ThreatLabz Report: Ransomware Data Theft Surges as Attackers Target High-Impact Employees

Summary
ThreatLabz reports a 275.8% year-over-year rise in data stolen by leading ransomware groups, alongside shifting group rankings and attacks targeting business users through collaboration and remote-support tools.
Key points
- The top 10 ransomware groups by reported leak volume exfiltrated 896.2 TB, up 275.8% year over year and more than seven times the 123.8 TB reported for 2023–2024.
- Among victims studied, 62% held manager-level roles or higher, and roughly 75% worked in finance, sales, operations, HR, or marketing.
- Reported initial-access tactics include spam bombing and Microsoft Teams vishing, followed by steering victims to legitimate remote-support tools such as Quick Assist; attackers then conduct reconnaissance, persist, move laterally, steal data, and encrypt.
- Leak sites listed 7,366 victims, down 3% year over year. Sixty percent of the top 15 groups by victim volume were new to the rankings, and ThreatLabz identified 52 newly active groups.
- Known ransomware payments fell 15.8% to $327.8 million and recorded payment counts fell 20.1%, while the average payment rose 5.3% to $431,995.
- The report recommends securing collaboration and remote-support workflows and prioritizing early access disruption, lateral-movement prevention, rapid containment, and stopping data exfiltration.
Article Details
- Publisher
- ThreatLabz (Zscaler)
- Report Period
- 2026 report; precise reporting dates not disclosed
- Scope
- Ransomware data theft, targeting, initial access, leak-site activity, and payments
- Key Statistics
- Among the top 10 ransomware groups by reported data leak volume, combined exfiltration rose 275.8% year over year to 896.2 TB, compared with 123.8 TB in the 2023–2024 reporting period.
- ThreatLabz found that 62% of victims it examined held manager-level titles or above; the number examined was not disclosed.
- Roughly 75% of victims examined worked in finance, sales, operations, HR, or marketing; the number examined was not disclosed.
- Leak sites listed 7,366 victims, down 3% year over year. Of the top 15 groups by victim volume, 60% were new to the rankings, and ThreatLabz identified 52 newly active groups over the last year.
- Known payment volume fell 15.8% year over year to $327.8M, and recorded payments fell 20.1%, while the average payment rose 5.3% to $431,995.
- Recommendations
- Prioritize post-compromise containment to prevent lateral movement and stop data exfiltration quickly.
- Apply policy, visibility, and detection to collaboration and remote support workflows.
- Focus durable controls on attacker behaviors and tactics rather than group names.
- Disrupt initial access early and limit post-compromise opportunities for data theft.
MITRE ATT&CK
T1219 · Remote Access ToolsThreat actors steer victims toward legitimate remote support and remote access tooling, including Quick Assist.T1486 · Data Encrypted for ImpactThe report describes attackers deploying tooling that enables encryption during ransomware intrusions.T1566.004 · Spearphishing VoiceThe report describes Microsoft Teams vishing used to steer victims toward remote support tooling.
Vendors
Products
Microsoft TeamsThreat actors are increasingly combining spam bombing with Microsoft Teams vishing and then steering victims toward legitimate remote support and remote access tooling (such as Quick Assist and in some cases otherQuick Assistvishing and then steering victims toward legitimate remote support and remote access tooling (such as Quick Assist and in some cases other common remote support utilities). From there, attackers deploy tooling that