Ransomware gangs are stealing more data than ever. Zscaler's ThreatLabz 2026 report shows a 275% spike in stolen data, with AI tools speeding up attacks and blockchain extortion payments hitting new records.
Attackers are no longer just locking up files. Zscaler's ThreatLabz 2026 Ransomware Report shows a 275% jump in stolen data over the past year. Criminals siphoned off 896.2 terabytes and pulled in $328 million through blockchain extortion. The old method of encrypting systems is fading. Now, the focus is on stealing huge amounts of data. AI is making this possible.
Ransomware used to mean downtime and locked files. That's changed. From April 2025 to March 2026, threat groups used generative AI to speed up every step. They aren't inventing new attacks. They're moving faster. AI helps them spot, reach, and grab sensitive data at a pace that was impossible last year.
AI supercharges cybercrime
ThreatLabz puts it plainly. Generative AI isn't replacing old ransomware tricks. It's making them faster and harder to stop. Attackers use AI to automate scouting, run phishing, and hide their moves inside normal business traffic. The result is a ransomware world that's more scattered, more aggressive, and tougher to defend.
Successful ransomware extortion is shifting away from file encryption that causes business disruption toward less visible but more damaging data theft, with GenAI used to speed operations.
In the last year, 52 new ransomware groups appeared. Nine of the top 15 by victim count are new. Attackers are misusing trusted tools like Microsoft Teams and Quick Assist for social engineering, moving inside networks, and stealing data. They're also writing custom tools in JavaScript, PowerShell, and Python to dodge security systems.
Who gets hit and why
People are now the main target. Managers and staff with special access make up 62% of victims. Manufacturing and tech still get hit the most. But freight and logistics saw a 725% jump in attacks. Utilities rose 622%. The United States alone had 7,366 victims listed on leak sites. That's just 3% less than last year.
Encryption still causes problems. But the real threat is stolen intellectual property, customer records, and sensitive files. Even companies with strong backups are at risk. Attackers threaten to leak or sell what they steal. The average ransom is now $431,995, up 5.3% from last year. Data theft is raising the stakes.
Defenders face new problems
AI is now part of daily business. That makes defense harder. Zscaler's 2026 AI Security Report found an 83% rise in enterprise AI use, covering over 3,400 apps. More AI means more ways for data to move-and more ways for attackers to get in. Companies must watch for breaches, strange data transfers, lateral moves, and misuse of identity access across huge digital networks.
Microsoft's Security Blog points to groups like Storm-3168 using agentic-driven cloud attacks. They exploit compromised service principals to move inside cloud systems. Storm-2570 uses cloud and file-transfer tools to pull out large amounts of data fast. Sometimes, there's no ransom note or clear evidence left behind. These moves make detection and response harder, especially as more companies use hybrid and multi-cloud setups. For technical advice, the Agenzia per la Cybersicurezza Nazionale keeps cloud security and incident response guidelines up to date in Italy.
Fragmented threats and Italy's challenge
The ransomware world is splitting apart. Dozens of new groups and shifting tactics force defenders to adapt fast. Attackers abuse workplace apps and scripting languages. Old security borders don't hold up. As shown in recent investigations, attackers switch tools and methods quickly. That makes it harder for companies and police to track or stop them.
Italy and the EU face real risks. Ransomware groups are going after sectors vital to infrastructure and the economy. There's an urgent need for joint defense, strong rules, and investment in AI-powered security. The ThreatLabz report is a warning. AI and ransomware are now joined. The threat is here and growing.
Zscaler's analysis is clear. Ransomware is no longer just about downtime or lost files. It's about massive data theft, AI as a weapon, and lost trust in digital systems. Companies that don't adapt-by tightening identity controls, tracking AI use, and breaking attacker workflows-could be next. The AI-powered ransomware era has arrived. Defenders are already behind.