Skip to content
File security for Windows systems — since 2003

How FileSure Would Have Stopped the 896 Terabyte Ransomware Data Theft Wave

• By Gene Allen

Zscaler’s ThreatLabz 2026 Ransomware Report documents a 275% increase in ransomware data theft, with attackers exfiltrating 896.2 terabytes of data — equivalent to 90 times the print collection at the Library of Congress. The report highlights a strategic shift: ransomware groups are moving away from file encryption toward data theft and extortion, targeting privileged users, and abusing trusted enterprise tools like Microsoft Teams for lateral movement.

The attacks described in this report share a common technical requirement: they all depend on Windows file system operations.

The Attack Chain Requires File Operations at Every Stage

Ransomware groups can use GenAI to accelerate their operations. They can target senior executives with privileged access. They can abuse Microsoft Teams to blend in with legitimate traffic. But none of that matters if they can’t complete the file operations their attack depends on.

Before ransomware can encrypt your files, it has to land on your system. That means writing an executable payload to disk — typically delivered via email attachment, browser download, or remote access tool. That write operation happens before the ransomware executes, before it encrypts anything, before you have a problem.

FileSure Defend operates at the Windows kernel level via a filter driver. It intercepts file system operations — open, read, write, delete, create, rename — before they complete. You define a policy: unauthorized programs cannot write executable files to this system. An email client or browser tries to save a ransomware payload? The write is blocked at the kernel level. The file never lands. The ransomware never executes.

Data exfiltration requires reading files from disk before transmitting them. The report describes attackers stealing intellectual property, customer information, and sensitive data. Those files have to be read from the file system before they can be uploaded to an attacker-controlled server or copied to removable media. FileSure logs every file read operation — which user, which program, which file, which machine, timestamp. Unusual access patterns become visible immediately.

Lateral movement across a network typically involves writing files to remote shares via SMB. The report mentions attackers moving laterally within an organization’s environment. That movement requires writing reconnaissance tools, credential dumpers, or additional payloads to network drives. FileSure controls write operations to network shares the same way it controls local disk writes.

A Specific FileSure Configuration That Applies

Here’s a threshold rule configuration that would have contained the bulk encryption described in the report:

  • File name filter: * (all files)
  • Operations: Write, Rename/Move (ransomware renames files after encryption)
  • Drive type: Hard drives, Network drives, Removable drives
  • Threshold: 20 matches within 60 minutes
  • Action: Block subsequent operations, alert administrator

Normal file save operations for a typical user fall well below 20 per hour. Ransomware encryption events modify hundreds of files per minute. The threshold fires within seconds. Subsequent write and rename operations are blocked. Damage is contained to the files modified before the threshold fired.

The Shift to Data Theft Doesn’t Change the Fundamentals

The report emphasizes that “successful ransomware extortion is shifting away from file encryption that often causes business disruptions to less visible, but more damaging data theft attacks.” That’s a strategic shift for the attackers, but it doesn’t change the technical fundamentals.

Data theft still requires reading files from disk. It still requires writing tools to disk before they execute. It still requires lateral movement via file writes to network shares. FileSure controls all of those operations at the kernel level.

The report notes that 62% of victims held manager-level titles or above. Privileged users have legitimate access to sensitive data — that’s why attackers target them. FileSure doesn’t prevent privileged users from accessing the files they’re authorized to access. It logs every access and enforces rules about what can be done with those files: no copying to USB drives, no uploading via webmail, no syncing to personal cloud storage.

The attackers in this report stole 896 terabytes of data. Every byte of that data was read from a Windows file system before it was exfiltrated. Control the file operations, and the attack surface collapses.

FileSure Defend runs on all Windows versions from Server 2003 through Server 2022 and Windows 7 through 11. If you have legacy systems that modern endpoint security tools won’t install on, FileSure protects those too. Start a free 21-day trial at bystorm.com — 1 server, 10 workstations, fully functional, no credit card required.


Source: New Zscaler Report Reveals AI-Assisted Attackers Move to Massive Data Theft, Executive Targeting, and Millions in Extortion Payments

Category: Ransomware

Tags: ransomware, data exfiltration, lateral movement, privileged user targeting, kernel filter driver, file system security, threshold blocking, smb

Gene Allen

Written by

Gene Allen

Gene Allen is a Windows file security expert with over 20 years of experience developing kernel-level solutions that protect enterprise data from ransomware, unauthorized access, and data loss. As founder of ByStorm Software, he architected FileSure — a patented file auditing and security platform trusted by 200+ organizations across healthcare, financial services, and government. Gene holds two U.S. patents in file system security and access control.

Ready to protect your organization?

Start your free 21-day trial today. No credit card required.

Start Your Free 21-Day Trial