Ransomware groups spent the last two years learning that encryption alone no longer forces a payout. The newest twist, according to Zscaler’s September 30, 2026 announcement of its ThreatLabz 2026 Ransomware Report, is that attackers are now leaning on generative AI to do the grunt work. Zscaler, Inc. (NASDAQ: ZS) says its threat researchers tracked GenAI-assisted malware development and scripting across the April 2025 to March 2026 reporting window, alongside a sharper focus on executive targeting and bulk data theft. The headline dollar figure, roughly $328 million in blockchain-traced extortion payments, is almost a footnote next to the bigger story: criminal groups are industrializing their tooling the same way everyone else is, using AI to write code faster, adapt to defenses, and squeeze more value out of every breach.

That framing matters because it changes who needs to pay attention. A ransomware report built around encryption statistics is a problem for backup administrators. A ransomware report built around AI-assisted tooling and executive targeting is a problem for CISOs, boards, and anyone who approves wire transfers. This piece digs into what Zscaler’s researchers actually found, how it stacks up against other ransomware trackers, and what the shift toward AI-aided extortion means for the next year of enterprise security spending.

What the ThreatLabz 2026 Ransomware Report Says About AI

Zscaler published the ThreatLabz 2026 Ransomware Report on September 30, 2026, covering ransomware activity from April 2025 through March 2026. Unlike prior editions that framed the story mostly around encryption and ransom demands, this year’s report leads with a different claim: attackers are using generative AI tools to speed up reconnaissance, adapt malware, and automate scripting tasks that used to require a skilled operator at a keyboard. Zscaler’s researchers describe this as GenAI-assisted malware development, a phrase that covers everything from AI-written obfuscation routines to chatbot-generated phishing lures tuned for a specific target’s industry and tone.

The report does not claim every ransomware group has gone fully autonomous with AI agents running attacks end to end. Instead, it describes AI as an accelerant layered onto an existing playbook. Attackers still need initial access, still need to move laterally, and still need to decide what to steal. What is changing is how fast they can iterate once they are inside, and how quickly they can rewrite tooling when an existing variant gets flagged by endpoint detection. For a deeper look at how commercially available AI models are already being pushed into building working exploits, our coverage of GLM-5.3’s 100% safety bypass rate shows the same dynamic playing out on the model-safety side of the industry.

Executive Targeting Enters the Ransomware Playbook

Alongside the AI-tooling angle, Zscaler’s announcement specifically calls out executive targeting as a growing feature of 2026 ransomware campaigns. That is a meaningful shift from the spray-and-pray phishing of a few years ago. Rather than blasting generic lures across an entire employee directory, groups appear to be narrowing their focus to finance leaders, general counsel, and other executives who can authorize payments or who hold access to the most damaging categories of data. A well-crafted, AI-assisted phishing message aimed at a CFO carries far more leverage than the same message sent to a help desk technician, both because the executive’s inbox often has fewer layers of filtering and because compromising that account can open doors a lower-level employee’s credentials never would.

Security teams have spent years hardening the perimeter against commodity phishing kits. Executive-targeted, AI-personalized lures are a different animal, closer to the kind of business email compromise tactics that fraud teams have tracked for a decade, now merged with ransomware’s data-theft playbook. The result is a hybrid threat that does not fit neatly into either the “ransomware” or “BEC” bucket that most security budgets are built around.

The Numbers Behind the Headline

The AI and executive-targeting findings sit on top of a set of figures that have already drawn attention across the security press. ThreatLabz measured 896.2 terabytes of data exfiltrated by the ten most active ransomware groups during the reporting window, a jump of more than 275% year over year. Blockchain-traced ransomware payments totaled roughly $328 million, down from the prior year, while the average individual payment rose 5.3% to $431,995. We covered that side of the story, including the sector-by-sector breakdown, in our earlier report on the 275% data-theft surge. The table below summarizes the figures most relevant to the AI and payment-behavior angle this piece focuses on.

