Zscaler Blog
Get the latest Zscaler blog updates in your inbox
Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims
Data exfiltrated by leading ransomware groups jumped 275.8% year over year to 896.2 terabytes, according to the Zscaler ThreatLabz 2026 Ransomware Report. That is more than seven times the volume recorded during the 2023–2024 reporting period. As organizations move more sensitive information through modern digital operations, and increasingly through AI-enabled systems, attackers have more high-value targets to steal and more ways to pressure victims once they do.
Government, education, and healthcare organizations were among the largest individual data theft incidents observed during the reporting period. Below, we break down what ThreatLabz observed across each sector, including a notable surge in attacks on utilities, and why these industries continue to attract ransomware campaigns. For the full view across industries and threat groups, download the Zscaler ThreatLabz 2026 Ransomware Report.
How initial access is changing
Many ransomware groups are shifting away from relying solely on malware delivery. ThreatLabz uncovered an initial access broker targeting employees who held manager positions primarily in non-technical departments such as accounting/finance, sales, operations, HR, and marketing, where a single compromised identity can open doors to sensitive data and essential services. Playbooks like spam bombing, IT-themed Microsoft Teams vishing, and abuse of legitimate support tools help adversaries gain a foothold quickly.
Generative AI is making these playbooks easier to execute. ThreatLabz observed AI accelerating everything from reconnaissance and social engineering to malware development, including a surge in new malware families where tooling appeared to have been created with GenAI assistance.
Some of the largest data theft claims involved government, education, and healthcare
Based on activity visible on ransomware leak sites, organizations in these sectors were tied to some of the largest data theft incidents observed during this reporting period.
Government. Ransomware attacks targeting government organizations declined 27% year over year, and the sector ranked ninth overall. Despite the decrease, government organizations were tied to the largest data theft claim in the ThreatLabz dataset: Babuk2 claimed to have stolen 30 TB of data from a government organization.
Healthcare. Healthcare ransomware activity declined 24% year over year, but the sector remained one of the most targeted industries overall, ranking fourth. INC Ransom claimed to have stolen 20 TB of data from a large healthcare organization, one of the largest claims in the dataset. In a separate incident, attackers used spam bombing and IT-themed impersonation to gain initial access, then pursued extortion without encrypting systems. The victim paid a $2 million ransom even though files were never encrypted.
Education. Ransomware activity targeting education declined 17% year over year, with the sector ranking eleventh. Pear, a relatively new ransomware group, claimed to have stolen 16 TB of data from a U.S. university. ShinyHunters, first observed in 2025, also drew attention for an extortion campaign targeting the education sector.
Utilities. While utilities had too few victims (10) in the prior year to include in the formal year-over-year comparison, the sector rose sharply by 622% to 65 victim organizations. As the Ransomware Report notes, ransomware attacks on sectors that support essential services carry implications beyond their absolute victim counts, with ripple effects through supply chains and dependent operations.
While overall attack volume against government, healthcare, and education decreased year over year, the scale of individual data theft incidents grew. The campaigns are fewer. The damage per campaign is larger.
Why these sectors attract ransomware campaigns
These sectors share characteristics that make them effective extortion targets:
- Compliance pressure is built in. ThreatLabz found that during ransom negotiations, threat actors often cite regulatory requirements, including HIPAA, SEC disclosure rules, and GDPR, directly to intensify pressure on victims. This tactic applies across industries, but for highly regulated sectors like government and healthcare, the stakes are especially acute. The theft of protected records can itself constitute a regulatory breach, meaning compliance and legal consequences are already locked in regardless of whether the ransom is paid to prevent public exposure.
- Trust is a currency. For government agencies, healthcare providers, schools, and utilities, a breach can become a community-wide event, not just an IT issue.
- Downtime carries outsized consequences. Essential services create urgency and have limited tolerance for prolonged disruption.
How to strengthen ransomware defenses
The scale and sophistication of ransomware threats in 2026 demand both immediate and strategic action:
Adopt a zero trust architecture. Remove implicit trust and enforce least-privilege access across users, devices, and workloads. Connecting users to specific applications rather than placing them on the network limits what a compromised identity can reach and prevents the lateral movement that leads to large-scale data theft.
Inspect encrypted traffic. Real-time TLS/SSL inspection is critical because payload delivery and C2 traffic are often hidden inside encrypted flows.
Treat data as the primary target. The incidents in this report show that data exfiltration, not encryption, is driving extortion. Use inline DLP controls and plan for exfiltration scenarios with clear incident response playbooks.
Fight AI with AI. Apply AI-powered tools to identify patterns, detect anomalies, and accelerate response, especially as attackers use GenAI to scale social engineering and develop new tooling.
See our full ransomware prevention guidance and best practices in the report.
The ThreatLabz 2026 Ransomware Report offers deeper analysis of ransomware trends, attacker tactics, and victim data across all industries, along with detailed guidance on how a zero trust architecture mitigates ransomware risk. Download the full report here.
Was this post useful?
Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.
Get the latest Zscaler blog updates in your inbox
By submitting the form, you are agreeing to our privacy policy.



