As cited
Copy frozen at (site build).
ransomware
Ransomware Moves up the Org Chart: Managers Are Prime Targets
Zscaler ThreatLabz research on a single ransomware campaign identified 351 victims across 334 organizations, finding that 62% held manager-level titles or higher and 75% worked in accounting, finance, sales, operations, human resources, or marketing. Attackers deliberately target mid-to-senior employees with business authority rather than those with administrative privileges, exploiting roles that provide access to financial systems, customer data, contracts, and cross-functional resources. The research reveals that compromised managerial accounts serve as entry points for data theft and extortion rather than random infections.
Why it matters: Security teams must prioritize protection of manager-level and business-critical roles in accounting, finance, sales, and operations, since attackers target these positions specifically for access to financial approvals, vendor relationships, and sensitive business data that can accelerate extortion and encryption campaigns.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Ransomware Moves up the Org Chart: Managers Are Prime Targets
Zscaler ThreatLabz research on a single ransomware campaign identified 351 victims across 334 organizations, finding that 62% held manager-level titles or higher and 75% worked in accounting, finance, sales, operations, human resources, or marketing. Attackers deliberately target mid-to-senior employees with business authority rather than those with administrative privileges, exploiting roles that provide access to financial systems, customer data, contracts, and cross-functional resources. The research reveals that compromised managerial accounts serve as entry points for data theft and extortion rather than random infections.
Why it matters: Security teams must prioritize protection of manager-level and business-critical roles in accounting, finance, sales, and operations, since attackers target these positions specifically for access to financial approvals, vendor relationships, and sensitive business data that can accelerate extortion and encryption campaigns.
- Source published
- First seen by Cybersecurity Tracker