MetricFigureYear-over-Year Change
Data exfiltrated by top 10 groups896.2 TB+275% (more than 7x prior period)
Blockchain-traced ransom payments~$328 million ($327.8M)-15.8%
Average individual ransom payment$431,995+5.3%
Recorded individual paymentsFewer than prior year-20.1%
Report windowApril 2025 – March 2026—

Put those four numbers side by side and a pattern emerges. Fewer victims are paying, but the ones who do pay are paying more, and the amount of data criminals are willing to steal before they even ask for money has exploded. AI-assisted tooling fits into that pattern as the mechanism that makes it all move faster: faster reconnaissance means attackers can identify which victims are worth a bigger ask, and faster malware iteration means they can keep operating even after a detection vendor flags their last build.

Deepen Desai on Why Attackers Are Reaching for GenAI

Deepen Desai, Zscaler’s Executive Vice President of Cybersecurity, put the shift in blunt terms in the company’s announcement of the findings. “They are using GenAI to speed up operations, and focusing on stealing more of an organization’s intellectual property, customer information, and other sensitive data to drive payment,” Desai said in the release. That sentence does two things at once. It confirms GenAI is being used operationally rather than experimentally, and it ties the AI angle directly back to the data-theft trend, since faster operations mean attackers can exfiltrate more before anyone notices.

Desai has also described the broader direction of the industry as a move toward “less visible, but more damaging data theft attacks”, a characterization that undercuts the instinct to measure ransomware severity by how loud or disruptive an attack looks from the outside. A quiet data-theft operation that never triggers a visible outage can still end with a company’s customer database posted on a leak site months later. That is the opposite of the smash-and-grab encryption attacks that defined ransomware’s first decade, and it is a harder pattern for traditional detection tools to catch early.

How Zscaler’s Numbers Compare to Chainalysis and Coveware

Zscaler is not the only firm tracking ransomware economics, and its figures do not always line up neatly with other trackers, largely because each firm measures a different slice of the problem. Chainalysis follows cryptocurrency flows tied to known ransomware wallets, Coveware tracks outcomes from the incident-response and negotiation cases it directly handles, and Zscaler’s ThreatLabz team leans heavily on monitoring the public leak sites that ransomware groups use to pressure non-paying victims. None of the three numbers is wrong. They are just answering slightly different questions.

TrackerMetricReported Figure
Zscaler ThreatLabzAverage ransom payment (2026 report)$431,995 (+5.3% YoY)
CovewareAverage payment, Q4 2025$591,988 (+57% vs. Q3 2025)
CovewareMedian payment, Q4 2025$325,000 (+132% vs. Q3 2025)
CovewareVictim payment rate, Q4 2025~20% (down from ~23% in Q3 2025)
ChainalysisTotal on-chain ransomware payments, 2025~$820 million (-8% vs. 2024)
ChainalysisMedian ransom payment, 2025$59,556 (+368% vs. $12,738 in 2024)

The differences in methodology explain why Coveware’s average payment lands well above Zscaler’s, and why Chainalysis counts a far larger total payment pool than Zscaler’s blockchain-traced $328 million figure. What all three agree on, despite the methodological gaps, is direction: fewer victims are paying, and the payments that still happen tend to be larger. That convergence across three independently built datasets is a stronger signal than any single report could provide on its own, and it is the kind of cross-validation that makes this year’s AI-assisted framing worth taking seriously rather than dismissing as a marketing angle from one vendor.

From Double Extortion to AI-Augmented Extortion

Ransomware’s evolution has moved in fairly clear stages. Encryption-only attacks dominated through the late 2010s, until the Maze group popularized double extortion around 2019 by stealing data before encrypting it, which neutralized the “just restore from backup” defense. Backup and recovery tooling improved in response, pushing more groups to treat data theft as the primary leverage rather than a backup plan. Zscaler’s 2026 report describes the next stage of that progression: AI-assisted tooling that lets a smaller crew of operators run the reconnaissance, malware-adaptation, and social-engineering work that used to require a larger, more specialized team.

