ThreatLabz Report: Ransomware Data Theft Surges as Attackers Target High-Impact Employees

· Original article ↗

Summary

ThreatLabz reports a 275.8% year-over-year rise in data stolen by leading ransomware groups, alongside shifting group rankings and attacks targeting business users through collaboration and remote-support tools.

Key points

  • The top 10 ransomware groups by reported leak volume exfiltrated 896.2 TB, up 275.8% year over year and more than seven times the 123.8 TB reported for 2023–2024.
  • Among victims studied, 62% held manager-level roles or higher, and roughly 75% worked in finance, sales, operations, HR, or marketing.
  • Reported initial-access tactics include spam bombing and Microsoft Teams vishing, followed by steering victims to legitimate remote-support tools such as Quick Assist; attackers then conduct reconnaissance, persist, move laterally, steal data, and encrypt.
  • Leak sites listed 7,366 victims, down 3% year over year. Sixty percent of the top 15 groups by victim volume were new to the rankings, and ThreatLabz identified 52 newly active groups.
  • Known ransomware payments fell 15.8% to $327.8 million and recorded payment counts fell 20.1%, while the average payment rose 5.3% to $431,995.
  • The report recommends securing collaboration and remote-support workflows and prioritizing early access disruption, lateral-movement prevention, rapid containment, and stopping data exfiltration.

Article Details

Publisher
ThreatLabz (Zscaler)
Report Period
2026 report; precise reporting dates not disclosed
Scope
Ransomware data theft, targeting, initial access, leak-site activity, and payments
Key Statistics
  • Among the top 10 ransomware groups by reported data leak volume, combined exfiltration rose 275.8% year over year to 896.2 TB, compared with 123.8 TB in the 2023–2024 reporting period.
  • ThreatLabz found that 62% of victims it examined held manager-level titles or above; the number examined was not disclosed.
  • Roughly 75% of victims examined worked in finance, sales, operations, HR, or marketing; the number examined was not disclosed.
  • Leak sites listed 7,366 victims, down 3% year over year. Of the top 15 groups by victim volume, 60% were new to the rankings, and ThreatLabz identified 52 newly active groups over the last year.
  • Known payment volume fell 15.8% year over year to $327.8M, and recorded payments fell 20.1%, while the average payment rose 5.3% to $431,995.
Recommendations
  • Prioritize post-compromise containment to prevent lateral movement and stop data exfiltration quickly.
  • Apply policy, visibility, and detection to collaboration and remote support workflows.
  • Focus durable controls on attacker behaviors and tactics rather than group names.
  • Disrupt initial access early and limit post-compromise opportunities for data theft.

MITRE ATT&CK

Vendors

Products

Related Articles