Zscaler said its ThreatLabz 2026 Ransomware Report found that ransomware data theft rose more than 275% year over year during an April 2025 through March 2026 review period, reaching 896.2 terabytes of exfiltrated data in the activity Zscaler analyzed. The finding arrives as a vendor research release rather than an audited industry accounting, and that distinction matters for anyone drawing conclusions about enterprise security spending or the wider cybersecurity group.
The scope is narrower than the headline figure suggests. Zscaler's methodology draws on its own network telemetry and internal ThreatLabz analysis, covering ransomware groups and affiliates, victim targeting, attack techniques, data theft and payment patterns. The 896.2 terabyte measure therefore describes what one vendor observed through its own sensors during a specific twelve month window. It is not a complete worldwide total for stolen data, and the report does not establish that identical coverage was applied in earlier years, which limits any attempt to build a longer trend line from the published figures.
Payment data carries its own wording discipline. Blockchain transactions associated with ransomware payments reached $328 million over the review period. That is a narrower measure than money transferred to criminal groups, a total of corporate losses, or a global estimate of ransomware damage. No methodology in the released material supports reading the figure as confirmed criminal proceeds or as the economic cost borne by victim organizations, so it should stay framed as transaction activity and nothing wider.
Zscaler also reported that the average ransom payment rose 5.3% year over year to $431,995. The two payment measures belong in separate categories: one tracks on chain transaction activity associated with ransomware, the other tracks the average payment recorded in cases Zscaler observed. Neither should be presented as an independently audited industry benchmark, since the released material does not disclose enough sampling detail to support that framing or to allow the two figures to be combined into a single loss estimate.
The victim profile is the quietest item on the list and the most useful for risk work. Manager level titles and above accounted for 62% of victims in attacks Zscaler observed, highlighting a focus on employees with privileged roles and business influence. The category includes managers, not only senior executives, and it describes the mix of victims rather than the share of all executives who were targeted across the economy. Zscaler's own earlier campaign work pointed the same direction.
Traditional encryption is losing its role as the visible event. Zscaler reported that 78% of ransomware attacks in its analysis involved data theft, up from 45% in 2024, and that extortion is shifting away from file encryption toward quieter theft of intellectual property, customer records and other sensitive material. The operational consequence is that outages, which usually trigger visible incident response, are a weaker signal that an attack is underway than they once were.
Zscaler describes generative AI as an accelerator rather than a proven cause. The report recorded a 340% increase in AI assisted attack techniques across its customer base, and threat actors are using AI generated phishing email and deepfake voice calls to defeat familiar security controls. The release attributes faster attacker operations to generative AI, but it does not separate that effect from changes in affiliate behaviour, extortion models, victim selection, tooling or the size of the observed threat set.
Industry exposure is shifting as well. Zscaler found that healthcare saw a 156% increase in ransomware attacks year over year and became the most targeted industry for the first time, while manufacturing and technology remained the most targeted overall. The fastest year over year growth appeared in freight and logistics, up 725%, and in utilities, up 622%, a pattern that points at operational technology and physical supply chains rather than office endpoints alone.
Geographically, the United States remained the top ransomware target, with US organizations accounting for 50.7% of observed activity, well ahead of Canada at 4.8%, Germany at 4.3% and the United Kingdom at 4.1%. The concentration matters for the security vendor revenue narrative, since most of the telemetry behind these findings comes from enterprises in those markets, and the report cannot be used to infer demand in regions it barely observes.
Response speed is the gap most security teams can act on. Zscaler reported that median time to detect a ransomware attack fell to 4.2 hours, while median time to contain it rose to 72 hours. Organizations that paid ransoms recovered only 65% of their data on average, and 15% recovered none at all, with the average cost of a ransomware attack including downtime, lost revenue and recovery reaching $5.2 million per incident.
The tradeable read is thematic rather than financial. ThreatLabz research is evidence about attacker behaviour, and it does not establish Zscaler revenue, bookings, customer demand, earnings or share price direction. It does support a directional view that data exfiltration control, identity and access management, and detection of misuse of legitimate collaboration tools are becoming larger parts of enterprise security budgets as extortion shifts away from visible encryption events.
The practical watch list is short. Track whether other vendors publish comparable telemetry for the same window, whether Zscaler repeats the study with a consistent enough methodology to compare runs, and whether the 896.2 terabyte figure moves as detection coverage broadens. Individual incidents, such as the disruption Scripps Health confirmed in May 2026, tend to move sector sentiment far more than annual research releases, which carry limited information value once the aggregates are already published.
Trading Insight
The tradable expression of this story is Zscaler as a proxy for enterprise security demand, not a forecast built on the report's numbers. Watch for follow on vendor telemetry covering the same April 2025 to March 2026 window, and read any move in ZS as sector sentiment rather than a reaction to a revenue change the report does not contain. A second large incident, of the kind Scripps Health confirmed in May 2026, matters more to near term positioning than the published aggregates.