The latest Zscaler ThreatLabz findings point to a clear shift in how ransomware gangs make money. According to the ransomware data theft 2026 report, which covers activity observed between April 2025 and March 2026, the volume of data stolen in ransomware incidents rose by more than 275% year on year, reaching 896.2 terabytes. Encrypting files is no longer the whole story. Stealing them is where much of the leverage now sits.

This post walks through the headline numbers, explains why the shift matters, and outlines practical steps for individuals and small teams. Only the figures reported in the source coverage are cited here, and some details of the report were not available in the summary we reviewed.

What the Zscaler ThreatLabz numbers show

The report examines ransomware activity and extortion economics over a twelve-month window, from April 2025 to March 2026. Three figures stand out from the summary:

  • Data stolen: more than a 275% year-on-year increase, reaching 896.2 terabytes.
  • Tracked payments: blockchain transactions associated with ransomware payments reached $328 million.
  • Average ransom payment: the summary says it rose, though the exact figure was cut off in the text available to us.

The headline is the data volume. A jump of that scale suggests attackers are spending more effort on taking information out of victim networks, not just locking it in place. The $328 million figure reflects payments that could be traced on blockchains, so it should be read as what researchers could observe, not necessarily the full total of money changing hands.

Why stolen data, not encryption, is now the main leverage

Traditional ransomware worked on a simple premise: lock the files, demand payment for the key. Defenders responded with better backups. If you can restore your systems, the encryption threat loses much of its force.

Data theft changes that math. Even with perfect backups, a victim cannot "restore" information that has already been copied by criminals. The threat becomes publication or sale of customer records, employee files, financial documents, or internal emails. Backups do nothing to reverse that exposure.

That is why the reported growth in stolen data matters more than a simple count of attacks. It signals that extortion through data theft is becoming the central pressure tactic, and that recovery planning needs to cover confidentiality, not only availability.

The targets of these campaigns are also worth understanding. Our coverage of who ransomware gangs are actually targeting shows how attackers are choosing the people inside organizations they approach, which ties directly into how stolen access and data are obtained in the first place.

How AI is speeding up ransomware operations

The report's framing links AI-assisted attacks to the rise in data theft. The summary we reviewed does not spell out the specific techniques, so it would be a mistake to guess at details. What can be said in general terms is that automation helps attackers do more with less effort: sorting through large volumes of stolen files, finding valuable material faster, and scaling operations that once took more manual work.

The practical takeaway is about speed. If attackers can find and move sensitive data more quickly, the window between initial access and serious damage shrinks. Detection and response that once seemed fast enough may not be.

What This Means For You

For most readers, the reported trend means three things.

Backups are necessary but not sufficient. They protect you from losing access to your files. They do not protect you from your files being leaked.

A VPN does not solve this. A VPN encrypts your traffic between your device and the VPN server, which is useful on untrusted networks. Ransomware crews typically get in through other routes, such as compromised accounts, stolen credentials, or phishing. A VPN alone will not stop any of those, so treat it as one layer, not a defense against extortion.

Less stored data means less to steal. Data you no longer keep cannot be taken. This applies to individuals with old email archives and to small businesses holding years of customer records.

Practical steps for individuals and small teams

  • Secure your accounts. Use a password manager, unique passwords, and multi-factor authentication, preferably with an authenticator app or hardware key rather than SMS.
  • Keep offline or immutable backups. Test restoring from them so you know they work.
  • Patch promptly. Update operating systems, browsers, routers, and any remote-access tools.
  • Reduce what you store. Delete old files, archived mailboxes, and exports you no longer need, and encrypt sensitive data you must keep.
  • Limit access. Give people only the permissions they need, and remove accounts for former staff or contractors.
  • Be skeptical of urgent messages. Phishing remains a common path in, so verify unexpected requests through a separate channel.
  • Have a plan. Decide in advance who to call and what to do if you suspect a breach, including how to notify affected people.

Takeaways

The ransomware data theft 2026 report from Zscaler ThreatLabz describes an environment where stolen information, not locked files, drives the pressure on victims. With 896.2 TB taken and $328 million in traceable payments, the financial incentive for attackers is clear.

You cannot control what criminals do, but you can shrink your exposure. Start by reviewing what data you hold, checking that your backups actually restore, and tightening account security. To understand how attackers choose their victims, read our piece on ransomware gangs targeting mid-level managers, then take an hour this week to audit your own accounts and backups.