Ransomware operators increasingly target influential managers, Zscaler reports
Ransomware groups are increasingly selecting victims based on their influence over business decisions rather than targeting only senior executives or system administrators, according to research from...
Ransomware groups are increasingly selecting victims based on their influence over business decisions rather than targeting only senior executives or system administrators, according to research from Zscaler’s ThreatLabz team.
The researchers examined 351 victims at 334 organizations involved in one ransomware campaign during a single month. Almost two-thirds of the victims held management positions or higher, while the average age was 46. Approximately 75 percent worked in accounting and finance, sales, operations, human resources, or marketing. Industrial and information technology organizations together accounted for about half of the affected employers.
Zscaler said attackers appear to combine information gathered from compromised networks with publicly available material to understand organizational structures. That reconnaissance can help them identify employees who influence payment approvals, vendor relationships, budgets, contracts, customer accounts, or sensitive personnel records.
In this context, the researchers distinguish between technical privilege and what they call “business privilege.” An account does not need administrative access to be valuable if its owner can authorize spending, coordinate departments, or influence how an incident is handled. Established managers in their forties and fifties may offer particularly useful access to business processes and decision-makers without requiring a direct compromise of the executive team.
The investigation also found that more than a dozen organizations reported multiple employees being compromised. That pattern suggests some attackers expanded across business functions after gaining an initial foothold, potentially improving their access to data and increasing pressure on the victim organization.
Extortion beyond encryption
The findings align with a broader shift toward data theft and extortion, rather than relying solely on file encryption. Zscaler reported that ransomware activity blocked by its cloud platform rose 146 percent over the previous year. It also recorded a 70 percent increase in publicly disclosed extortion incidents and a 92 percent increase in the amount of data stolen from victims.
The report underscores the need for organizations to protect business-sensitive accounts as carefully as traditional privileged accounts. Access reviews, multifactor authentication, segmentation, monitoring for unusual account activity, and rehearsed incident-response plans can help reduce the impact of targeted ransomware operations.
