Skip to content
TECH CEO Daily

Microsoft Digital Defense Report says AI favors attackers; Zscaler logs 896.2 TB stolen

Microsoft says AI hands attackers the early advantage, Zscaler tracks a shift to data-theft extortion that hits managers, and researchers spot an AI agent fleet on Tencent Cloud.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1Microsoft's 2026 Digital Defense Report says AI gives attackers a near-term edge, cutting sophisticated attack chains from days to seconds.
  • 2Zscaler found ransomware data theft rose more than 275% to 896.2 terabytes; manager-level staff and above were 62% of victims.
  • 3Researchers traced 2,048 Amap submissions to an AI agent fleet on Tencent Cloud, spotted through records on a public scanner.

The news

The Microsoft Digital Defense Report 2026, released October 1, says AI has handed attackers a near-term advantage over defenders. A day earlier, Zscaler (ZS) said ransomware groups stole 896.2 terabytes of data in a year as extortion shifts from locking files to stealing them.

Microsoft (MSFT) writes that AI is changing the economics of attack and defense and that attackers are reaching its benefits first, so defenders must move sharply to close the gap. For sophisticated groups, the company says, AI cuts the attack chain from days to seconds. For less skilled ones, it offers the kind of persistence once limited to intelligence agencies. Microsoft expects AI-driven threats to be commoditized within a year.

The report's executive summary says 63% of intrusions involved data theft and that user execution, valid accounts, social engineering and phishing made up 73.3% of initial access attempts. Exposed cloud workloads were attacked an average of 5.3 hours after exposure. According to BleepingComputer and Help Net Security, the full report puts the median time from a flaw's discovery in the wild to its weaponization well below 24 hours.

Zscaler's ThreatLabz 2026 Ransomware Report, which covers April 2025 to March 2026, found that data theft by ransomware groups rose more than 275% year over year to 896.2 terabytes. Blockchain transactions associated with ransomware payments reached $328 million, and the average payment rose 5.3% to $431,995. Victims with manager-level titles and above made up 62% of the total, and Zscaler said attackers use generative AI to speed operations and build new tools faster.

Zscaler also said attackers increasingly abuse trusted tools such as Microsoft Teams and Quick Assist, Microsoft's remote-support app. Leak sites listed 7,366 victims, down 3%, and the Qilin, Akira and INC Ransom groups accounted for 34% of them. "Successful ransomware extortion is shifting away from file encryption," said Deepen Desai, Zscaler's executive vice president of cybersecurity.

A separate finding shows how hard machine traffic can be to see. On October 4, researchers Alecto Irene Perez and Ethan Elasky of the Swarmchasers project said a fleet of AI agents running on Tencent Cloud in Hong Kong, part of Tencent (0700.HK), filed 2,048 submissions about Alibaba's (BABA) Amap map service to the public scanner urlquery between September 28 and October 4, covering 216 places. TechCrunch reported on October 5 that the agents appeared to sidestep Alibaba's API rules but did nothing overtly malicious.

The numbers

Data stolen by ransomware groups, Apr 2025–Mar 2026 (Zscaler)
896.2 TB
Year-over-year rise in ransomware data theft (Zscaler)
More than 275%
Blockchain transactions tied to ransomware payments (Zscaler)
$328 million
Average ransom payment, up 5.3% (Zscaler)
$431,995
Victims with manager-level titles and above (Zscaler)
62%
Intrusions involving data theft (Microsoft)
63%
Amap submissions traced to the Tencent Cloud agent fleet (Swarmchasers)
2,048

Why CEOs should care

For CISOs, the key figure is time. If flaws are now often weaponized within a day, a monthly patch cycle leaves internet-facing systems open for weeks. Ask how long your team takes to patch edge devices, identity systems and developer tools, and whether automated containment can disable accounts and revoke sessions in minutes, as Microsoft recommends. Microsoft still names phishing-resistant multifactor authentication and strong privileged-access controls as the highest-leverage defenses.

For CFOs and boards, Zscaler's numbers mean backups alone no longer cap the bill. When a group steals data instead of encrypting it, restoring systems does not remove the threat of a leak. Review whether cyber insurance covers data-theft extortion, and fund monitoring for large outbound data transfers alongside recovery. Microsoft also urges boards to get regular reporting on identity exposure, patch latency, AI agent permissions, critical dependencies, dwell time and recovery readiness.

Because staff with manager-level titles and above made up 62% of victims in Zscaler's data, executives and their assistants need the strongest protections, including tighter controls on external Teams chats and remote-support tools such as Quick Assist. Companies that run public APIs should also ask whether they would notice an agent fleet like the one on Tencent Cloud, which outside researchers spotted through records on a public scanner.

The bigger picture

Both reports describe the same shift: AI makes attacks faster and cheaper, while defense still depends on patching, identity hygiene and staff training. Microsoft expects the balance between attackers and defenders to be restored eventually, but says defenders will need AI agents of their own and must share threat signals across systems and companies, which it calls the primary strategic variable. In a companion blog post, Microsoft deputy CISO Terrell Cox wrote that attackers' AI use remains focused on specific parts of existing attack workflows.

The agent fleet episode fits a pattern TechCrunch described: researchers have watched more closely for AI agent activity since the Hugging Face security incident, and the agents they find usually make little effort to hide. BleepingComputer reported that Microsoft's report says most observed campaigns still have human direction, even as lab systems show end-to-end autonomy.

What’s next

TechCrunch described the Swarmchasers post as preliminary, and its authors say no record names the model behind the fleet, though their code-style tests pointed to Chinese models from Tencent and Zhipu rather than to Anthropic's Claude. Watch for a firm identification, for any comment from Tencent or Alibaba, and for whether the shift to data-theft extortion that Zscaler describes shows up in incident and insurance data over the coming quarters.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftZscalerRansomwareAI agentsTencent

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.