Zscaler Finds Ransomware Crews Targeting Managers Over the C-Suite
New Zscaler ThreatLabz research finds a ransomware campaign targeted manager-level employees for their business authority instead of executives for their titles.
Zscaler’s ThreatLabz research team says a single ransomware campaign it tracked over one month skipped past chief executives almost entirely and went after managers instead. Analyzing 351 victims across 334 organizations, ThreatLabz found that 62 percent held manager-level titles or higher, a pattern first reported by The Register on Sunday.
Table Of Content
In a blog post published August 6, ThreatLabz Senior Director of Threat Intelligence Brett Stone-Gross described the work as an early look at how a real-world ransomware attack unfolds, tracing victims tied to a single ransomware group the post did not name beyond calling it one “known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems.” The findings are a preview of the Zscaler ThreatLabz 2026 Ransomware Report, due within the next two months.
Business Privilege, Not Just Technical Privilege
Security teams typically define a privileged account by its system permissions: administrator rights, elevated access to servers or databases. Zscaler’s research points to attackers pursuing a different kind of privilege entirely. As the ThreatLabz team put it: “The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units.” None of that shows up on a list of admin credentials.
That framing lines up with who ThreatLabz actually found in the victim pool. Roughly three-quarters of the 351 victims worked in accounting and finance, sales, operations, human resources, or marketing, the kind of roles that routinely touch invoices, contracts, and payroll. Half worked at companies in the industrial or information technology sectors. More than a dozen of the 334 affected organizations had multiple employees compromised; The Register’s reporting read that as attackers working their way through several business functions once inside a network rather than stopping at the first foothold.
Mapping the Org Chart Before Striking
According to The Register, the attackers behind the campaign are not blasting a single extortion email to everyone in an organization and hoping it lands. Instead, they combine information already sitting on compromised systems with publicly available data to reconstruct reporting lines, then target the specific employees most able to influence whether a ransom gets paid. Zscaler described the shift bluntly: “The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns. Rather than targeting executives directly, attackers are increasingly focusing on managers and other key personnel with the authority or influence to accelerate payment decisions.”
The victim pool also skewed heavily toward one generation: 44 percent were Gen Xers, with an average age of 46 across a range The Register put at 23 to 70 years old. Zscaler tied that less to age itself than to career stage, since workers in their forties and fifties are more likely to have reached the kind of established management roles that carry real budget and vendor authority, giving attackers a path to valuable systems and decision-making power without ever needing to compromise the executive suite.
Part of a Bigger Extortion Trend
The Register also cited broader Zscaler figures showing the shift toward extortion extends well beyond this one campaign: ransomware attempts blocked across Zscaler’s cloud platform rose 146 percent over the past year, publicly listed extortion cases climbed 70 percent, and the volume of data stolen from victims grew 92 percent. Encryption alone, in other words, is increasingly just one part of the pressure campaign rather than the whole attack.
For security teams, the practical implication is that hardening admin accounts is no longer enough on its own. A manager’s ordinary day-to-day authority to approve an invoice, sign off on a vendor contract, or pull a personnel file is now something attackers plan around before they ever send a ransom note. Zscaler says the full ThreatLabz 2026 Ransomware Report, due within the next two months, will expand on victim profiles, tactics, and the wider trends behind this campaign.








No Comment! Be the first one.