Tech • AI • Robotics • Game

VIDEO
ENFR

Daily Podcast full article

Ransomware extracts $328M with AI

Zscaler’s latest ransomware snapshot puts a hard price on AI-assisted extortion: 896.2 terabytes of stolen data, more than $328 million in blockchain-linked payments, and a shift toward executive targeting and legitimate workplace tools. At the same time, the arrest of Canadian ransomware negotiator Edward Dubrovsky shows law enforcement pressing beyond malware crews into the specialist ecosystem around cyber-extortion.

Generated October 11, 2026 at 6:15 PM1426 words
AI-generated illustration

The current story

The ransomware story of the weekend is not simply that criminals are asking for more money. It is that ransomware is becoming more industrial, more data-driven, and easier to scale with generative AI.

Cybersecurity Insiders, summarizing Zscaler ThreatLabz’s 2026 ransomware findings on October 11, reported that ransomware activity increased by more than 275% year over year, with campaigns increasingly using AI and producing more than $328 million in payments to hacking groups . Zscaler’s researchers also recorded 896.2 terabytes of stolen data over the report period, and said employees with manager-level titles or higher accounted for 62% of victims, which points to a strategy focused on people who can approve payments, access sensitive systems, or influence crisis decisions .

That same data set shows why the ransomware conversation has moved beyond encrypted files. According to the report summary, attackers are abusing trusted tools such as Microsoft Teams and Quick Assist for social engineering, lateral movement, data theft, and encryption . In other words, the danger is not always a strange executable detonating on a server. Increasingly, it is a believable conversation, a normal enterprise app, a privileged identity, and an attacker who knows enough about the organization to make pressure feel personal.

The second live development is legal rather than technical. Reuters reported on October 10 that Canadian ransomware negotiator Edward Dubrovsky was arrested Thursday and faces extortion-related charges, citing court documents, prison records, and a person familiar with the matter . The records reportedly list charges involving conspiracy to threaten the confidentiality of information with intent to extort money and interference with commerce, while also showing conflicting spellings of the surname and leaving some details sealed . Those caveats matter: an arrest is not a conviction, and the public record does not yet establish guilt.

Why the $328 million number matters

The $328 million figure is important because it measures more than criminal revenue. It is evidence that extortion is still functioning as a business model even as defenders improve backup, endpoint detection, and incident response. Zscaler’s summary says the average ransom payment rose 5.3% year over year to $431,995, suggesting that the market is not merely producing more incidents but sustaining meaningful payment pressure .

The stronger signal, however, may be the combination of payments and data volume. Zscaler says ransomware data theft reached 896.2 terabytes, while victim counts on leak sites remained high despite churn among ransomware groups . That means defenders should not treat “we can restore from backup” as the end of the discussion. Backups help restore operations; they do not unsteal customer records, intellectual property, executive emails, or regulated data.

Generative AI worsens that asymmetry. The report summary says attackers are using GenAI to speed up operations and improve the theft of intellectual property, customer information, and other sensitive data . That does not require science-fiction malware. It can mean faster reconnaissance, better phishing copy, automated translation for global targeting, help writing scripts, and more convincing executive impersonation. If Skynet discovered accounts receivable, it apparently also learned procurement workflows and calendar etiquette.

The Dubrovsky arrest widens the frame

The Dubrovsky arrest adds a different layer to the same problem: the ecosystem around extortion. BleepingComputer reported on October 10 that Dubrovsky, 54, has held senior roles at cybersecurity firms that help data-breach and ransomware victims negotiate with cybercriminals, and that public court records show he appeared in the Eastern District of Pennsylvania after being taken into custody . BleepingComputer also reported that a later order transferred him to the Eastern District of Texas, where the charges were filed, and that the docket lists conspiracy and extortion-related charges while the complaint remains sealed .

Nextgov/FCW reported that the arrest may be linked to the FBI’s pursuit of ShinyHunters, while stressing that Dubrovsky’s specific alleged conduct and any role in the FBI intrusion had not been publicly established . CyberScoop similarly reported that the case appears to align with actions following the ShinyHunters attack on FBI IT systems, but also noted that the FBI did not publicly announce Dubrovsky’s arrest by name and that other case details remain sealed .

That distinction is not legal nitpicking. Ransomware response involves many legitimate roles: lawyers, insurers, forensic firms, negotiators, crisis communications teams, and cryptocurrency specialists. Law enforcement interest in a person from that world does not make the profession criminal. But it does show that investigators are looking at relationships, services, payment flows, communications, and expertise networks around extortion campaigns, not only at the malware operators who press “run.”

