Number of Corporate Ransomware Victims in Spain Rises 19%, According to Zscaler ThreatLabz
The Zscaler ThreatLabz 2024 Ransomware Report identifies 160 observed Spanish companies as victims of ransomware, a 19% increase on the previous year. Globally, the volume of data stolen in these attacks has grown by more than 275%.

News summary
Zscaler has published new data from its ThreatLabz 2024 Ransomware Report. According to the company, the number of Spanish companies victimised by ransomware rose by 19% year-on-year to 160, placing Spain as the seventh most affected country among those analysed, accounting for more than 2% of observed cases.
The growth in Spain is similar to that of Germany (nearly 21%) and France (17%), and higher than that of Italy (7%). Globally, the report puts the volume of data exfiltrated in ransomware attacks at 896.2 terabytes, up more than 275% from the previous year.
Zscaler further highlights that 62% of individual victims held C-level or senior management positions, reflecting the attackers’ interest in accounts with privileges and decision-making authority.
The figures originate from a single vendor and the cases it observes, so they should be interpreted as a trend rather than a census. In any case, the trend is consistent: ransomware combines encryption with data theft, and recovery requires both backups and the ability to detect an intrusion before encryption occurs.
Source: El Obrero (Zscaler ThreatLabz) — 7 October 2026
Frequently Asked Questions
- Do these figures represent all ransomware cases in Spain?
- No. These are the cases Zscaler observed in its analysis. Many incidents are not made public, so the figures should be understood as a trend indicator.
- Are backups sufficient to recover from a ransomware attack?
- Backups allow for system recovery, but they do not prevent data exfiltration. That is why early detection and access control are also necessary.
Concepts mentioned in this article: Backup · Ransomware
Detection before encryption makes all the difference. At Seintec, we combine monitoring, endpoint protection, and immutable backups. Speak with our cybersecurity team.
Contact SeintecRelated service
Managed SOC and MDR
Continuous monitoring, detection and response to security incidents across endpoints, servers, network and identities.