Zscaler ThreatLabz published its 2026 ransomware report on 30 September 2026, covering April 2025 to March 2026. The headline figures are large and they are worth separating, because the report contains two numbers that move in opposite directions.

Attacks, as Zscaler counts them in its own cloud, rose by more than 275% against the previous year. 896.2 terabytes of data were stolen. Payments visible on the blockchain came to 328 million dollars, with the average payment at 431,995 dollars, up 5.3%.

And the count of victims named on leak sites fell 3%, to 7,366.

The two numbers are not in conflict

They are measuring different events.

The first is attempted attacks crossing a security vendor's own platform. It rises when activity rises, and it also rises when a vendor's coverage grows or its detections improve. It says nothing about whether any of those attempts succeeded.

The second is a public list that criminals maintain for their own purposes. A name appears on a leak site when extortion fails, not when it succeeds — a victim who pays quietly is a victim nobody counts. It also shifts with how the groups behave: a crew that negotiates privately, or one that has been disrupted, publishes fewer names without attacking fewer people.

Read together, the pair is still useful. More attempts and fewer publications is consistent with extortion moving away from the shame-list model, and it is consistent with more victims paying before anything is posted. The report does not resolve which, and neither should a headline that quotes only one of the two.

Where it is landing

Manufacturing and technology are the most targeted sectors in the data. The fastest growth is elsewhere: freight and logistics up 725%, and utilities up 622%.

Both of those are businesses where the cost of being stopped is measured in hours. A container terminal that cannot allocate slots and a utility that cannot run its billing and control systems are under a different kind of pressure from an office that cannot reach its file server, and the people choosing targets know it.

By country, the United States accounts for 50.7% of observed activity, ahead of Canada at 4.8%, Germany at 4.3% and the United Kingdom at 4.1%.

The target is increasingly a person

The report's finding on who gets attacked is the one most likely to change a security programme. Manager-level titles and above account for 62% of victims, and Zscaler says nearly two-thirds of senior executives were targeted.

That is a shift in method rather than in malware. Executive assistants, finance approvers and senior managers hold the approvals that make an intrusion profitable in a single step, and they are also the people most likely to be helped quickly by an IT department over a chat message. The report describes exactly that: Microsoft Teams and Quick Assist abused for social engineering and lateral movement, with generative AI used to make the approach faster to produce.

The crews

Three groups — Qilin, Akira and INC Ransom — account for 34% of disclosed victims. Zscaler counts 52 newly active groups over the year.

Both numbers matter at once. A third of the published victims belong to three brands, which makes a defender's reading list short. But fifty-two new entrants in twelve months is a market with low barriers, where tooling and affiliates move between names faster than defenders can learn them.

What to do

  • Treat the 275% and the 7,366 as separate measurements when you quote them internally. One is attempted activity on a vendor's platform; the other is what criminals published.
  • Rehearse the approval paths used by managers and above, not only the technical controls. The report's victim profile is senior staff, and the route in is a help request that looks routine.
  • Restrict remote-assistance tooling. Quick Assist and similar should be a deliberate capability with logging, not a default one.
  • If you are in freight, logistics or utilities, assume you are in the growth column and plan for the operational outage, not only the data loss.

What is not established

  • What exactly counts as an attack in the 275% figure. It is vendor telemetry, with the vendor's own definition and coverage behind it.
  • How much of the payment total is missed. The 328 million dollars is what is traceable on the blockchain, which is a floor and not a total.
  • Whether the 3% fall in named victims reflects fewer successful attacks, more quiet payments, or a change in how the groups publish.
  • Whether the executive-targeting share reflects attacker preference or the sectors where Zscaler has most visibility.