Key Takeaways

  • Researchers examined how compromised employees’ roles and authority can support ransomware operators’ initial access and internal movement.
  • Elevated business access can make identity compromise as consequential as malware reaching an endpoint.
  • High victim volumes in 2025 reinforce the case for identity-focused controls, segmented access, and tested recovery plans.

Zscaler ThreatLabz has examined an often-overlooked stage of a real-world ransomware campaign: the compromise of individual employees whose access can provide a path into sensitive corporate systems.

Public reporting on ransomware incidents typically focuses on the final, visible damage. Systems stop working, stolen information appears on a leak site, or executives receive an extortion demand. The identity that gave an attacker an opening often receives far less attention.

That gap matters. Researchers identified victims associated with a campaign linked to a ransomware group known for obtaining initial access, stealing substantial amounts of corporate data, and selectively encrypting critical systems. The analysis considered who the compromised employees were and how their roles and authority could help an attacker penetrate further into a business.

The findings do not identify the ransomware group or provide a detailed breakdown of the affected roles, but the emphasis reflects a broader shift in how enterprises assess ransomware exposure. A compromised identity is not simply another infected device. It can carry application permissions, access to shared data, trusted relationships with colleagues, and the ability to approve or initiate business processes.

Attackers do not necessarily need the most senior person in a business; they need an identity with useful reach. An employee connected to important workflows, sensitive records, administrative functions, or external partners may offer more practical value than someone with an impressive title but narrowly constrained access.

This dynamic forces security teams to determine which identities would create the most damaging chain reaction if compromised.

The scale of ransomware activity makes that question more pressing. Check Point Research monitored 1,592 new victims across more than 85 active public leak sites in Q3 2025, compared with 1,607 in Q2 2025 and 1,270 in Q3 2024. The Q3 comparison represented roughly 25% year-over-year growth.

Separate research points in the same direction. Black Kite reported 6,046 publicly disclosed ransomware victims in 2025, up 24% from 4,893 in 2024. Breachsense tracked 7,307 companies claimed by ransomware groups during 2025, a 45% increase from 5,028 in 2024, with the U.S. accounting for 51.8% of the total.

Those measurements use different collection methods, so they should not be treated as interchangeable incident counts. Leak-site claims can also include errors, duplicate posts, or organizations that dispute an attacker’s account. Even with those caveats, the datasets indicate sustained pressure from a ransomware economy that includes frequently referenced groups such as LockBit, Clop, and AlphV.

Operationally sensitive sectors face particular exposure. Rapid7 found that services represented 44.4% of ransomware posts in Q2 2025, followed by healthcare at 10.6% and technology at 10.0%. These industries often depend on interconnected identities, time-sensitive operations, third-party access, and systems where prolonged downtime can quickly affect customers.

Paying an extortion demand does not necessarily end the risk, either. A CrowdStrike 2025 survey found that 78% of respondents had experienced ransomware in the preceding year, while 83% of paying victims were attacked again. That finding highlights the danger of restoring operations without closing the identity, access, or process weaknesses involved in the original intrusion.

For enterprise leaders, the practical response starts with mapping authority rather than merely counting accounts. Security teams can identify identities with access spanning multiple applications, review dormant privileges, restrict administrative activity, and apply stronger verification when users request unusual access or perform sensitive actions. Privileged-access controls, phishing-resistant authentication, endpoint monitoring, network segmentation, and rapid credential revocation can reduce an attacker’s room to maneuver.

A login may look legitimate in isolation while becoming suspicious when paired with a new device, abnormal download activity, or access to systems outside the employee’s usual workflow. Integrating identity, endpoint, network, and data signals can help defenders recognize that sequence earlier.

The NIST Cybersecurity Framework and CISA Ransomware Guide provide useful foundations for prevention, response, and recovery planning. However, recovery plans also benefit from exercises built around compromised people, not only encrypted servers, addressing what happens when a trusted employee’s credentials are used to access several systems at once.

Zscaler ThreatLabz plans to expand on these issues in the 2026 Ransomware Report, due within the next two months. This employee-centered approach offers a timely reminder: ransomware defense increasingly begins with understanding who holds meaningful access, how far that access extends, and how quickly it can be contained when trust is abused.