Zscalerのブログ

Zscalerの最新ブログ情報を受信

Security Research

Ransomware Leverage is Growing by the Terabyte: Takeaways from ThreatLabz 2026 Ransomware Report

Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in.

The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns.

The findings reinforce a clear reality for defenders: ransomware’s leverage is growing by the terabyte, while initial access is increasingly driven by repeatable playbooks that abuse trusted enterprise tools and trusted people. At the same time, the economics are shifting: total known ransom payments fell year over year, but the average payment increased, suggesting attackers are extracting more from the victims that do pay.

This blog highlights a subset of the most significant findings and implications for security teams. The full report provides deeper analysis of ransomware trends, case studies, and practical guidance to disrupt ransomware across the attack lifecycle.

5 key takeaways for security teams in 2026

Terabyte-scale data theft is now the center of gravity in ransomware
The biggest ransomware story this year isn’t a spike in victim counts, it’s the scale of data theft. Among the top 10 ransomware groups by reported data leak volume, combined exfiltration volume increased 275.8% year over year to 896.2 TB; more than seven times the volume recorded during the 2023–2024 reporting period (123.8 TB).

This is a clear leverage shift. When attackers can steal multiple terabytes from a single organization, extortion pressure grows even if the total number of victims stays relatively flat. For defenders, this raises the stakes on post-compromise containment: preventing lateral movement and stopping exfiltration quickly is now as critical as preventing encryption.

Ransomware threat actors are targeting employees with privileged roles and business influence
Ransomware groups are also now targeting “high-impact” business users, not just technical admins. And these intrusions are increasingly starting with something that looks routine: a support interaction, a Teams message, or an IT-themed request from a seemingly credible source. ThreatLabz uncovered that 62% of victims held manager-level titles or above, roles that often carry broad operational access and organizational trust.

Additionally, research shows that roughly 75% of victims worked in finance, sales, operations, HR, and marketing, functions tied to business-critical processes and high-value data. The takeaway is clear: the “high-risk user” profile often includes employees with influence, workflow access, and data proximity, not only those with explicit IT privilege.

Trusted enterprise tools are being turned into the initial access pathway
Threat actors are increasingly combining spam bombing with Microsoft Teams vishing and then steering victims toward legitimate remote support and remote access tooling (such as Quick Assist and in some cases other common remote support utilities). From there, attackers deploy tooling that enables reconnaissance, persistence, lateral movement, data theft, and encryption.

This technique succeeds because it blends into normal operations. Security teams should treat collaboration and remote support workflows as part of the ransomware attack surface, and apply policy, visibility, and detection accordingly.

Victim counts remain high, but the ransomware landscape is reshuffling fast
Publicly disclosed ransomware victim counts remained elevated: 7,366 victims were listed on leak sites, down only 3% year over year. But the groups driving that activity changed significantly: 60% of the top 15 groups by victim volume were new to the rankings, with ThreatLabz identifying 52 newly active groups over the last year.

Disruptions, shutdowns, and rebrands can change the names on leak sites while affiliates carry proven access techniques and tooling into new operations. Defenders need durable controls that focus on behaviors and tactics, not just group names.

Even with lower total payments, the cost of a successful extortion remains high
Known payment volume declined 15.8% year over year to $327.8M and the number of recorded payments fell 20.1%, but the average payment increased 5.3% to $431,995. The takeaway for defenders is the same: reducing the likelihood of any “paid incident” depends on disrupting initial access early and limiting post-compromise opportunities for data theft and other tactics that increase negotiating pressure.

How Zscaler helps disrupt ransomware across the attack lifecycle

Ransomware attacks succeed when adversaries can gain access, move laterally, and reach valuable data before they’re stopped. Many organizations still rely on legacy architectures such as VPNs, network-based access, and disconnected point products, which leave visibility gaps.

The Zscaler Zero Trust Exchange™ helps reduce those gaps with a cloud native, AI-powered zero trust architecture designed to stop ransomware at multiple stages:

Minimize the attack surface: Reduce exposed infrastructure and remove direct network access by connecting users to apps, limiting what attackers can discover and reach.

Prevent initial compromise: Stop threats before they reach users and devices with inline controls like TLS/SSL inspection, AI-powered detections, sandboxing, and browser isolation.

Eliminate lateral movement and contain attacks: Use segmentation and risk-based policies to restrict access and reduce blast radius when identities or devices are compromised.

Protect data from exfiltration and extortion: Apply inline DLP and SaaS controls to identify sensitive data and block unauthorized transfers—especially as data theft becomes the primary leverage mechanism.

Accelerate SOC response with Agentic SecOps: Correlate low-signal events into high-confidence incidents using zero trust telemetry and business context, then automate investigation and response workflows to contain threats faster.

Get the report—stay ahead of ransomware’s next evolution

The Zscaler ThreatLabz 2026 Ransomware Report provides a data-backed view into how ransomware operations are changing: where leverage is growing, how initial access is evolving, which groups are most active, and what defenders can do to disrupt attacks earlier in the lifecycle.

Download the full report to explore the data, case studies, and recommendations shaping the next phase of ransomware defense.

form submtited
お読みいただきありがとうございました

このブログは役に立ちましたか?

免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。

Zscalerの最新ブログ情報を受信

このフォームを送信することで、Zscalerのプライバシー ポリシーに同意したものとみなされます。