New Zscaler ThreatLabz 2026 Ransomware Report finds attackers stole nearly 900 terabytes of data, increasingly targeted employees with privileged roles, and used GenAI to accelerate operations
SAN JOSE, Calif., Sept. 30, 2026 (GLOBE NEWSWIRE) -- Zscaler, Inc. (NASDAQ: ZS), the cybersecurity platform for the AI era, today released new findings from the Zscaler ThreatLabz 2026 Ransomware Report, showing that ransomware is on the rise, and is being aided by AI, increasing by more than 275% since last year, while costing companies more than $328 million in payments to hacking groups. Zscaler’s research revealed that nearly 900 terabytes of data – the equivalent to 90 times the print collection at the Library of Congress – were stolen over the course of a year. The AI-driven increase in ransomware is targeting nearly two-thirds of senior-level executives, and threat actors are increasingly using trusted workplace tools, including Microsoft Teams, to enable data theft and lateral movement within an organization’s environment.
Key findings from the ThreatLabz 2026 Ransomware Report reveal:
"Successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging data theft attacks," said Deepen Desai, Executive Vice President of Cybersecurity at Zscaler. "They are using GenAI to speed up operations, and focusing on stealing more of an organization’s intellectual property, customer information, and other sensitive data to drive payment. Security teams need to stop these attacks early by reducing initial access opportunities, limiting lateral movement, and preventing data exfiltration."
Additional findings in the Zscaler ThreatLabz 2026 Ransomware Report include:
The Zscaler ThreatLabz 2026 Ransomware Report provides guidance on how to disrupt ransomware across the attack lifecycle and examines the current threat landscape in depth, including exfiltration trends, victim targeting, evolving attacker tradecraft, and extortion economics.
To learn more, read the full report here: https://www.zscaler.com/campaign/threatlabz-ransomware-report
Methodology
The report is based on Zscaler telemetry and ThreatLabz analysis and examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns. Together, the findings show a threat landscape where attackers are increasing leverage through stolen data, targeting business-influential employees, and improving operational efficiency with AI-assisted tooling and abuse of legitimate enterprise platforms.
About Zscaler
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™ ️platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 200+ public data centers globally and thousands of private sites at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
Media Contact
Nick Gonzalez, Director of Global Public Relations, press@zscaler.com

| 7 hours | |
| 7 hours | |
| 16 hours | |
| Sep-29 | |
| Sep-28 | |
| Sep-28 | |
| Sep-28 | |
| Sep-25 |
Zscaler Falls Amid Executive Change As Cybersecurity Stocks Pull Back
ZS -10.06%
Investor's Business Daily
|
| Sep-25 | |
| Sep-25 | |
| Sep-25 | |
| Sep-25 | |
| Sep-25 | |
| Sep-24 | |
| Sep-24 |
Join thousands of traders who make more informed decisions with our premium features. Real-time quotes, advanced visualizations, alerts, and much more.
Learn more about Finviz Elite