Ransomware Data Theft Rose 275 Percent

The Zscaler report detailed a surge in digital extortion and data exfiltration from April 2025 through March 2026.

Updated on Oct. 5, 2026 in Cybersecurity

Isometric editorial illustration of a heavy shipping container with a glowing lattice of light inside, representing digital data theft.
Ransomware-related data theft surged by 275% between April 2025 and March 2026, with logistics and utility companies reporting record-high exfiltration of proprietary information. AI Illustration. Upload story photo >

Live Poll

Do you feel less secure about your personal or professional data due to recent cyberattacks?

Ransomware-related data theft increased by over 275% during the period between April 2025 and March 2026. Attackers successfully exfiltrated 896.2 terabytes of data while extorting millions from organizations globally.

Why it matters

The shift highlights a trend where cybercriminals increasingly target manager-level employees to gain network access. High-value sectors like logistics and utilities have seen explosive growth in targeted attacks during the past year.

Attackers primarily leveraged Microsoft Teams and Quick Assist as tools for social engineering and lateral network movement. The average ransom payment climbed 5.3% to reach $431,995.

The players

Zscaler

This is a cloud-based information security company that provides network and data protection services for global organizations.

Microsoft

This is a multinational technology corporation whose enterprise software tools were reportedly exploited by ransomware actors for social engineering.

The details

Criminal groups shifted their focus to individuals in manager-level roles, who accounted for 62% of victims. This strategy fueled massive sector-specific spikes, including a 725% increase in attacks on freight and logistics companies and 622% in the utility sector.

Timeline

  1. The Zscaler report analyzed data from April 2025 through March 2026.

The Tech Race

The transition toward targeting administrative personnel via collaboration tools represents a major shift away from legacy phishing attempts. This development forces security teams to adopt more rigorous identity verification processes to defend against modern social engineering tactics.

Employees with management titles should exercise heightened caution regarding unexpected support requests delivered via collaboration platforms like Microsoft Teams. Companies may face increased operational costs as they implement stricter security protocols to mitigate these risks.

The takeaway

Organizations should prioritize securing privileged accounts and training staff on social engineering risks to prevent unauthorized access. The rising costs of average ransom payments underline the financial necessity of robust, proactive data backups.

Further reading

For more information on the evolving threat landscape, visit the Cybersecurity section.

Source note: This article includes information reported by Security Today.

Live Poll

Do you feel less secure about your personal or professional data due to recent cyberattacks?