Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops
Recent ransomware campaigns are increasingly targeting 40-something IT managers rather than executives, according to Zscaler's ThreatLabz researchers. In a month-long study of 351 victims across 334 organizations, nearly two-thirds of victims held manager-level titles or higher, with an average age of 46. The attackers' prey primarily worked in accounting and finance, sales, operations, HR, or marketing, as well as industrial or IT sectors.
Instead of sending a generic extortion email to the entire organization, the attackers conduct thorough research to identify the most influential employees who can expedite payment decisions. This shift in tactics highlights a growing emphasis on "business privilege" over technical privilege. Managers possess access to sensitive data such as invoices, payment approvals, budgets, contracts, customer accounts, HR records, and other critical business processes.
The prevalence of compromised managerial accounts suggests that the attackers are content with multiple footholds within the network and work their way through different departments to maximize the chances of reaching valuable data and decision-makers. The ransomware landscape is evolving from indiscriminate attacks to highly targeted extortion campaigns.
Ransomware attempts blocked across Zscaler's cloud platform increased by 146% in the past year, while public extortion cases rose by 70%, and the volume of data stolen from victims climbed by 92%.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.