Ransomware crews are going after managers, not just admins

Ransomware coverage almost always starts after the encryption, with the systems locked and the ransom demanded. New research from Zscaler's ThreatLabz team looks at the other end of the attack, the employees compromised at the very start of it, and finds the crews aiming higher up the org chart than defenders tend to assume.

Over a one-month period, ThreatLabz identified 351 victims across 334 organizations linked to a single ransomware campaign, run by a group known for gaining initial access, stealing large amounts of corporate data and selectively encrypting critical systems. 62% of those victims held manager-level titles or higher.

Business privilege, not admin privilege

The point Brett Stone-Gross, senior director of threat intelligence at Zscaler, draws out is that security teams usually define a privileged user as an administrator or someone else with elevated system access. Ransomware attackers use a broader definition. A manager may approve payments, oversee budgets and vendors, review contracts, reach sensitive records and coordinate work across business units, all without holding a single elevated system permission. ThreatLabz calls this business privilege, and it is what makes such an account a useful foothold: it opens a path to more users and systems, to data worth stealing, and to extra leverage once the extortion starts.

The functional breakdown supports that reading. Roughly 75% of victims worked in five business areas: accounting and finance (17.7%), sales (17.4%), operations (16.8%), human resources and marketing. Finance staff hold invoices, payments, approvals, banking details and vendor records. Sales teams work with customer accounts, pricing, contracts and live deals. Operations coordinates across suppliers and business units.

Who the victims were

That last figure carries an operational lesson: in this campaign, finding one compromised account was not a reason to stop looking.

What you should do

ThreatLabz's recommendations focus on how these employees are approached and what a compromised account can then reach. Block unsolicited messages and calls from external users on collaboration platforms such as Microsoft Teams and Slack. Train staff to verify unusual requests from purported IT personnel through a trusted internal channel and the company directory before acting, a habit that matters more as AI makes reconnaissance, personalization and impersonation faster and more convincing. Enforce least-privilege access so each role reaches only what it needs. Watch for unusual behavior across users, devices, applications, data transfers and remote access tools, and segment access so an intruder cannot move laterally from that first foothold. IntelFusions recently covered an Interlock campaign that turns forensics tools against victims once such a foothold exists.

The findings are set out in Stone-Gross's write-up on the Zscaler blog, which says a fuller ThreatLabz ransomware report follows within the next two months.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions