Why managers are ransomware's top targets now - and 6 ways to stay safe
Almost two-thirds of the victims targeted in a single ransomware campaign held managerial positions or higher.
Managers are frequently targeted by ransomware attacks due to their elevated network and business privileges. These employees often have access to sensitive data, handle critical business operations, and control various roles within an organization. A recent Zscaler study identified 351 victims across 334 organizations, with 62% of targeted employees holding manager-level titles or above.
These individuals work in sectors such as industrial, information technology, accounting, finance, sales, operations, human resources, and marketing. Managers' extensive responsibilities, including approving payments, overseeing budgets, and coordinating departmental activities, make them attractive targets for cybercriminals.
ThreatLabz, the threat intelligence unit of Zscaler, analyzed the initial stages of a real-world ransomware attack to understand the commonalities among the victims. The study revealed that 75% of the targeted employees worked in industries such as industrial, information technology, accounting and finance, sales, operations, human resources, and marketing.
The four primary roles targeted in the campaign were regional sales managers, accounts payable managers, senior project managers, and property managers. Each of these roles provides attackers with access to critical information, such as customer accounts, contracts, invoices, payment data, budgets, roadmaps, and lease agreements.
To prevent such attacks, organizations should implement several strategies. First, they should limit external communications via collaboration tools by blocking unsolicited messages on platforms like Microsoft Teams and Slack. Second, employees should be trained to recognize impersonation attempts from IT personnel, ensuring they verify unusual requests before taking action.
Third, organizations should employ AI-powered network and endpoint detection tools to identify malicious content, suspicious behavior, and potential attacks. Fourth, they should monitor signs of compromise, such as atypical actions and behaviors among users, devices, applications, data transfers, and remote access tools. Fifth, organizations should adopt a least-privilege access model, providing employees with access only to the applications, systems, and data necessary for their job functions.
Finally, a zero trust approach should be adopted, segmenting network access to prevent attackers from moving laterally and compromising additional systems after gaining initial access.
Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.