A new Zscaler report puts a number on something defenders have been watching for a while: ransomware gangs are stealing data at enormous scale. According to the findings, ransomware attackers exfiltrated 896.2 terabytes of data over a year, a 275.8% increase year on year. The research points to a shift in ransomware tactics away from disruption through encryption alone and towards the theft of large volumes of data for extortion.

This post looks at what the ransomware data theft trend means, why it changes the risk for ordinary people as well as companies, and which practical steps can limit your exposure.

What Zscaler Found About Ransomware Data Theft

The headline figure is the 896.2 TB of stolen data, which Zscaler reports as a 275.8% rise from the previous year. The coverage also notes that average ransom payments rose 5.3% from a year earlier to more than £327,000. The source summary adds that blockchain transactions linked to ransomware payments were also part of the findings, though the excerpt we have does not include further detail, so we will not speculate on those numbers.

The key point is the change in emphasis. Historically, ransomware meant locking files and demanding payment for a decryption key. If an organisation had good backups, it could often restore systems and refuse to pay. Stealing data changes that equation. Even when systems are restored, the attacker still holds copies of sensitive files and can threaten to publish them.

Why Attackers Are Moving From Encryption to Extortion

Data theft gives criminals leverage that backups cannot remove. A victim can rebuild a network, but it cannot un-leak customer records, employee files or internal emails. That pressure is what makes extortion effective.

Recent reporting on vpn.social shows the same pattern from different angles. The Clop-ShinyHunters feud revealed how data extortion groups compete and pressure victims. When Berlin rejected a Rhysida ransom demand after 5.79TB of data was stolen, the central issue was data being held over the victim, not locked systems. Another group, TITAN, has claimed it uses AI to scan 700GB of stolen data hourly, which, if accurate, would speed up how quickly stolen files are turned into pressure.

The more data a group takes, the more options it has: targeting individual employees, contacting customers, or selling information to others.

What This Means For You

You do not need to run a company to be affected. Large volumes of stolen data usually include personal information about customers, patients, staff and partners. If an organisation you deal with is breached, your details may be in that haul, regardless of how careful you are.

There is also a people angle. Zscaler has previously highlighted that ransomware victims are often managers, which shows attackers go after individuals with access and influence. Stolen data can help them craft convincing follow-up scams.

A VPN has a limited role here. It encrypts your traffic on untrusted networks and can help hide your activity from local observers, but it does not stop a company you trust from being breached. Treat it as one layer, not a fix for this problem.

How to Reduce Your Exposure

For individuals:

  • Share less data. Information a company never collects cannot be stolen from it. Skip optional fields and delete accounts you no longer use.
  • Use unique passwords and a password manager. Leaked credentials are often reused against other services.
  • Turn on multifactor authentication, preferably with an app or hardware key rather than SMS.
  • Encrypt sensitive files and devices so that stolen copies are harder to read.
  • Be wary of extortion messages. If you are contacted after a breach, verify through official channels and do not pay or reply to unsolicited demands.

For small businesses and teams:

  • Minimise retention. Delete data you no longer need, since old archives add to the size of a potential leak.
  • Segment your network so that one compromised account cannot reach everything.
  • Monitor outbound traffic. With exfiltration now central to attacks, unusual large transfers deserve attention, not just suspicious logins.
  • Keep offline, tested backups, but remember they address encryption, not theft.
  • Limit access by role, especially for executives and administrators.

Key Takeaways

The Zscaler findings show that ransomware is increasingly a data theft business: 896.2 TB stolen in a year, up 275.8%, with average ransom payments rising 5.3% to more than £327,000. Backups alone no longer solve the problem. The most reliable defences are collecting and keeping less data, encrypting what remains, segmenting networks, and watching for data leaving your systems. Start with one step today, such as deleting unused accounts or enabling multifactor authentication, and build from there to reduce the impact of the next ransomware data theft headline.