Skip to content

Security1 publisher2 min readPublished Updated

Zscaler counts a fifth fewer ransomware payments at a higher $432,000 average

Zscaler ThreatLabz logged 20.1% fewer ransomware payments in the year to March 2026, worth $327.8M in total, while the average payment rose 5.3% to $431,995. Leak-site listings fell just 3% over the same period, so the decline is in how many victims pay.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Zscaler counts a fifth fewer ransomware payments at a higher $432,000 average
Generated illustration

What happened

  • The ten groups with the largest leak volumes exfiltrated 896.2 TB combined, up 275.8% on the year and more than seven times the 123.8 TB recorded in 2023-2024.
  • The recurring entry route is spam bombing followed by Microsoft Teams vishing that steers staff into Quick Assist or other remote support tools before attacker tooling is deployed.
  • ThreatLabz found 62% of victims held manager-level titles or above, roles that often carry broad operational access and organisational trust.
  • Of the top 15 groups by victim volume, 60% were new to the rankings, and 52 newly active groups appeared over the year.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure User-risk programs scoped to IT admins miss most of the people this chain targets, since Zscaler puts the high-risk profile with staff who have influence, workflow access and data proximity.
  • decision Security teams now have to set policy, visibility and detection for Teams contact and remote support sessions, workflows Zscaler counts as ransomware attack surface.
  • constraint Blocklists and hunts keyed to group names go stale within a year when most top groups are new, so Zscaler's guidance is controls built on behaviours and tactics.

Both payment figures cover known, recorded payments [2][3]. Dividing the $327.8M total by the $431,995 average gives about 759 payments for the year [1]. The 20.1% fall in count puts the previous year near 950 [6]. Backing out the 15.8% decline, prior-year known payments come to about $389M [2], at an average near $410,000 [3]. The average payer handed over roughly $21,700 more than a year earlier [4]. A 5.3% rise is small next to a one-fifth drop in the number of payments [3][4].

Leak volumes grew much faster. Taking the 275.8% rise back one year, the top ten groups by leak volume held about 238.5 TB of stolen data a year earlier [5]. The series runs 123.8 TB, then roughly 238.5 TB, then 896.2 TB across three reporting years [6][5][5]. Zscaler wrote that the payment pattern is "suggesting attackers are extracting more from the victims that do pay" [13]. It argues that stealing multiple terabytes from one organisation raises extortion pressure even when victim numbers stay flat [16].

Zscaler's published summary does not tie any payment to the volume stolen from that victim, so the step from terabytes to ransom size is Zscaler's inference [13]. Over the same twelve months [1], stolen data at the top groups grew about 3.8 times [5] while the average payment rose 5.3% [4].

The access findings are more concrete. Zscaler describes initial access as driven by repeatable playbooks that abuse trusted enterprise tools and trusted people [18]. In the Teams chain, every step before the attacker's own tooling arrives runs on legitimate remote support and collaboration software [8]. Zscaler says the technique succeeds because it blends into normal operations [15].

Targeting links access to theft. About 75% of victims worked in finance, sales, operations, HR and marketing, functions Zscaler describes as tied to business-critical processes and high-value data [10].

The group churn points to a sustained affiliate method. Zscaler attributes the turnover in names to disruptions, shutdowns and rebrands, with affiliates carrying proven access techniques and tooling into new operations [12]. On that account the Teams and Quick Assist route belongs to the affiliates and moves with them when a brand shuts down [12].

What to watch

  • Whether the full ThreatLabz report ties individual payments to the data volume stolen from each paying victim.
  • Independent payment tallies for April 2025 to March 2026 that confirm or contradict a 20.1% fall in recorded payments.
  • Any change to default external Teams contact or Quick Assist settings, the two legitimate tools at the front of the access chain ThreatLabz describes.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories