Skip to main content

Number of Corporate Ransomware Victims in Spain Rises 19%, According to Zscaler ThreatLabz

The Zscaler ThreatLabz 2024 Ransomware Report identifies 160 observed Spanish companies as victims of ransomware, a 19% increase on the previous year. Globally, the volume of data stolen in these attacks has grown by more than 275%.

CybersecuritySeintec team2-3 min read
Number of Corporate Ransomware Victims in Spain Rises 19%, According to Zscaler ThreatLabz

News summary

Zscaler has published new data from its ThreatLabz 2024 Ransomware Report. According to the company, the number of Spanish companies victimised by ransomware rose by 19% year-on-year to 160, placing Spain as the seventh most affected country among those analysed, accounting for more than 2% of observed cases.

The growth in Spain is similar to that of Germany (nearly 21%) and France (17%), and higher than that of Italy (7%). Globally, the report puts the volume of data exfiltrated in ransomware attacks at 896.2 terabytes, up more than 275% from the previous year.

Zscaler further highlights that 62% of individual victims held C-level or senior management positions, reflecting the attackers’ interest in accounts with privileges and decision-making authority.

The figures originate from a single vendor and the cases it observes, so they should be interpreted as a trend rather than a census. In any case, the trend is consistent: ransomware combines encryption with data theft, and recovery requires both backups and the ability to detect an intrusion before encryption occurs.

Source: El Obrero (Zscaler ThreatLabz) — 7 October 2026

Frequently Asked Questions

Do these figures represent all ransomware cases in Spain?
No. These are the cases Zscaler observed in its analysis. Many incidents are not made public, so the figures should be understood as a trend indicator.
Are backups sufficient to recover from a ransomware attack?
Backups allow for system recovery, but they do not prevent data exfiltration. That is why early detection and access control are also necessary.

Concepts mentioned in this article: Backup · Ransomware

Detection before encryption makes all the difference. At Seintec, we combine monitoring, endpoint protection, and immutable backups. Speak with our cybersecurity team.

Contact Seintec

Related service

Managed SOC and MDR

Continuous monitoring, detection and response to security incidents across endpoints, servers, network and identities.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.