Ransomware Data Theft Jumped 275.8% to 896 TB—Defense Budgets Must Shift
Zscaler's ThreatLabz reports ransomware groups exfiltrated 896.2 TB of data in the past year, a 275.8% increase. Enterprise defense spending must move from endpoint blocking to identity controls and recovery validation.
Data exfiltration is the new encryption
The 10 largest ransomware groups exfiltrated 896.2 TB of data in the past year, a 275.8% increase, according to Zscaler's ThreatLabz 2026 Ransomware Report published September 30. Blockchain-tracked payments dropped 15.8% to $327.8 million, while the average payment rose 5.3% to $431,995. The gap between falling payment volume and rising theft volume means attackers are extracting more data per victim and relying less on encryption alone.
For enterprise buyers, this shift changes the procurement equation. Endpoint detection and encryption prevention are necessary but insufficient. Budgets must now cover identity protection, privileged-access controls, SaaS monitoring, and exfiltration detection—capabilities that prevent bulk data movement before encryption occurs.
Attackers are targeting managers and abusing collaboration tools
Employees at manager level and above represented 62% of victims in the ThreatLabz report. Attackers are also abusing trusted enterprise tools: Microsoft Teams and Quick Assist are now common vectors for social engineering, lateral movement, and data theft. This targeting pattern creates a procurement problem for buyers relying primarily on endpoint security. If an attacker can compromise a manager's identity or abuse a legitimate remote-support tool, file-based defenses become irrelevant.
The competitive field is shifting accordingly. Vendors measured only by endpoint blocking rates—such as traditional antivirus or standalone EDR—face pressure from platforms offering identity threat detection, zero-trust access, and SaaS-data controls. Zscaler's findings strengthen its case for zero-trust architecture, but buyers should also evaluate Palo Alto Networks Cortex XDR and Prisma Access, CrowdStrike Falcon, Microsoft Defender, Cisco security products, and Netskope. The question is no longer "Can you block the file?" but "Can you detect identity compromise and restrict lateral movement across collaboration tools?"
Industry exposure is expanding rapidly
Manufacturing and technology remain the most targeted sectors, but freight and logistics attacks grew 725% year over year, while utilities grew 622%. NCC Group recorded 1,073 publicly reported ransomware attacks in August 2026, approximately 12% above July's 960 attacks. The breadth of targeting argues against assuming your sector is low-priority. Procurement teams in previously less-targeted industries should expect to fund 24/7 monitoring, external attack-surface scanning, and pre-negotiated incident-response capacity.
The $431,995 average payment provides a direct financial benchmark. Compare that figure to the cost of identity protection, immutable backup, recovery testing, and an incident-response retainer. If prevention and recovery cost less than the expected payment—and avoid the operational downtime and data-breach notification costs—the procurement case is straightforward.
Recovery readiness is the weakest control
A September report from Fenix24, based on more than 500 ransomware recovery engagements involving over 800 clients, found that only 0.5% came close to their stated 24- to 48-hour recovery-time objectives. None reached full operational capacity for several weeks. Most critically, 99.2% lacked documented identity-recovery plans. Restoring files without restoring authentication and authorization systems does not restore business operations.
This finding expands the competitive field beyond endpoint security to recovery platforms and services. Rubrik, Cohesity, Commvault, Veeam, Dell, Druva, and specialist recovery providers such as Fenix24 all compete here. Backup vendors that can demonstrate immutable storage, clean-room recovery, identity restoration, and recovery orchestration have a stronger position than products offering backup capacity alone.
Buyers should treat recovery-time objectives as testable engineering requirements. Procurement should require evidence of recovery tests for identity systems, privileged accounts, domain services, SaaS applications, and critical databases. A vendor claiming 24-hour recovery without test data showing identity and application restoration is making an unverifiable assertion.
What to fund
Three budget priorities emerge from this data:
Identity and privilege controls. Manager-level and privileged users are disproportionately targeted, while identity recovery is missing from nearly all assessed recovery plans. Fund identity threat detection, privileged-access management, and identity-recovery procedures—not just endpoint licenses.
Data-exfiltration prevention. A 275.8% increase in stolen data means ransomware defenses must detect bulk data movement and abuse of legitimate collaboration and remote-support tools. Evaluate vendors on their ability to monitor SaaS applications, detect abnormal data flows, and block exfiltration through trusted channels.
Recovery validation. Demand measured recovery performance: time to restore identity, critical applications, and operational capacity. Reject backup-capacity claims or endpoint-detection statistics as substitutes for tested recovery procedures.
The available developments are primarily research and threat-intelligence findings rather than newly disclosed products with public pricing or independently verified efficacy benchmarks. Vendor claims about "AI-powered" protection should be evaluated against the more concrete measures emerging from these reports: exfiltration prevented, privileged identities protected, recovery objectives achieved, and restoration performance demonstrated. The 896.2 TB of stolen data and the 99.2% identity-recovery gap are the numbers that matter.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
