Ransomware Data Theft Surges 275% in 2026 Report

0
13
Ransomware Data Theft Surges 275% in 2026 Report
Ransomware Data Theft Surges 275% in 2026 Report

Editorial Disclosure: This article is an editorial-assisted curated synthesis of verified global coverage. The original source reporting has been analyzed, structured, and compiled by Pune.Media’s Editorial Desk to bring you high-density business insights.

Original Coverage & Source Attribution: shattered.io

A new ransomware report is forcing security teams to rethink what “getting hit” actually means in 2026. According to the Zscaler ThreatLabz 2026 Ransomware Report, as covered by Security Boulevard, the volume of data stolen by the ten most active ransomware groups jumped 275.8% year over year, from 123.8 terabytes in the prior reporting window to 896.2 terabytes in the period spanning April 2025 through March 2026. That is more than seven times the data-theft volume recorded just two reporting cycles earlier, and it is happening at the same time ransom payment volume is falling.

The headline number sounds like a contradiction. Attackers are stealing far more data, yet fewer victims are paying, and the total known payment volume is down. Read the report closely and the contradiction resolves into a strategy shift: ransomware operators have stopped treating encryption as the main weapon and started treating stolen data as the primary leverage. Schools, hospitals, and government agencies absorbed some of the largest single claims, with one group alone reportedly exfiltrating 30 terabytes from a government target in a single campaign.

What the Zscaler ThreatLabz 2026 Ransomware Report Actually Found

ThreatLabz, Zscaler’s threat intelligence arm, built the report by tracking activity tied to the top 10 ransomware groups and their public leak sites, a method that has become standard across the industry because most ransomware gangs now operate “shame sites” where they post stolen files to pressure non-paying victims. The 275.8% year-over-year increase in stolen data refers specifically to the volume these groups claimed or demonstrated taking, not a theoretical estimate. The report frames the current window as April 2025 through March 2026, compared against a 2023–2024 baseline of 123.8 terabytes.

Running the math on that comparison tells its own story. A jump from 123.8 TB to 896.2 TB is not a modest escalation, it is a different order of magnitude. For context, 896 terabytes is roughly enough storage to hold tens of millions of scanned documents, medical records, or internal email archives, depending on file type and compression. When that much material sits on a criminal server, “restore from backup and move on” stops being a complete incident response plan.

The Data Theft Numbers, Side by Side

The scale of the shift is easiest to see in a direct comparison of the two reporting windows ThreatLabz tracked.

Reporting Period Data Stolen by Top 10 Groups Change vs. Prior Period
2023–2024 baseline 123.8 TB —
April 2025–March 2026 896.2 TB +275.8%
Implied multiple — More than 7x prior volume

Data-theft volume and ransom payments are no longer moving in the same direction, which is the real story buried inside this report. Known ransom payment volume fell 15.8% year over year to $327.8 million, and the total number of recorded individual payments dropped 20.1%. Fewer organizations are cutting checks to criminals. But the ones who do pay are paying more: the average ransom payment rose 5.3% to $431,995, continuing a multi-year trend where big-game-hunting groups chase fewer, larger targets instead of spraying ransomware across smaller businesses.

Why Attackers Are Stealing More While Collecting Less in Ransom

Three forces explain the gap between rising theft and falling payment totals. First, cyber insurers and incident response firms have gotten better at talking victims out of paying when backups are intact, which cuts into payment counts even as attacks continue. Second, law enforcement pressure, sanctions exposure, and crypto-tracing tools from firms like Chainalysis have made receiving and laundering ransom proceeds riskier, pushing some operators to pursue extortion through data leaks instead of waiting for a wire transfer. Third, and most practically, modern backup and recovery tooling has made pure encryption attacks less effective. If a hospital can restore its systems from immutable backups in a day, the encryption half of the attack loses its teeth.

What has not lost its teeth is the threat of publishing stolen patient records, student files, or internal government communications. That is why groups are hoarding more data than ever even as fewer victims agree to pay for a decryption key. The extortion now happens on two tracks: pay to get files back, or pay to keep them from being published. ThreatLabz’s numbers suggest the second track is increasingly doing the heavy lifting.

