Why managers are ransomware's top targets now - and 6 ways to stay safe
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
- Managers were the prime targets in a single ransomware campaign.
- Managers often have special privileges, making them tempting targets.
- Training and network security are key to preventing such attacks.
Ransomware attacks don't just target specific organizations but also specific employees. Those employees are often the ones with special privileges or higher levels of access that attackers can exploit to reach confidential resources. That's why managers often end up being in the crosshairs of such attacks.
In new research, "Ransomware Moves up the Org Chart: Managers Are Prime Targets," Zscaler's ThreatLabz threat intelligence unit analyzed the early stage of a real-world ransomware attack. Part of Zscaler's upcoming ThreatLabz 2026 Ransomware Report, the research looked for details among one specific campaign to try to find common clues and signals.
Also: Why this fully agentic ransomware attack is giving researchers nightmares
The ransomware group that staged the campaign was known for capturing initial access, stealing a huge amount of corporate data, and then encrypting certain critical systems. Over a period of one month, ThreatLabz identified 351 victims across 334 organizations targeted by this single campaign.
Why do cybercrooks target managers?
The initial analysis did uncover several commonalities. Some 62% of the targeted employees held manager-level titles or higher. Around three-quarters of them worked in accounting and finance, sales, operations, human resources, or marketing. Half of the organizations were in the industrial or information technology sector. And multiple employees were targeted across more than a dozen of the organizations.
Cybercriminals target managers and other higher-level employees for a couple of reasons.
First, managers typically hold higher network and business privileges. That means they not only have access to sensitive records and resources but they also control different roles and relationships within the organization.
Also: What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
Second, they handle a variety of business tasks, including approving payments, overseeing budgets, reviewing contracts, and coordinating work across different departments. This means that a compromised managerial account can be used by the attacker to target different business units and employees.
In its research, ThreatLabz identified four examples of real victims hit by this single campaign.
- Regional sales manager in an industrial company. This person was a target because they have access to customer accounts, contracts, pricing, revenue forecasting, and sales communications. With this type of account, an attacker can impact product and service orders and put customer relationships at risk.
- Accounts payable manager in the IT field. This type of manager was a prime victim as they have access to invoices, payment data, financial approvals, and vendor records. Here, an attacker could disrupt payments to suppliers, affecting the delivery of needed products and services.
- Senior project manager in a consumer company. This role can be targeted for its access to budgets, roadmaps, and sensitive files. Here, an attacker could delay product launches or openings of new locations, creating havoc with the company's revenue sources.
- Property manager in real estate. In this role, a manager has access to lease agreements, vendor invoices, contracts, client data, and financial information. That means an attacker could create interruptions in service, expose the agency to legal problems, and impact property income.
6 defenses against ransomware attacks
To help protect your managers and your organization from targeted ransomware attacks, ThreatLabz offers the following six recommendations:
- Limit external communications via collaboration tools. Block any unsolicited, external calls and messages on such platforms as Microsoft Teams and Slack.
- Teach employees to spot impersonation attempts from IT. Make sure employees know how to verify unusual requests from alleged IT personnel before they follow any requests.
- Set up network threat and endpoint security protection. Use AI-powered network and endpoint detection tools to spot malicious content, suspicious behavior, and potential attacks.
- Be on the lookout for signs of compromise. Watch for atypical actions and behaviors among users, devices, applications, data transfers, and remote access tools. If one account is compromised, monitor for any similar activity that might hit other accounts.
- Adopt least-privilege access. Give each employee access only to the applications, systems, and data needed for their jobs. This limits what an attacker can do with a compromised account.
- Take a zero trust approach. Segment network access to stop attacks from moving laterally and hitting other systems after the initial access point.
