Your Backups Won’t Stop This

Welcome back to THE IT EDGE. Ransomware crews now spend less time locking your files and more time quietly copying your data.
896 Terabytes Walked Out the Door
Zscaler’s ThreatLabz 2026 Ransomware Report tracked 896.2 terabytes of stolen data between April 2025 and March 2026, up more than 275% year over year. Ransom payments traced on the blockchain reached $328 million, and the average payment rose 5.3% to $431,995. Attackers get paid when they hold your customer records and intellectual property, whether or not your servers stay online. Zscaler adds that attackers use GenAI to speed up operations, and that the shift toward theft is harder to see than an outage.
A Tested Backup Covers Half the Problem
Restoring from clean backups ends an outage. It does not pull back data that has already left the building. Keep the restore runbook, then add a data-exposure runbook beside it: who calls legal, who calls your insurer, and who drafts the customer notice on the day an attacker emails you a sample of what they took.

Managers Are the Target
Manager-level titles and above made up 62% of victims in the Zscaler data. Those accounts carry broad access and the authority to approve requests quickly. Review privileged and executive accounts first. Confirm phishing-resistant MFA, trim standing access, and check who can approve a remote support session. CM-Alliance’s August roundup of roughly 10 major ransomware incidents pointed to the same weak spots: credential gaps and missing MFA.
Your Everyday Tools Are the Door
Zscaler reports attackers abusing Microsoft Teams and Quick Assist for social engineering and lateral movement. An outside caller on Teams posing as the help desk makes a believable story. Limit external Teams access to approved domains, disable Quick Assist where another remote tool exists, and tell staff your help desk never starts a session unprompted. Then watch outbound data volume, since that is where theft shows up first.
Mid-Market Is in the Crosshairs
Black Kite’s 2026 report found the $50M to $100M revenue band grew to 29.3% of victims, and 43.5% of victims still carried critical patch gaps after the incident. Trackers count differently: Black Kite saw victims rise 24.9%, and Zscaler saw a 3% decline over the same twelve months. Both show high volume and constant turnover, with Zscaler logging 52 newly active groups. For a team your size, patching critical flaws and tightening privileged access will do more than any new tool purchase.
Where EdgeTeam Fits
Reach out to EdgeTeam for a quick consult on your data-exposure plan, privileged account review, or Teams and remote support settings.
Start Your 2027 Planning With EdgeTeam
That’s it for this edition of THE IT EDGE. We’ll be back in November with another single-topic issue.
