New research from Zscaler ThreatLabz argues that ransomware operators are shifting their aim up the org chart, targeting mid-level managers who hold approval authority and business access.
In a blog post published August 6, ThreatLabz analyzed a single campaign over roughly one month and identified 351 compromised individuals across 334 organizations. The firm reports that 62% of those victims held manager-level titles or above, which it attributes to attackers chasing “business privilege” rather than IT-admin privilege alone.
The victims clustered in predictable places. About three-quarters worked in accounting and finance, sales, operations, HR, or marketing, and half of the affected organizations sat in the industrial or IT sectors. More than a dozen organizations had several employees compromised at once.
These numbers are single-sourced to Zscaler, and no outside researcher or law-enforcement body has corroborated the dataset. Zscaler also describes the post as a preview of a fuller ransomware report due in the next two months, so treat the figures as vendor threat intelligence rather than independent findings.
The security takeaway holds regardless. Access-governance programs built around executives and system administrators leave a gap if managers who approve payments, touch vendor and contract data, or bridge business units get lighter protection.
For CISOs, the practical move is to extend privileged-access assumptions down a tier. Phishing-resistant MFA, least-privilege enforcement, session monitoring, and targeted awareness training should reach manager roles in finance, sales, ops, HR, and marketing, and lateral-movement paths from a single manager account deserve a fresh review.
Source: Zscaler ThreatLabz



Leave a Reply