Ransomware gangs skip the CEO, head straight for the 40-something IT manager

← Back to the feed

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

The Register · 2 hours ago

A Zscaler ThreatLabz analysis of a month-long ransomware campaign found that attackers are increasingly bypassing chief executives and instead targeting mid-level managers, particularly those around 46 years old, who hold enough operational authority to influence a company's decision on whether to pay a ransom. Rather than sending indiscriminate extortion emails, criminal groups now combine data from compromised systems with publicly available information to map out reporting structures and pinpoint staff with what Zscaler terms "business privilege" – access to invoices, budgets, contracts and sensitive records – rather than technical or administrator-level access.

The research tracked 351 victims across 334 organisations, finding that nearly two-thirds held manager-level titles or higher, with three-quarters working in finance, sales, operations, HR or marketing, and half in the industrial or IT sectors. Zscaler noted the skew towards Gen X employees likely reflects that this age group has typically reached established management positions. The report also found that attackers often compromised multiple employees within a single organisation to widen their access, and pointed to a broader industry shift towards extortion, with blocked ransomware attempts up 146 per cent, public extortion cases up 70 per cent, and stolen data volumes up 92 per cent over the past year.

  • Ransomware gangs now target managers, not CEOs, for faster ransom decisions
  • Average victim is 46, working in finance, HR, sales or operations
  • Zscaler reports ransomware attempts up 146% and data theft up 92% yearly

Business Companies Cybersecurity Technology

Read the full article at the source →