Zscaler ThreatLabz is warning that ransomware risk is shifting from “can we restore encrypted files?” to “can we stop data leaving the network in the first place?” That distinction matters for small businesses, public-sector suppliers, and government contractors because modern extortion campaigns often gain leverage before encryption ever starts.

In reporting tied to its 2026 ransomware research, Zscaler said the top ransomware groups exfiltrated 896.2 terabytes of data between April 2025 and March 2026, a 275.8% year-over-year increase. The data-theft scale is the story. Attackers are not just hitting victims; they are taking more from each one and using regulatory, operational, and reputational pressure as the ransom multiplier.

The most useful takeaway for defenders is operational: ransomware response cannot wait for file encryption. If the first high-confidence alert is a ransom note, the organization may already be negotiating over stolen data.

What Zscaler reported

Zscaler’s reporting highlights several connected trends:

  • Data theft volume jumped sharply. ThreatLabz reported 896.2 TB exfiltrated by the top ransomware groups during the reporting period, up 275.8% year over year.
  • Large single-victim theft claims are becoming normal. The research notes major claimed theft volumes affecting government, healthcare, and education organizations, including multi-terabyte incidents.
  • Utilities moved in the wrong direction. Zscaler reported utilities rising from 10 victim organizations in the prior year to 65, a 622% increase in the dataset.
  • Extortion may happen without encryption. In one healthcare case cited by Zscaler, attackers reportedly pursued extortion after data theft even though files were never encrypted.
  • Initial access is often social and tool-based. The reporting describes spam bombing, fraudulent Microsoft Teams outreach, IT-helpdesk impersonation, Quick Assist, AnyDesk, TeamViewer, and other trusted remote-access paths.

This lines up with what defenders keep seeing across ransomware and intrusion cases: attackers increasingly abuse legitimate administration channels, trusted identities, cloud storage, remote access tools, and encrypted outbound protocols. That makes the problem less about one malware family and more about whether the environment can detect abnormal access, staging, and outbound transfer quickly enough.

Why this matters for SMBs and government contractors

Smaller organizations often prepare for ransomware by focusing on backups. Backups are still mandatory, but they do not solve the extortion problem when contracts, personnel records, customer data, export-controlled information, regulated data, or CUI-adjacent material has already been copied out.

For government contractors, the risk is bigger than downtime. A data-theft incident can trigger customer notification obligations, contract reporting requirements, cyber-insurance scrutiny, legal review, and uncomfortable questions about access control, logging, and incident response maturity. Even when the victim is not a prime contractor, exposed business systems can create downstream risk for customers and partners.

The sectors called out in Zscaler’s reporting also matter. Government, healthcare, education, and utilities carry data and operational dependencies that make extortion pressure stronger. Attackers understand that. They know which records create regulatory pain, which systems interrupt public services, and which relationships create reputational leverage.

The defensive priority: shorten time-to-exfiltration detection

The practical metric is not just mean time to detect ransomware. It is how quickly the organization can detect the steps before data leaves:

  • Inbox flooding or coordinated spam bursts followed by “IT support” contact
  • Unexpected Teams, phone, or helpdesk interactions asking users to launch remote support tools
  • New or unusual RMM tools such as ScreenConnect, AnyDesk, TeamViewer, Quick Assist, SuperOps, or similar utilities
  • Mass file discovery, archive creation, compression, staging folders, or unusual file-access patterns
  • Outbound SFTP, cloud-storage, tunneling, or large encrypted transfers from endpoints and servers that do not normally move bulk data
  • Privilege changes, shadow credentials, new service accounts, or abnormal Active Directory modifications after a helpdesk-themed event

If those signals are not visible, the organization may still have endpoint tools and backups, but it lacks the telemetry needed to interrupt extortion before leverage is created.

Controls that match the attack timeline

Defenders do not need a perfect enterprise security stack to improve this. They need controls placed earlier in the chain.

  • Restrict remote support tools. Maintain an approved RMM list, block unsanctioned tools where possible, and alert on first-seen remote-access binaries.
  • Harden helpdesk workflows. Train users that real IT support will not ask them to accept unexpected Teams calls or install remote tools after an email flood. Give them a fast internal verification path.
  • Watch for spam-bombing sequences. A sudden inbox flood followed by support contact should be treated as a social-engineering indicator, not just email noise.
  • Baseline outbound data movement. Identify which systems legitimately use SFTP, cloud sync, external object storage, or large encrypted transfers. Alert on deviations.
  • Monitor staging behavior. Look for mass compression, archive splitting, temp-directory staging, and unusual access to file shares by non-IT users.
  • Segment sensitive repositories. Contracts, HR files, finance exports, engineering data, and regulated records should not all be reachable from a single compromised workstation.
  • Test incident response before encryption. Run tabletop scenarios where the first evidence is RMM installation and outbound data transfer, not locked files.

Incident response checklist

If a ransomware intrusion is suspected but encryption has not occurred, move quickly and preserve evidence.

  1. Identify the initial access path. Check for spam bombing, Teams/vishing contact, remote support sessions, VPN events, exposed appliances, or stolen credentials.
  2. Contain remote-access tooling. Disable unauthorized RMM sessions, revoke persistence, and block known attacker remote-access infrastructure.
  3. Preserve logs before wiping systems. Collect endpoint, identity, firewall, DNS, proxy, cloud, file-server, and SaaS audit logs tied to the suspected timeline.
  4. Hunt for staging and exfiltration. Search for archives, unusual file access, bulk reads, SFTP sessions, cloud uploads, and outbound transfer spikes.
  5. Review identity abuse. Look for new accounts, privilege changes, shadow credentials, mailbox rules, OAuth grants, token creation, and abnormal MFA behavior.
  6. Assess data exposure, not just malware. Determine what data was accessed or moved so legal, customer, contractual, and regulatory decisions are based on evidence.
  7. Rotate credentials touched by the intrusion. Include service accounts, admin accounts, VPN credentials, RMM credentials, cloud keys, and credentials stored on affected hosts.

Bulwark Black assessment

The ransomware story has matured past “malware encrypts files.” The modern pattern is access, reconnaissance, staging, theft, pressure, and sometimes encryption. That means a backup-only strategy is incomplete, even when backups are well tested.

For SMBs and government contractors, the best near-term improvement is to treat data movement as a core ransomware detection surface. Know which tools are allowed, know where sensitive data lives, watch for abnormal staging and outbound transfer, and rehearse the response before encryption starts.

The organizations that do well against this model are not the ones with the prettiest ransom-note playbook. They are the ones that make attackers noisy before the data is gone.

Original source: Zscaler — Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims.

Additional context: Zscaler — From Access to Exfiltration: What Defenders Need to Know.