Ransomware Data Theft Rose 275 Percent Through 2026

A new report shows exfiltration volume and payment costs climbed significantly between April 2025 and March 2026.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration of a geometric monolith, representing the scale of digital data theft in cyber-security.
Ransomware-related data theft grew by 275 percent between April 2025 and March 2026, as criminal groups increasingly focused on high-value data exfiltration. AI Illustration. Upload story photo >

Live Poll

Do you feel less secure about your personal or professional data due to recent cyberattacks?

Between April 2025 and March 2026, ransomware data theft increased by more than 275%, with attackers exfiltrating 896.2 terabytes of data. This retrospective analysis of activity during that twelve-month period highlights a shift toward high-level targets and specific critical infrastructure sectors.

Why it matters

The surge in exfiltration volume indicates that threat actors are increasingly prioritizing the theft of sensitive data for leverage over simple service disruption. This trend was accompanied by a rise in both individual payment amounts and the number of active criminal groups.

The average ransomware payment rose 5.3% to $431,995 during the period, while total blockchain-based payments reached $328 million. Freight and logistics saw a 725% spike in attacks, while utilities experienced a 622% increase.

The players

Zscaler

A cloud-based security company providing zero-trust exchange platforms and threat intelligence services.

The details

Attackers utilized legitimate enterprise tools such as Microsoft Teams and Quick Assist—a built-in Windows application for remote desktop support—to facilitate social engineering and lateral movement within corporate networks. By targeting employees with manager-level titles or above, who accounted for 62% of victims, adversaries gained access to privileged systems and sensitive data. This strategy allowed groups to bypass standard perimeter defenses by compromising the credentials of high-ranking personnel directly.

Timeline

  1. April 2025 through March 2026: The period analyzed for the ransomware data activity report.

The Tech Race

The Zscaler ransomware report marks a significant escalation in observed criminal activity compared to historical baseline years. It highlights how the proliferation of 52 new ransomware groups has outpaced traditional defensive monitoring in key infrastructure sectors.

Organizations should prepare for heightened scrutiny of privileged accounts, as managers are now the primary targets for social engineering attacks. Security teams are advised to review remote assistance policies to prevent the misuse of tools like Quick Assist for initial network access.

The takeaway

The sharp rise in freight, logistics, and utility sector attacks suggests these industries have become primary targets for ransom leverage. Professionals should monitor upcoming annual cybersecurity reports for shifts in group behavior and the emergence of new, non-standard attack vectors.

Further reading

For broader trends in enterprise defense, explore our Cybersecurity section.

Source note: This article includes information reported by Security Today.

Live Poll

Do you feel less secure about your personal or professional data due to recent cyberattacks?