogether in pursuit of better net returns. Coveware sees the same pattern, with criminals logging in on stolen credentials, copying valuable data, and threatening to publish it without deploying any malware.

That matters because most ransomware defenses were built around the encryption event. Immutable backups, tested restores, and recovery time objectives all assume the damage is availability. When the damage is disclosure, none of them apply. Coveware's second-quarter figures show how uneven the outcomes have become: an average payment of $1,880,612 against a median of $150,000, which means a handful of very large settlements are dragging the mean while the typical case is far smaller.

Backups answer the question of whether you can keep operating. They say nothing about whether your customers' data is on a criminal's server, and that is the question the 896.2 terabytes now puts to every security team.

Share

More in Security

All Resources →