That staffing math is worth sitting with. If generative AI tools can handle a meaningful share of the phishing-copy writing, code obfuscation, and target research that used to eat up analyst hours inside a ransomware crew, smaller and less sophisticated groups can suddenly compete with established operations. The barrier to running a credible extortion campaign keeps dropping, even as the sophistication of the output keeps rising. August 2026 alone saw ransomware attack volume climb 12% to 1,073 incidents, a trend line that fits comfortably with a lower cost of entry for attackers.

Market Impact: What This Means for Zscaler and Security Spending

For Zscaler itself, the report functions as both research and marketing. StockTitan’s coverage of the release framed it primarily as investor-relevant news, noting the company’s emphasis on AI-assisted attacker behavior as a reason enterprises need updated zero-trust and data protection architecture, categories the company sells directly into. That is not unusual. Threat intelligence reports from security vendors routinely double as sales collateral, and that does not make the underlying data wrong, but it is a useful lens for reading any single paragraph that happens to recommend a category of product the publishing vendor also sells.

The bigger market signal sits with buyers, not with Zscaler’s stock ticker. A report tying AI-assisted tooling to bigger data-theft volumes and bigger average payouts is the kind of statistic that security budget owners cite when asking boards for more money in categories like data loss prevention, insider-risk monitoring, and outbound traffic inspection. Expect data security posture management and exfiltration-detection vendors broadly, not just Zscaler, to lean on this report in sales conversations through the rest of 2026 and into 2027.

Why AI-Written Malware Is Harder to Catch

Signature-based and even many behavior-based detection tools were built around the assumption that malware families change slowly, with a handful of variants circulating for months before defenders catch up. Generative AI breaks that assumption. If an attacker can ask a model to rewrite obfuscation logic, swap out strings, or restructure a script’s control flow in minutes, a detection signature written against yesterday’s sample can miss today’s version entirely, even though the underlying behavior is identical. This is the same core problem security researchers have flagged when AI coding models get pushed toward building working exploit code, a trend our newsroom tracked closely in the GLM-5.3 safety-bypass story from earlier this cycle.

Defenders are not standing still. Outlets covering Zscaler’s findings, including Digital Watch Observatory and IT Brief, have both noted that the shift toward AI-assisted, data-theft-first campaigns is pushing incident responders to prioritize exfiltration monitoring and outbound traffic inspection over the encryption-trigger alerts that dominated detection strategy a few years ago. The practical upshot is that a security stack tuned purely to catch ransomware notes and encrypted file extensions is increasingly looking in the wrong place.

Who Is Most Exposed Right Now

Zscaler’s report ties some of the largest individual data-theft claims to schools, hospitals, and government agencies, sectors that combine large volumes of sensitive personal data with historically thin security budgets. Add AI-assisted executive targeting into that mix and the exposure compounds: a school district’s business office or a hospital system’s finance team is exactly the kind of under-defended, high-trust target that a well-crafted, AI-personalized phishing lure is built to exploit. Financial institutions face a related but distinct version of the same pressure, as seen in South Korea’s ongoing probe into AI-linked bank hacks across four lenders, where AI tooling has already been tied to attacks on financial infrastructure rather than just ransomware crews.

None of this means every organization faces equal risk. It means the calculus for prioritizing defenses has shifted. A company that has spent the last three years hardening against ransomware encryption and building fast backup-restore pipelines may still be exposed on the executive-targeting and data-exfiltration side, since those attacks do not care how quickly you can restore a file server.

Law Enforcement’s Uneven Record Against These Groups

Arrests and extraditions have continued throughout 2026, though they have done little to slow the overall trend line in Zscaler’s data. German authorities extradited a 28-year-old Qilin ransomware member earlier this year, and the FBI separately arrested a well-known ransomware negotiator, 54-year-old Cypfer founder on two counts tied to his role facilitating payments. Those cases show law enforcement can reach individual actors, but they also underscore how much of the ransomware economy, from negotiators to affiliates to the AI tools now in the mix, operates across jurisdictions that make a single arrest more symbolic than disruptive to the overall volume Zscaler is measuring.

