Zscaler's ThreatLabz tracked a 275.8% jump in stolen data across the ten biggest ransomware groups while the victim count slipped 3%. Arctic Wolf and Coveware both report that crews are increasingly skipping encryption and selling silence instead.
Key Takeaways
For two decades the ransomware playbook was simple: lock the files, demand payment, and let the backup team decide whether to negotiate. The numbers published at the end of September suggest that playbook is being retired by the people who wrote it. The data volume leaving victim networks grew sevenfold in a year, while the number of victims named on leak sites actually slipped. Attackers are not hitting more companies. They are taking far more from each one, and a restored backup does nothing to un-steal it.
Zscaler's ThreatLabz 2026 Ransomware Report, released September 30, covers April 2025 through March 2026 and counts 7,366 victims disclosed on leak sites, a 3% decline year over year. Across the ten groups that published the most data, exfiltration reached 896.2 terabytes, a 275.8% increase on the 123.8 terabytes recorded in the previous reporting period. The market also churned: ThreatLabz identified 52 newly active groups, and nine of the top 15 by victim volume were new to the rankings, even though Qilin, Akira, and INC Ransom together still account for 34% of disclosed victims.
The economics moved in an odd direction. Zscaler's own breakdown shows total payment volume down 15.8% to roughly $328 million and the number of payments down 20.1%, while the average payment climbed 5.3% to $431,995. Read together, the figures describe an extortion business that is more selective and more data-hungry, with the threat of publication carrying more of the weight that encryption used to carry.
The same report describes who is being targeted and how. Some 62% of named victims held manager-level titles or above, and about three quarters worked in finance, sales, operations, HR, or marketing, the functions that hold contracts, payroll, customer lists, and deal terms. The documented pathway starts with spam bombing that floods an inbox, followed by a Microsoft Teams call from someone posing as helpful IT support, who then steers the victim toward a legitimate remote support tool such as Quick Assist. From there, JavaScript, PowerShell, and Python tooling handles reconnaissance, persistence, and lateral movement, with attackers using generative AI to speed up the work.
An independent source points the same way. Coveware's second-quarter 2026 report, published September 22, names help desk impersonation as the primary attack vector, with intruders posing as internal IT staff or contractors to talk employees into granting access or resetting multi-factor authentication. Command-and-control activity appeared in 69% of its cases, up 11 points from the first quarter. Nothing in that chain looks like malware at the front door. It looks like a normal support request.
Arctic Wolf's 2026 threat report, published February 17, put a number on the shift: data-extortion-only incidents rose elevenfold between November 2024 and November 2025, from 2% to 22% of its incident-response cases, while classic ransomware still made up 44%. Arctic Wolf noted that some threat actors have started abandoning encryption altogether in pursuit of better net returns. Coveware sees the same pattern, with criminals logging in on stolen credentials, copying valuable data, and threatening to publish it without deploying any malware.
That matters because most ransomware defenses were built around the encryption event. Immutable backups, tested restores, and recovery time objectives all assume the damage is availability. When the damage is disclosure, none of them apply. Coveware's second-quarter figures show how uneven the outcomes have become: an average payment of $1,880,612 against a median of $150,000, which means a handful of very large settlements are dragging the mean while the typical case is far smaller.
Backups answer the question of whether you can keep operating. They say nothing about whether your customers' data is on a criminal's server, and that is the question the 896.2 terabytes now puts to every security team.
Guide
Zscaler counted 896.2 terabytes stolen in a year, and none of it needed encryption to hurt. This guide covers access controls and audit trails across the data lifecycle, so one hijacked login reaches less and you can show what left.
Download
Guide
The chain Zscaler describes starts with a flood of spam and a friendly voice on Teams offering help. This awareness guide covers the habits that stop an employee handing over a credential or a remote session.
Download
Guide
Data theft finishes before any ransom note appears, and Arctic Wolf says 22% of its cases never involved encryption at all. This guide covers the behavioral signals of an attack in progress, so you can act while data is still leaving.
Download
Unit 42 found only 12 of 405 AI-enabled malware samples on a real production endpoint, with roughly 97% never leaving sandboxes and VirusTotal.
Cyera's review of 7,246 publicly reported AI incidents found 188 cases where an autonomous agent caused real damage with no attacker involved.
CrowdStrike's 2026 Global Threat Report puts the average eCrime breakout time at 29 minutes, a 65% jump in attacker speed.