Ransomware groups target mid-level IT managers instead of CEOs
Zscaler reports that ransomware attackers are focusing on 46-year-old IT managers rather than senior executives to pressure companies into paying.
Zscaler’s ThreatLabz team observed a ransomware operation that infected 351 users in 334 organizations over a month, revealing a clear preference for mid-level managers. About two-thirds of the victims were managers, averaging 46 years old, and most worked in departments such as accounting, finance, sales, operations, human resources or marketing, with half in industrial or IT sectors. Rather than blasting the entire company, attackers combine data from compromised machines with publicly available information to chart reporting lines and pinpoint employees who can approve payments or contracts.
This strategy emphasizes “business privilege” - exploiting the broader business access of managerial accounts instead of traditional privileged technical accounts. The campaign often compromised multiple employees within the same firm, moving laterally to increase the chance of reaching decision-makers. Zscaler also noted a sharp rise in ransomware attempts, public extortion cases and stolen data volumes over the past year.
Why it matters
Understanding the new focus on managerial accounts helps organizations improve defenses against ransomware extortion.
In this story