Security1 publisher2 min readPublished Updated
Zscaler counts a fifth fewer ransomware payments at a higher $432,000 average
Zscaler ThreatLabz logged 20.1% fewer ransomware payments in the year to March 2026, worth $327.8M in total, while the average payment rose 5.3% to $431,995. Leak-site listings fell just 3% over the same period, so the decline is in how many victims pay.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The ten groups with the largest leak volumes exfiltrated 896.2 TB combined, up 275.8% on the year and more than seven times the 123.8 TB recorded in 2023-2024.
- The recurring entry route is spam bombing followed by Microsoft Teams vishing that steers staff into Quick Assist or other remote support tools before attacker tooling is deployed.
- ThreatLabz found 62% of victims held manager-level titles or above, roles that often carry broad operational access and organisational trust.
- Of the top 15 groups by victim volume, 60% were new to the rankings, and 52 newly active groups appeared over the year.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure User-risk programs scoped to IT admins miss most of the people this chain targets, since Zscaler puts the high-risk profile with staff who have influence, workflow access and data proximity.
- decision Security teams now have to set policy, visibility and detection for Teams contact and remote support sessions, workflows Zscaler counts as ransomware attack surface.
- constraint Blocklists and hunts keyed to group names go stale within a year when most top groups are new, so Zscaler's guidance is controls built on behaviours and tactics.
Both payment figures cover known, recorded payments [2][3]. Dividing the $327.8M total by the $431,995 average gives about 759 payments for the year [1]. The 20.1% fall in count puts the previous year near 950 [6]. Backing out the 15.8% decline, prior-year known payments come to about $389M [2], at an average near $410,000 [3]. The average payer handed over roughly $21,700 more than a year earlier [4]. A 5.3% rise is small next to a one-fifth drop in the number of payments [3][4].
Leak volumes grew much faster. Taking the 275.8% rise back one year, the top ten groups by leak volume held about 238.5 TB of stolen data a year earlier [5]. The series runs 123.8 TB, then roughly 238.5 TB, then 896.2 TB across three reporting years [6][5][5]. Zscaler wrote that the payment pattern is "suggesting attackers are extracting more from the victims that do pay" [13]. It argues that stealing multiple terabytes from one organisation raises extortion pressure even when victim numbers stay flat [16].
Zscaler's published summary does not tie any payment to the volume stolen from that victim, so the step from terabytes to ransom size is Zscaler's inference [13]. Over the same twelve months [1], stolen data at the top groups grew about 3.8 times [5] while the average payment rose 5.3% [4].
The access findings are more concrete. Zscaler describes initial access as driven by repeatable playbooks that abuse trusted enterprise tools and trusted people [18]. In the Teams chain, every step before the attacker's own tooling arrives runs on legitimate remote support and collaboration software [8]. Zscaler says the technique succeeds because it blends into normal operations [15].
Targeting links access to theft. About 75% of victims worked in finance, sales, operations, HR and marketing, functions Zscaler describes as tied to business-critical processes and high-value data [10].
The group churn points to a sustained affiliate method. Zscaler attributes the turnover in names to disruptions, shutdowns and rebrands, with affiliates carrying proven access techniques and tooling into new operations [12]. On that account the Teams and Quick Assist route belongs to the affiliates and moves with them when a brand shuts down [12].
What to watch
- Whether the full ThreatLabz report ties individual payments to the data volume stolen from each paying victim.
- Independent payment tallies for April 2025 to March 2026 that confirm or contradict a 20.1% fall in recorded payments.
- Any change to default external Teams contact or Quick Assist settings, the two legitimate tools at the front of the access chain ThreatLabz describes.