Blog Zscaler

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Best Practices

From Access to Exfiltration: What Defenders Need to Know

image

For years, ransomware coverage has tended to focus on two numbers: How many victims were hit and how much they paid. The ThreatLabz 2026 Ransomware Report points to a more consequential shift happening beneath the usual headlines. Attackers aren’t just hitting more targets, they’re taking more from victims. The volume of data exfiltrated by the top ransomware groups surged 275.8% year over year to 896.2 terabytes. 

That scale of theft doesn't happen in a vacuum. It requires access, reconnaissance, lateral movement, and staging—a chain of activity that gives defenders a real window to intervene. The question is whether their controls are positioned to close it in time.

Terabyte Theft is the New Standard

It wasn’t long ago that attackers mostly targeted high-volume, low-storage textual and financial databases; the concept of a multi-terabyte breach was an outlier. Today it’s increasingly become the baseline of some of the most active ransomware groups.

The 896.2 terabytes exfiltrated by the top 10 ransomware groups between April 2025 and March 2026 represents more than seven times the volume recorded during the 2023-2024 reporting period. Groups including Rhysida and Embargo aren’t just posting large numbers in aggregate, both had average and median exfiltration volumes of at least one terabyte per victims, meaning outsized individual leaks aren’t distorting the picture. High-volume theft is a consistent feature of how they operate. Rhysida underscored this in April 2026 by ransoming roughly 10 terabytes from a single victim.

The reason this scale of theft works as leverage is straightforward. The more sensitive and operationally important the stolen data, the greater potential business, reputational, and legal exposure. Ransomware operators know this: During negotiations, groups routinely cite HIPAA, SEC disclosure requirements, and GDPR to intensify pressure on victims. In some cases, the threat of public exposure is the entire extortion strategy: ThreatLabz identified a healthcare organization that paid $2 million in ransom solely to prevent stolen data from appearing on a leak site. No encryption ever occurred.

More data stolen means more leverage, and for defenders, more at stake if an attacker makes it to the exfiltration stage.

The Path In: Trusted Tools, Targeted People

Understanding how attackers get in and who they target first matters because it shapes how quickly they can reach the data worth stealing.

This year’s report documents a repeatable initial access playbook that ransomware operators and their affiliated brokers have refined over the past two years. It starts with spam bombing: flooding a target’s inbox with a high volume of legitimate-looking marketing emails. That chaos sets the stage for a follow-on call through Microsoft Teams, where the attacker impersonates IT help desk staff from a fraudulent Microsoft 365 tenant. With the victim already confused and frustrated by the inbox flood, the “IT support” outreach feels credible. From there, the attacker persuades the victim to grant remote access through tools like Microsoft Quick Assist, AnyDesk, or TeamViewer, and the foothold is established.

What’s notable is who gets targeted first. An analysis of 351 victims linked to a prominent ransomware campaign found that 62% held manager-level titles or above. More than three quarters worked in finance, sales, operations, HR, or marketing, functions with broad access to the kind of information organizations can’t afford to have exposed, including: payment records, contracts, customer data, employee files, and operational systems. These aren’t the most technically privileged accounts in the organization, but they carry something equally valuable: trust. A message or request that looks like it comes from a manager carries inherent credibility, creating downstream opportunities for attackers to extend their reach.

Generative AI is also making target selection and social engineering sharper. Attackers can use it to identify high-value employees faster, personalize lures more convincingly, and generate functional malware code and script variants with less manual effort. For instance, ThreatLabz observed likely AI-assisted tooling in a campaign by Payouts King, a group that emerged in mid-2025 with tradecraft tied to former Black Basta affiliates, in which multiple functional iterations of a malicious batch script appeared to have been generated programmatically.

Speed Favors the Attacker

Once inside, attackers move quickly. In incidents linked to Payouts King, ThreatLabz observed data being staged and exfiltrated over Secure File Transfer Protocol (SFTP) within hours of initial access. After establishing a foothold via Quick Assist, the threat actor deployed remote monitoring and management (RMM) tools including ScreenConnect, SuperOps, and JumpCloud, moved laterally using built-in Windows features, and abused Active Directory through shadow credentials to maintain persistent access, all before any file encryption took place.

That sequencing has an important implication for defenders: encryption isn't the name of the game for every threat actor. By the time files are locked, the data is already gone. Controls that focus primarily on detecting or recovering from encryption (traditional antivirus, backup and restore procedures) don’t reduce exfiltration impact. The leverage is already in the attacker’s hands.

These compressed timelines call for a different way of thinking about risk. Time-to-exfiltration should be a key risk indicator for security teams, not just an incident debrief metric. The window between initial access and meaningful data loss may be measured in hours. That means detection and response capabilities need to be operating well before the attacker reaches the staging phase.

Close the Window: Controls that Match the Timeline

Reducing ransomware risk at the speed these attacks move requires controls positioned across the kill chain, not just at the end of it.

Shrink the Attack Surface Before Access is Gained

Zero trust network access replaces VPN-based remote access by hiding private applications from the public internet entirely, eliminating inbound exposure at the source. If attackers can't find or reach internal resources, there's no foothold to exploit. Breach prediction technology can also simulate likely attack paths before an incident occurs, giving security teams the ability to remediate proactively.

Stop Data From Leaving

Data loss prevention enforces inline controls across web, cloud, and email traffic, blocking unauthorized uploads to personal cloud storage, web file-sharing services, and unsanctioned SaaS destinations. CASB controls govern SaaS activity that ransomware actors specifically abuse, file sharing, bulk downloads, and lateral data movement within cloud applications.

Compress the Response Window

Managed detection and response combines zero trust telemetry with threat intelligence to surface exfiltration patterns that indicate an attack is underway. Deception technology adds another layer by luring attackers into monitored traps during the lateral movement phase, exposing their presence before data reaches staging. Agentic SOC capabilities help analysts prioritize and investigate at machine speed when those signals fire.

The Window is Real But it Won’t Wait

While the 275.8% surge in exfiltration volume is alarming, the report also shows that terabyte-scale theft requires time, access, and movement, a chain of attacker activity that defenders can disrupt at multiple points. The organizations that fare best aren’t necessarily the ones with the fastest incident response. They’re the ones that made the attacker’s job harder at every stage: harder to get in, harder to move laterally, harder to reach in and remove valuable data. 

Treat time-to-exfiltration as a risk metric. Measure it, monitor for it, and build controls that operate well before encryption is ever on the table. 

For a full analysis of the top ransomware groups, victimology data, payment trends, and technical case studies, download the ThreatLabz 2026 Ransomware Report.

form submtited
Grazie per aver letto

Questo post è stato utile?

Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Inviando il modulo, si accetta la nostra Informativa sulla privacy.