Ransomware attacks are increasingly centred on stealing sensitive information rather than simply encrypting files, with attackers also using generative AI and legitimate workplace software to improve their operations, according to Zscaler’s ThreatLabz 2026 Ransomware Report.

The report, released on September 30, analyses ransomware activity between April 2025 and March 2026 using Zscaler telemetry and ThreatLabz research. It found that 896.2 terabytes of data were exfiltrated during the period, representing an increase of more than 275% from the previous year. Blockchain transactions linked to ransomware payments totalled $328 million, while the average ransom payment increased 5.3% to $431,995.

The research also points to a greater focus on employees in positions with access and influence. People holding manager-level positions or above represented 62% of victims recorded in the attacks analysed by ThreatLabz. Attackers were also found to be using trusted enterprise applications, including Microsoft Teams and Quick Assist, for activities such as social engineering, lateral movement and data theft.

Manufacturing and technology remained the most targeted sectors. Freight and logistics recorded the fastest year-over-year increase in observed ransomware activity at 725%, followed by utilities at 622%. The United States accounted for 50.7% of observed activity, compared with 4.8% in Canada, 4.3% in Germany and 4.1% in the United Kingdom.

The report recorded 7,366 victims listed on ransomware leak sites, a 3% decline from the previous year. Qilin, Akira and INC Ransom together accounted for 34% of disclosed victims. ThreatLabz also identified 52 newly active ransomware groups, while nine of the 15 groups with the highest victim volumes were new to that ranking.

Zscaler said scripting languages such as JavaScript, PowerShell and Python are increasingly being incorporated into ransomware activity, allowing attackers to develop tooling faster and blend malicious activity with legitimate processes. The report also identifies the growing use of GenAI as a factor in speeding up attacker operations.
source:Zscaler 2026 Ransomware Report: GenAI & Massive Data Theft