Zscaler: ransomware gangs now target middle managers, not the CEO

Zscaler: ransomware gangs now target middle managers, not the CEO

Zscaler's ThreatLabz researchers studied 351 victims across 334 organizations compromised during a single ransomware campaign that ran for one month, and found a strikingly specific victim profile. Nearly two-thirds of the victims held manager-level positions or above, the average victim was 46 years old, and three-quarters worked in accounting/finance, sales, operations, HR, or marketing; half worked in industrial or IT sectors. Rather than mass-distributing extortion emails, the attackers conduct reconnaissance using compromised system data combined with public information to map organizational hierarchies before striking. Zscaler said the ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns, with attackers focusing on managers and other key personnel who have the authority or influence to accelerate payment decisions. The strategy targets what the researchers call "business privilege": access to invoices, payment approvals, budgets, supplier contracts, customer accounts, and HR records, rather than technical administrative privileges. The researchers explained that the value of a compromised managerial account lies in the breadth of business access tied to the position. The concentration of victims in the Gen X age bracket is deliberate: workers in their forties and fifties typically hold established management roles, giving attackers access to valuable systems, sensitive information, and decision-making authority without having to compromise the C-suite directly. More than a dozen organizations reported multiple employee compromises, which the researchers say indicates attackers are systematically working through different business functions to maximize their chances of reaching valuable data and ransom-influencing staff. The wider report also shows the ransomware ecosystem leaning harder on extortion over encryption alone: ransomware attempts blocked across Zscaler's cloud platform rose 146 percent annually, public extortion cases rose 70 percent, and stolen data volumes climbed 92 percent.

Key facts

  • Zscaler's ThreatLabz analyzed 351 victims across 334 organizations from one ransomware campaign spanning a single month
  • Nearly two-thirds of victims held manager-level positions or above, with an average age of 46
  • Three-quarters worked in accounting/finance, sales, operations, HR, or marketing; half worked in industrial or IT sectors
  • Attackers target 'business privilege', access to invoices, payment approvals, budgets, supplier contracts, customer accounts, and HR records, rather than admin credentials
  • Zscaler's cloud platform saw ransomware attempts rise 146 percent annually, public extortion cases rise 70 percent, and stolen data volumes climb 92 percent

Why it matters

The finding marks a documented shift in ransomware tradecraft: attackers are moving away from broad, indiscriminate extortion emails toward reconnaissance-driven targeting of specific employees who can approve payments or access sensitive business processes, rather than technical administrators or top executives.

Who it affects

Mid-level managers in accounting, finance, sales, operations, HR, and marketing are the primary targets, according to the data; industrial and IT sector staff account for about half of the victims studied. The single campaign Zscaler analyzed affected 334 organizations in total.

How to use it

Security teams reviewing access controls can use this research to reconsider who holds 'business privilege', payment approval rights, budget access, supplier and customer account control, and HR record access, since these are now explicit attacker targets independent of technical admin rights. More than a dozen organizations in the dataset had multiple employees compromised, suggesting attackers probe several business functions rather than stopping at the first foothold.

How solid is it

The figures come from a named vendor, Zscaler, and its ThreatLabz research team, drawn from analysis of one specific month-long campaign plus broader annual trend data (146 percent rise in blocked ransomware attempts, 70 percent rise in public extortion cases, 92 percent rise in stolen data volumes) from Zscaler's own cloud platform telemetry. No independent replication is cited in the reporting, and the campaign is not named.

Risks and caveats

The article does not name the ransomware gang or group behind the analyzed campaign, does not identify the calendar month it took place in, does not name any victim organizations, and gives no figures for ransom amounts demanded or paid. As with any vendor-produced threat research, the data reflects what Zscaler's own platform observed and may not generalize beyond its customer base.

“Value of a compromised managerial account lies in the breadth of business access associated with the position”

— ThreatLabz researchers, Zscaler