Ransomware groups exfiltrated 896.2 TB of data over the past year, a 275.8% increase that the Zscaler ThreatLabz 2026 Ransomware Report ties partly to AI-assisted tradecraft.
Healthcare slipped 24% year over year in attack volume but still ranked fourth among the most targeted sectors. INC Ransom claimed one of the largest thefts in the dataset, a 20 TB haul from a large healthcare organization.
The report also records a healthcare victim that paid a $2 million demand even though attackers never encrypted its files, an extortion model that leans on the threat of exposure rather than downtime.
ThreatLabz describes an access broker that targets managers in accounting, finance, sales, operations, HR, and marketing, where one stolen identity opens the door to sensitive data. Spam bombing, IT-themed Microsoft Teams vishing, and abuse of legitimate support tools round out the initial-access playbook.
Generative AI is speeding up reconnaissance, social engineering, and malware development, the researchers said, with a growing share of new malware families showing signs of AI assistance.
For hospital security leaders, the pattern argues for treating data theft, not just encryption, as the primary loss scenario. Backups and recovery plans help with ransomware that locks systems, but they do little once records are already in an attacker’s hands.