Ransomware Crews Have Done Their Homework: It's the IT Manager They Want
Forget the corner office. Ransomware gangs have apparently decided that the 46-year-old IT manager with budget authority is a far more useful target than the CEO.
That conclusion comes from Zscaler's ThreatLabz team, which spent a month tracking a single ransomware campaign across 334 organisations, covering 351 individual victims. The numbers paint a fairly precise portrait of who these attackers are going after, and why.
Close to two-thirds of victims held manager-level titles or above. The average age was 46. Three-quarters worked in accounting, finance, sales, operations, HR, or marketing. Half were in the industrial or IT sectors. This is not random.
Attackers are reportedly combining data harvested from compromised systems with publicly available information to build org charts and identify who can actually move a payment decision. The goal isn't necessarily to reach the most powerful person in the building. It's to reach the most useful one.
Zscaler describes this as targeting 'business privilege' rather than technical privilege. Security teams have spent years obsessing over admin rights and privileged access management. Ransomware crews, meanwhile, are quietly mapping who approves invoices, who manages vendor contracts, who can greenlight a six-figure transaction without escalating to the board.
'The value of a compromised managerial account lies in the breadth of business access associated with the position,' the researchers noted. Managers sign things off. They sit across multiple business units. They have context and authority, without the scrutiny that typically surrounds C-suite accounts.
The Gen X skew is worth noting. Workers in their forties and early fifties are disproportionately likely to have reached mid-to-senior management without necessarily carrying the same security profile as executives. They're senior enough to matter, not so senior that every action triggers a compliance alert.
The campaign also showed attackers weren't satisfied with a single point of compromise. More than a dozen organisations had multiple employees hit, suggesting a deliberate strategy of spreading laterally through different business functions rather than camping on one account and hoping for the best.
The broader picture Zscaler paints is one where encryption is almost a side note. Ransomware attempts blocked on its platform jumped 146 percent over the past year. Public extortion cases were up 70 percent. Data exfiltration volumes rose 92 percent. The business model has quietly shifted: steal the data, threaten to publish it, and use your knowledge of the victim's internal structure to squeeze someone with the authority to actually write a cheque.
By the time anyone sees a ransom note, the attackers already know who reports to whom, who controls the budget, and who would be most embarrassed by a data leak. The encryption is almost theatrical at that point. The real work happened weeks earlier.