Zscaler: Ransomware Steals 896 TB, Targets Managers
ThreatLabz report shows 275.8% rise in exfiltrated data, with managers and executives making up 62% of individual victims. Logistics and utilities lead the surge.

Ransomware groups exfiltrated 896.2 terabytes of data from victims between April 2025 and March 2026, an increase of 275.8% compared to the previous twelve months, according to the annual report from ThreatLabz, Zscaler's research division, released on Wednesday (30). During the same period, the number of victims listed on leak sites decreased by only 3%, to 7,366. Fewer new targets, but much more data taken from each one.
"Successful ransomware extortion is shifting from file encryption, which often disrupts business, to less visible yet more damaging data theft attacks," said Deepen Desai, executive vice president of cybersecurity at Zscaler, in the statement.
Ransom Is No Longer About System Recovery
The average ransom payment rose by 5.3% to $431,995, according to the report. The modest increase in value contrasts sharply with the spike in stolen volume, indicating something about the crime's business model. When attackers encrypt servers, the victim pays to resume operations, and backups reduce the bargaining power. However, when attackers steal intellectual property and customer databases, no backup can undo the copy. Zscaler claims that gangs are utilizing generative AI to expedite various operational steps, such as screening stolen material, but the statement does not quantify this effect.
This shift has direct implications for security budgets. A decade of investment in immutable backups and disaster recovery plans protects against outages, not against exposure. Data loss prevention tools and outbound traffic monitoring, which many companies have deprioritized, are back in focus.
Managers in the Crosshairs
The most concerning data for C-level executives: professionals in manager roles or above accounted for 62% of identified individual victims in the attacks, according to ThreatLabz. Attackers target individuals with broad access, who approve payments and possess inboxes that hold significant value in negotiations. Industry and technology remained the most attacked sectors, but the greatest growth came from freight and logistics, up 725%, and utility providers, up 622%.
The surge in logistics and utilities coincides with sectors that have connected operational networks to corporate IT in recent years. At the end of September, South African ATNS, which manages air traffic for approximately 10% of the world's airspace, reported discovering malware associated with early stages of ransomware in an operational network for meteorological services, according to local press reports.
How Numbers Drop in Each Market
In the U.S., the SEC's incident disclosure rule, effective since December 2023, requires public companies to file a Form 8-K within four business days after determining that an incident is material. Data theft without operational disruption complicates this evaluation: without factory shutdowns, the board has fewer obvious indicators of materiality, increasing the pressure on the CISO and legal department to make quick decisions.
In Europe, the calculation changes due to GDPR, which imposes fines of up to 4% of global revenue, and NIS2, which requires notification to authorities within 24 hours. For a German logistics operator or an Italian energy distributor, the increases of 725% and 622% in their sectors weigh more heavily than the overall average.
In India, the Digital Personal Data Protection Act of 2023 mandates fines of up to 2.5 billion rupees for security failures. The country houses service centers processing data for American and European clients, and a breach there could trigger obligations across three jurisdictions simultaneously. In Brazil, LGPD limits fines to 2% of local revenue, capped at R$ 50 million per infraction, but the reputational damage for a bank or retailer with tens of millions of customers often exceeds the sanctions.
The Limits of the Portrait
The report has three caveats that a board should consider. First, it consists of telemetry from Zscaler combined with data from leak sites, and companies that pay ransoms quietly do not appear on these lists. Second, the period ends in March 2026, six months prior to publication. Third, Zscaler sells the traffic inspection and zero trust tools that the diagnosis recommends, which does not invalidate the numbers but suggests that they should be read alongside other sources, such as Chainalysis data on payments.
Despite these caveats, the overall direction is hard to dispute: the less visible the attack is in operations, the more it shows up on the balance sheet of those with data to lose.
Sources
- globenewswire.comhttps://www.globenewswire.com/news-release/2026/09/30/3371551/0/en/new-zscaler-report-reveals-ai-assisted-attackers-move-to-massive-data-theft-executive-targeting-and-millions-in-extortion-payments.html
- ir.zscaler.comhttps://ir.zscaler.com/news-releases/news-release-details/new-zscaler-report-reveals-ai-assisted-attackers-move-massive
- securitybrief.co.ukhttps://securitybrief.co.uk/story/ransomware-gangs-steal-896-terabytes-zscaler-says
- dig.watchhttps://dig.watch/updates/zscaler-threatlabz-2026-ransomware-report-275