Schools, Hospitals, and Government Absorb the Biggest Claims

The report singles out schools, hospitals, and government agencies as sectors tied to some of the largest individual data-theft claims of the period. These sectors share a common vulnerability: they hold large volumes of sensitive personal data (medical histories, student records, benefits information) but historically have had smaller security budgets than finance or technology companies to defend it. That mismatch between data sensitivity and security spend has made them attractive, high-leverage targets for groups optimizing for extortion value rather than ransom speed.

Interestingly, the broader sector-level attack frequency tells a more complicated story than “government and healthcare are under siege.” According to the figures cited in the report, overall government ransomware activity actually fell 27% year over year, healthcare activity dropped 24%, and education activity declined 17%. Fewer attacks against these sectors, in other words, but the attacks that did land were bigger and more damaging in terms of data volume. Quality over quantity, from the attacker’s point of view.

The Sector Breakdown: Fewer Attacks, Bigger Losses

Metric Figure Year-over-Year Change
Known ransom payment volume $327.8 million -15.8%
Recorded individual ransom payments — -20.1%
Average ransom payment $431,995 +5.3%
Government sector attack activity — -27%
Healthcare sector attack activity — -24%
Education sector attack activity — -17%
Utilities sector victim organizations 65 organizations +622% (small prior-year base of 10, excluded from formal comparison)

That utilities figure deserves a caveat the report itself includes: a jump from 10 to 65 victim organizations produces a startling percentage purely because the starting base was so small. ThreatLabz excluded it from the formal year-over-year comparison for that reason, and treating a 622% headline as proof that utilities attacks exploded sixfold would overstate the case. Still, 65 confirmed utility-sector victims in one year is a real number worth watching, particularly given how often utility breaches intersect with physical infrastructure risk.

Named Groups Behind the Biggest Single Claims

The report attaches specific numbers to three individual claims that illustrate how far the data-theft arms race has gone. Babuk2 claimed roughly 30 terabytes stolen from a government organization. INC Ransom claimed around 20 terabytes from a large healthcare organization. A group identified as Pear claimed about 16 terabytes from a U.S. university. None of the underlying reporting names the specific victim organizations, and these figures come from the groups’ own leak-site claims rather than independent forensic confirmation, a distinction worth keeping in mind since ransomware gangs routinely inflate numbers to maximize pressure.

Ransomware Group Victim Sector Claimed Data Volume
Babuk2 Government organization 30 TB
INC Ransom Large healthcare organization 20 TB
Pear U.S. university 16 TB

Even taken at face value as unverified claims, the combined 66 terabytes across just three incidents shows how a handful of large campaigns can move an entire industry-wide statistic. If three groups alone claim that much, the remaining volume behind the 896.2 TB total is spread across dozens of smaller but still significant thefts from the rest of the top-10 cohort.

Historical Context: How Ransomware Became a Data-Theft Business

This shift did not happen overnight. Ransomware spent most of the 2010s as a pure encryption play: lock the files, demand payment for the key, move on. That changed in late 2019 when the Maze ransomware group pioneered what the industry now calls double extortion, stealing data before encrypting it and threatening to publish the files if victims refused to pay, even if they could restore from backup. Maze’s model spread quickly because it solved the backup problem for attackers. A company with perfect backups could still be extorted over the threat of a public leak.

Six years later, the ThreatLabz numbers suggest double extortion has matured into something closer to data-theft-first extortion, where encryption is almost an afterthought and the real product criminals are selling back to victims is silence. That evolution tracks with what incident response firms have been saying anecdotally for the past two years: ransom notes increasingly skip encryption entirely in favor of a straight “pay or we publish” threat, particularly against organizations known to have strong backup discipline.

How This Compares to Other Ransomware Trackers

Zscaler is not the only firm tracking ransomware economics, and its data-volume focus sets it apart from competitors that center on payment statistics instead. Coveware, a ransomware incident response and negotiation firm, has published quarterly reports for years tracking median ransom demands, negotiation outcomes, and the declining share of victims who ultimately pay. Chainalysis approaches the same problem from the blockchain side, tracing ransomware-linked cryptocurrency flows to estimate total payment volume across the ecosystem. The FBI’s Internet Crime Complaint Center publishes its own annual tally of reported ransomware losses, though its figures are widely understood to undercount the real total since many victims never file a complaint.