KrebsOnSecurity, which first identified Dubrovsky in connection with the arrest, reported that federal court records listed an Edward Dobrovsky, with a slight spelling variation, arrested in Pennsylvania on October 8 on cyber-extortion and conspiracy charges, and that several core documents were sealed . Krebs also reported that the FBI’s ShinyHunters investigation had become centered in a Texas field office, according to sources, and that the group typically uses phishing and stolen credentials to steal data from software-as-a-service accounts before threatening publication .

The common thread: scale, leverage, and identity

The Zscaler findings and the Dubrovsky arrest are not the same event, but they describe the same ransomware economy from two angles. Zscaler quantifies the operational side: more data theft, bigger payment flows, executive targeting, trusted-tool abuse, and AI-assisted efficiency . The arrest coverage describes the enforcement side: investigators tracing alleged extortion conduct through people, companies, court records, and possibly the broader ShinyHunters network .

For enterprises, the lesson is uncomfortable. The ransomware kill chain now overlaps heavily with ordinary business infrastructure. Microsoft Teams can be a collaboration platform and an attack channel. Quick Assist can be a support tool and a social-engineering prop. A manager’s identity can be more valuable than a random workstation. A data lake, CRM export, HR portal, or file share can be more coercive than an encrypted server if the attacker’s goal is public pressure.

That is why “AI-aware defense” cannot mean buying a dashboard with the letters AI in the product sheet. It means detecting synthetic or highly tailored lures, monitoring abnormal behavior in collaboration tools, tightening conditional access, reducing standing privileges, and validating whether remote-support sessions are legitimate. It also means assuming attackers will use automation to compress the time between initial access, discovery, exfiltration, and extortion.

What defenders should do now

The practical response starts with identity. If senior employees and privileged users are disproportionate targets, companies need phishing-resistant multi-factor authentication, strong device posture checks, conditional access rules, just-in-time privilege, and rapid revocation playbooks for suspected account compromise. Zscaler’s finding that manager-level and higher titles represented 62% of ransomware victims should push boards to treat executive identity as critical infrastructure, not a VIP convenience issue .

Second, organizations should treat collaboration and remote-support tools as monitored attack surfaces. Trusted applications cannot be exempt from logging simply because employees rely on them. Security teams need visibility into unusual Teams chats, suspicious external contact patterns, unexpected Quick Assist sessions, anomalous file downloads, and scripted activity that blends with normal administration .

Third, recovery plans must be rehearsed around data theft, not only encryption. A tabletop exercise that ends with “restore from backup” is incomplete. The harder questions are who decides whether stolen-data claims are credible, how quickly legal and communications teams can assess notification duties, how executives communicate with customers, and what evidence is needed before any negotiation decision. The sealed nature of parts of the Dubrovsky case is also a reminder that organizations may not know in real time which intermediaries, channels, or counterparties are under investigation .

Finally, boards should measure ransomware risk in time. AI-assisted attackers are valuable to themselves because they reduce delay: faster reconnaissance, faster lure creation, faster scripting, and faster pressure. Defenders need the same obsession with time: shorter detection windows, faster account containment, quicker legal escalation, and recovery drills that involve executives rather than only the security operations center.

The current ransomware story is therefore not “AI invented a new crime.” It is that AI is lowering the cost of familiar crimes, while law enforcement is widening its aim from malware to the human and professional networks around extortion. The $328 million headline is the bill. The Dubrovsky arrest is a sign that investigators are following the payment machinery as well as the code.

Comments

Be the first to comment.

Sources from the last 72 hours

  1. [1]Zscaler Report Finds AI-Assisted Ransomware Attacks Drive Massive Data Theft and $328 Million in Extortion PaymentsOct 11, 2026, 2:00 AM
  2. [2]Canadian ransomware negotiator arrested amid FBI hacker crackdownOct 11, 2026, 12:14 AM
  3. [3]Cyber exec arrested in case allegedly tied to ShinyHunters hackersOct 10, 2026, 1:07 PM
  4. [4]Cybersecurity executive who helped hacking victims arrested on federal extortion chargesOct 10, 2026, 6:11 PM
  5. [5]FBI Arrests Executive at Ransomware Negotiation FirmOct 9, 2026, 2:00 AM
  6. [6]Canadian cybersecurity executive arrested in federal extortion caseOct 10, 2026, 2:00 AM

AI-generated article based on recent web research, then preserved as a dated editorial snapshot.