Gadget.Co.Za Ransomware Data Theft Increases 275% Amid Falling Payments
Article Content
- •Data theft from ransomware groups surged 275.8% in 2026, reaching 896.2 terabytes.
- •Ransom payments decreased by 15.8%, indicating a strategic shift in ransomware tactics.
- •In South Africa, 63% of ransomware incidents involved data encryption, with high recovery costs.
The Zscaler ThreatLabz 2026 Ransomware Report reveals a staggering 275.8% increase in data theft by the top ten ransomware groups, escalating from 123.8 terabytes to 896.2 terabytes year-over-year. Despite this surge, ransom payments have decreased by 15.8% to $327.8 million, indicating a shift in strategy where attackers leverage stolen data rather than solely relying on encryption. Schools, hospitals, and government agencies were notably affected, with one group reportedly exfiltrating 30 terabytes from a government target in a single campaign. In South Africa, a separate Sophos report indicates that 63% of ransomware incidents involved data encryption, with recovery costs averaging over R17 million. Although 99% of encrypted data was recovered, only 40% of organizations returned to normal operations within a week, the lowest among surveyed countries. The findings highlight the evolving tactics of ransomware operators and the challenges organizations face in recovery.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Babuk2 and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the scale of data theft?
How are organizations recovering from attacks?
What are the financial impacts of ransomware?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…