What makes the ThreatLabz report distinct is its emphasis on stolen-data volume as the primary metric rather than payment dollars. That is a meaningful methodological choice: it captures the growing data-theft-first strategy that payment-only trackers can miss entirely, since a victim who refuses to pay still shows up as zero dollars in a payment-focused report even if the attacker walked away with terabytes of sensitive files. Security teams benchmarking their own risk exposure should treat these reports as complementary rather than redundant, since they are measuring different parts of the same crime.

What Rising Data Theft Means for Cyber Insurance and Breach Costs

A data-theft-first ransomware economy changes the cost calculus for cyber insurers, who have spent the last several years tightening policies specifically around ransomware payment coverage. If attackers increasingly profit from exfiltration and extortion rather than encryption and payment, insurers face a different exposure: notification costs, regulatory fines tied to the type of data exposed (health records, student data, government files), and class-action litigation risk, all of which can accumulate even when a ransom is never paid. Expect underwriters to push harder for proof of data loss prevention controls and network segmentation during policy renewals, since those controls address exfiltration risk directly in a way that ransomware-specific encryption coverage does not.

There is also a market signal here for security vendors. Data security posture management, data loss prevention, and exfiltration-detection tooling have all seen renewed enterprise interest over the past two years, and a 275.8% jump in confirmed data-theft volume is the kind of statistic that tends to show up in vendor sales decks for the next several quarters. Whether that interest translates into faster adoption inside under-resourced sectors like education and local government, the two groups least equipped to buy new tooling, is a separate and harder question.

Spotting Data Exfiltration Before the Leak Site Posts It

Because so much of the current ransomware playbook now hinges on moving large volumes of data out of a network before the victim even notices, incident responders increasingly focus on exfiltration indicators rather than waiting for an encryption event to trigger an alert. Common red flags include unusual outbound traffic volume to unfamiliar cloud storage endpoints, spikes in archive-utility usage across file servers, and the use of legitimate sync tools in ways that do not match normal business patterns.

# Example indicators worth hunting for in logs
# (illustrative pattern, not tied to a specific vendor or incident)
grep -E "rclone|megasync|mc.exe|aws s3 cp" security_events.log
netstat -an | grep ESTABLISHED | sort | uniq -c | sort -rn | head -20
# Large, sustained outbound transfers to a single new external IP
# in a short window are the classic staging-and-exfiltration pattern

None of this is exotic tradecraft. It is the same exfiltration pattern incident responders have documented for years, but the ThreatLabz numbers suggest defenders are catching it less often than the volume of stolen data would imply they should be.

What Security Teams Should Take From This Report

For CISOs, the practical takeaway is that backup strategy alone no longer constitutes ransomware resilience. A company that can restore every system within hours still faces the full extortion threat if attackers walked out the door with sensitive files first. That means data loss prevention, network segmentation to limit how much an attacker can reach from a single compromised account, and outbound traffic monitoring now matter as much as backup cadence. The National Institute of Standards and Technology and the UK’s National Cyber Security Centre have both published guidance emphasizing segmentation and least-privilege access as core defenses against the lateral movement that makes large-scale exfiltration possible in the first place.

Sector-specific guidance matters too. Schools and hospitals, the two groups absorbing some of the largest individual claims in this report, typically operate with flat or shrinking IT security budgets relative to the data they hold. Industry groups like the Center for Internet Security offer free or low-cost benchmarks specifically aimed at under-resourced public sector organizations, which is often the more realistic starting point than enterprise-grade tooling these institutions cannot afford.

Five Predictions for Ransomware Data Theft Through 2027

Based on the trajectory in this report and the broader direction ransomware groups have taken since the Maze era, a few predictions seem reasonable heading into 2027.

  • Data-theft volume will keep climbing even if ransom payment totals stay flat or fall further, since exfiltration has become the primary leverage point rather than a supplement to encryption.
  • More ransomware groups will drop encryption entirely in favor of extortion-only attacks, since encryption increasingly triggers faster incident response while data theft can go undetected for weeks.
  • Utilities and critical infrastructure victim counts will keep rising off a historically low base, drawing closer regulatory attention given the physical-world stakes of a successful attack.
  • Cyber insurers will increasingly price policies around proof of segmentation and exfiltration monitoring rather than backup quality alone, changing what “ransomware ready” means for an audit.
  • Average ransom payments will keep climbing even as total payment counts fall, reinforcing the big-game-hunting pattern where fewer, better-resourced victims account for a larger share of total criminal revenue.

