Key Takeaways
- Zscaler ThreatLabz tracked 351 victims across 334 organizations during a month-long ransomware campaign.
- Attackers prioritized managers with financial, operational, and organizational influence rather than focusing only on executives.
- The findings suggest identity security programs should account for business authority as well as technical privilege.
Ransomware operators are refining how they choose their human targets, and the corner office may no longer be the main prize. Research from Zscaler ThreatLabz indicates that attackers are increasingly pursuing managers who can approve payments, access sensitive records, coordinate business functions, or influence how quickly an employer responds to extortion.
During one month-long campaign, ThreatLabz tracked 351 victims across 334 organizations, according to reporting from The Register. Nearly two-thirds of those victims held manager-level positions or higher. Their average age was 46, while three-quarters worked in accounting and finance, sales, operations, human resources, or marketing. Half were employed in the industrial or IT sectors.
That profile matters more for what it says about authority than age. Workers in their forties and fifties are often established managers with broad access to employees, vendors, contracts, financial processes, and internal systems. Compromising one of those accounts can expose several routes through a business without requiring an attacker to breach the CEO or another highly monitored executive.
Zscaler describes this as "business privilege," which differs from the technical privilege commonly associated with administrators and system operators. Security programs tend to focus heavily on accounts that can install software, change configurations, or grant access. Attackers are also interested in the manager who approves invoices, oversees a supplier relationship, reviews customer information, or knows which executive will authorize an emergency payment.
An employee does not need domain administrator rights to create substantial leverage. A finance manager may understand payment workflows. An HR leader may hold sensitive personnel records. An operations manager may know which systems could halt production. A sales leader may control customer communications and account data. Each role presents a different pressure point.
"The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns," the threat analysts wrote. "Rather than targeting executives directly, attackers are increasingly focusing on managers and other key personnel with the authority or influence to accelerate payment decisions."
Attackers can build those target lists by combining information taken from compromised systems with publicly available details. Corporate websites, professional profiles, job descriptions, email signatures, calendars, shared documents, and organizational charts can help reveal reporting relationships. Who approves invoices? Who manages a critical vendor? Who reports to the chief financial officer? Those details can turn a generic intrusion into tailored social engineering.
More than a dozen affected organizations reported that multiple employees were compromised during the campaign. That suggests the operators did not stop after gaining one foothold. Instead, they appeared to move among business functions, gathering data and reaching additional people who could strengthen the extortion attempt. Limiting lateral movement therefore applies to ordinary business identities as well as conventional administrator accounts.
The findings arrive amid sustained ransomware activity. Broadcom's 2026 analysis counted 4,737 attacks claimed in 2025, the highest total recorded. Specialist coverage from Infosecurity Magazine and SCWorld also reflects the continuing operational pressure from active ransomware groups, including their focus on sectors holding regulated, commercially sensitive, or time-critical data.
According to the firm's data, ransomware attempts blocked across its cloud platform rose 146% over the past year. Public extortion cases increased 70%, while the amount of data stolen from victims climbed 92%. Those figures point toward a model centered increasingly on data theft and coercion, with encryption serving as one component rather than the entire attack.
For security leaders, the practical shift is to map business authority alongside system permissions. Strong authentication, segmented access, unusual-login detection, payment verification, tested incident procedures, and restrictions on cross-functional data access can reduce exposure. Managers also need role-specific training that reflects the information and decisions attackers are likely to exploit. By the time encryption becomes visible, the intruder may already understand the reporting chart, the payment chain, and exactly whom to pressure.
⬇️