Blog Zscaler
Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta
Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims
Data exfiltrated by leading ransomware groups jumped 275.8% year over year to 896.2 terabytes, according to the Zscaler ThreatLabz 2026 Ransomware Report. That is more than seven times the volume recorded during the 2023–2024 reporting period. As organizations move more sensitive information through modern digital operations, and increasingly through AI-enabled systems, attackers have more high-value targets to steal and more ways to pressure victims once they do.
Government, education, and healthcare organizations were among the largest individual data theft incidents observed during the reporting period. Below, we break down what ThreatLabz observed across each sector, including a notable surge in attacks on utilities, and why these industries continue to attract ransomware campaigns. For the full view across industries and threat groups, download the Zscaler ThreatLabz 2026 Ransomware Report.
How initial access is changing
Many ransomware groups are shifting away from relying solely on malware delivery. ThreatLabz uncovered an initial access broker targeting employees who held manager positions primarily in non-technical departments such as accounting/finance, sales, operations, HR, and marketing, where a single compromised identity can open doors to sensitive data and essential services. Playbooks like spam bombing, IT-themed Microsoft Teams vishing, and abuse of legitimate support tools help adversaries gain a foothold quickly.
Generative AI is making these playbooks easier to execute. ThreatLabz observed AI accelerating everything from reconnaissance and social engineering to malware development, including a surge in new malware families where tooling appeared to have been created with GenAI assistance.
Some of the largest data theft claims involved government, education, and healthcare
Based on activity visible on ransomware leak sites, organizations in these sectors were tied to some of the largest data theft incidents observed during this reporting period.
Government. Ransomware attacks targeting government organizations declined 27% year over year, and the sector ranked ninth overall. Despite the decrease, government organizations were tied to the largest data theft claim in the ThreatLabz dataset: Babuk2 claimed to have stolen 30 TB of data from a government organization.
Healthcare. Healthcare ransomware activity declined 24% year over year, but the sector remained one of the most targeted industries overall, ranking fourth. INC Ransom claimed to have stolen 20 TB of data from a large healthcare organization, one of the largest claims in the dataset. In a separate incident, attackers used spam bombing and IT-themed impersonation to gain initial access, then pursued extortion without encrypting systems. The victim paid a $2 million ransom even though files were never encrypted.
Education. Ransomware activity targeting education declined 17% year over year, with the sector ranking eleventh. Pear, a relatively new ransomware group, claimed to have stolen 16 TB of data from a U.S. university. ShinyHunters, first observed in 2025, also drew attention for an extortion campaign targeting the education sector.
Utilities. While utilities had too few victims (10) in the prior year to include in the formal year-over-year comparison, the sector rose sharply by 622% to 65 victim organizations. As the Ransomware Report notes, ransomware attacks on sectors that support essential services carry implications beyond their absolute victim counts, with ripple effects through supply chains and dependent operations.
While overall attack volume against government, healthcare, and education decreased year over year, the scale of individual data theft incidents grew. The campaigns are fewer. The damage per campaign is larger.
Why these sectors attract ransomware campaigns
These sectors share characteristics that make them effective extortion targets:
- Compliance pressure is built in. ThreatLabz found that during ransom negotiations, threat actors often cite regulatory requirements, including HIPAA, SEC disclosure rules, and GDPR, directly to intensify pressure on victims. This tactic applies across industries, but for highly regulated sectors like government and healthcare, the stakes are especially acute. The theft of protected records can itself constitute a regulatory breach, meaning compliance and legal consequences are already locked in regardless of whether the ransom is paid to prevent public exposure.
- Trust is a currency. For government agencies, healthcare providers, schools, and utilities, a breach can become a community-wide event, not just an IT issue.
- Downtime carries outsized consequences. Essential services create urgency and have limited tolerance for prolonged disruption.
How to strengthen ransomware defenses
The scale and sophistication of ransomware threats in 2026 demand both immediate and strategic action:
Adopt a zero trust architecture. Remove implicit trust and enforce least-privilege access across users, devices, and workloads. Connecting users to specific applications rather than placing them on the network limits what a compromised identity can reach and prevents the lateral movement that leads to large-scale data theft.
Inspect encrypted traffic. Real-time TLS/SSL inspection is critical because payload delivery and C2 traffic are often hidden inside encrypted flows.
Treat data as the primary target. The incidents in this report show that data exfiltration, not encryption, is driving extortion. Use inline DLP controls and plan for exfiltration scenarios with clear incident response playbooks.
Fight AI with AI. Apply AI-powered tools to identify patterns, detect anomalies, and accelerate response, especially as attackers use GenAI to scale social engineering and develop new tooling.
See our full ransomware prevention guidance and best practices in the report.
The ThreatLabz 2026 Ransomware Report offers deeper analysis of ransomware trends, attacker tactics, and victim data across all industries, along with detailed guidance on how a zero trust architecture mitigates ransomware risk. Download the full report here.
Questo post è stato utile?
Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.
Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta
Inviando il modulo, si accetta la nostra Informativa sulla privacy.