The Bigger Picture: A Shift From Extortion to Data Monetization

The numbers in this report point toward a ransomware economy that is slowly decoupling from the word “ransom” altogether. When data theft outpaces payment volume by this much, the stolen files themselves start to carry independent value, sellable to other criminal groups, usable for follow-on phishing and identity fraud, or simply useful as leverage in future extortion attempts even after the original ransom demand has been resolved one way or another. That has implications well beyond the immediate victim, since a single breach involving a hospital or university can feed years of downstream fraud long after the headline incident fades from the news cycle. Security teams tracking the total cost of a breach increasingly need to account for that long tail, not just the immediate response bill.

Outlets covering the report, including The Record and BleepingComputer, have both tracked similar double-extortion trends across individual incidents throughout 2026, lending independent support to the broader pattern ThreatLabz describes even where specific dollar figures differ between trackers using different methodologies.

Frequently Asked Questions

What is the Zscaler ThreatLabz 2026 Ransomware Report?
It is an annual threat intelligence report from Zscaler’s ThreatLabz research team that tracks ransomware activity, including data volumes stolen and published by the top 10 most active ransomware groups, based largely on monitoring public leak sites.

How much did ransomware data theft increase in 2026?
According to the report, data stolen by the top 10 ransomware groups rose 275.8% year over year, from 123.8 terabytes in the prior reporting period to 896.2 terabytes in the window spanning April 2025 through March 2026.

Are ransom payments going up or down in 2026?
Both, depending on which figure you look at. Total known payment volume fell 15.8% year over year to $327.8 million and the number of recorded individual payments dropped 20.1%, but the average individual payment rose 5.3% to $431,995.

Which sectors were hit hardest by ransomware data theft?
Schools, hospitals, and government agencies were tied to some of the largest individual data-theft claims in the report, even though overall attack frequency against government, healthcare, and education sectors actually declined year over year.

Which ransomware groups claimed the largest data thefts?
The report cites Babuk2 claiming roughly 30 terabytes from a government organization, INC Ransom claiming around 20 terabytes from a large healthcare organization, and a group identified as Pear claiming about 16 terabytes from a U.S. university. These are the groups’ own claims and have not been independently verified victim by victim.

Why are ransomware groups stealing more data instead of just encrypting files?
Better backup and recovery practices have made pure encryption attacks less effective, since a victim who can restore systems quickly has less incentive to pay for a decryption key. Stolen data gives attackers continued leverage through the threat of public exposure, regardless of how fast a victim recovers its systems.

Is the utilities sector increase in attacks as dramatic as it sounds?
Not necessarily. The reported 622% increase to 65 victim organizations is measured against a prior-year base of just 10, which inflates the percentage. ThreatLabz itself excluded this figure from its formal year-over-year comparisons because of the small starting base.

What should organizations do differently given this data-theft trend?
Security teams should treat exfiltration monitoring, network segmentation, and data loss prevention as equally important to backup strategy, since a strong backup posture no longer removes the extortion risk tied to stolen data being published.

{
“@context”: “https://schema.org”,
“@type”: “NewsArticle”,
“headline”: “Ransomware Data Theft Surges 275% in 2026 Report”,
“datePublished”: “2026-10-07 04:31:00”,
“image”: “https://shattered.io/wp-content/uploads/2026/10/ransomware-data-theft-surge-275-percent-2026-1.webp”,
“author”: {
“@type”: “Organization”,
“name”: “Pune.Media Editorial Desk”,
“url”: “https://pune.media”
},
“publisher”: {
“@type”: “Organization”,
“name”: “Pune.Media”,
“logo”: {
“@type”: “ImageObject”,
“url”: “https://pune.media/wp-content/uploads/logo.png”
}
},
“isBasedOn”: “https://shattered.io/ransomware-data-theft-surge-275-percent-2026/”,
“mainEntityOfPage”: “https://shattered.io/ransomware-data-theft-surge-275-percent-2026/”,
“creativeWorkStatus”: “Editorial-assisted Curation”,
“comment”: {
“@type”: “Comment”,
“text”: “This article was curated, verified, and structured under organizational human editorial guidelines by the Pune.Media Editorial Desk.”
}
}