Five Predictions for AI-Assisted Ransomware Through 2027

  • More ransomware groups will advertise AI-assisted capabilities openly on affiliate forums, treating faster tooling turnaround as a recruitment pitch the same way they once advertised encryption speed.
  • Executive-targeted, AI-personalized phishing will grow faster than generic employee-wide phishing campaigns, since the leverage per successful compromise is higher and AI lowers the cost of writing a convincing, role-specific lure.
  • Average ransom payments will keep climbing even if total payment volume keeps falling, continuing the pattern Zscaler, Coveware, and Chainalysis all independently documented through 2025 and 2026.
  • Security vendors across the data loss prevention and exfiltration-detection categories will increasingly market “AI-aware” detection as a response to AI-assisted attacker tooling, following the same report-driven sales cycle Zscaler itself is riding now.
  • Regulators and cyber insurers will start asking breach-disclosure questions specifically about AI-assisted intrusion techniques, separate from the generic ransomware checkboxes that dominate current disclosure forms, as reported by The Tech Edvocate’s coverage of the broader payment-and-data-theft divergence driving this year’s reports.

What Security Teams Should Change First

The most actionable change coming out of this report is not a new tool purchase, it is a shift in what counts as a high-priority alert. Outbound traffic to unfamiliar storage endpoints, unusual archive-utility activity, and finance-team phishing attempts that read as unusually well-researched all deserve the same urgency that encryption-trigger alerts used to get automatically. Security teams should also revisit who inside the organization is treated as a high-value target for social engineering. If executive targeting is rising the way Zscaler describes, the finance and legal teams that can authorize payments or access sensitive records need the same phishing-resistant authentication and awareness training that technical staff typically receive first.

Budget conversations should follow the same logic. A backup strategy that can restore systems in hours no longer counts as ransomware resilience on its own, since AI-assisted, data-theft-first attacks do not depend on encryption succeeding to extract value. Organizations that have not yet invested in exfiltration monitoring or data classification should treat this report as a prompt to move those line items up the priority list, rather than treating AI-assisted ransomware as next year’s problem.

Frequently Asked Questions

What is the Zscaler ThreatLabz 2026 Ransomware Report?
It is an annual threat intelligence report from Zscaler’s ThreatLabz research team, published September 30, 2026, covering ransomware activity from April 2025 through March 2026. This year’s edition centers on AI-assisted attacker tooling, executive targeting, and large-scale data theft.

How is AI being used in ransomware attacks, according to Zscaler?
The report describes attackers using generative AI tools to speed up operations such as malware development, scripting, and reconnaissance, which lets smaller teams adapt their tooling faster and evade detection more effectively than before.

How much are ransomware groups collecting in payments in 2026?
Zscaler traced roughly $328 million in blockchain-linked ransomware payments during the report’s window, down 15.8% year over year, while the average individual payment rose 5.3% to $431,995.

What does “executive targeting” mean in this context?
It refers to attackers focusing phishing and social-engineering efforts on finance leaders, legal counsel, and other executives who can authorize payments or access sensitive data, rather than spreading generic phishing attempts across an entire company.

How do Zscaler’s numbers compare to Chainalysis and Coveware?
The three trackers measure different things, blockchain flows, incident-response case outcomes, and leak-site activity, so exact dollar figures differ. All three, however, point the same direction: fewer victims paying overall, with the payments that do happen trending larger.

Does this mean ransomware encryption attacks are disappearing?
No. The report indicates data theft and extortion are becoming more prominent alongside encryption, not replacing it entirely. Some groups have shifted toward extortion-only models, but encryption still features in many campaigns.

Who did Zscaler quote on the AI-assisted trend?
Deepen Desai, Zscaler’s Executive Vice President of Cybersecurity, was quoted in the company’s announcement describing attackers using GenAI to speed up operations and focus on stealing sensitive data to drive payment.

What should security teams do first in response to this report?
Prioritize exfiltration and outbound-traffic monitoring alongside encryption-trigger alerts, extend phishing-resistant authentication to finance and legal staff, and treat data loss prevention as equally important to backup and recovery planning.