Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Oregon Housing Director Failed to Report Husband’s Related Business Interests — ProPublica

    October 2, 2026

    Brazil Election: Lula, Flávio Bolsonaro Vie for Swing Votes in Final Days

    October 2, 2026

    Did water levels at Yellowstone Lake drop 11 feet overnight?

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Oregon Housing Director Failed to Report Husband’s Related Business Interests — ProPublica
    • Brazil Election: Lula, Flávio Bolsonaro Vie for Swing Votes in Final Days
    • Did water levels at Yellowstone Lake drop 11 feet overnight?
    • Netanyahu warns of ‘very heavy price’ if any country found to be behind FlyDubai incident
    • Diesel : sous la pression des Etats-Unis, l’exécutif envisage de libérer une part importante de ses réserves – POLITICO
    • Polanski says he does not need to win ‘50/50’ byelection to stay Green leader | Green party
    • Tesla sustains its EV sales momentum despite US troubles
    • macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    Why managers are ransomware’s top targets now – and 6 ways to stay safe

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Technology No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Eugene Mymrin/ Moment via Getty Images

    Follow ZDNET: Add us as a preferred source on Google.


    ZDNET’s key takeaways

    • Managers were the prime targets in a single ransomware campaign.
    • Managers often have special privileges, making them tempting targets.
    • Training and network security are key to preventing such attacks.

    Ransomware attacks don’t just target specific organizations but also specific employees. Those employees are often the ones with special privileges or higher levels of access that attackers can exploit to reach confidential resources. That’s why managers often end up being in the crosshairs of such attacks.

    In new research, “Ransomware Moves up the Org Chart: Managers Are Prime Targets,” Zscaler’s ThreatLabz threat intelligence unit analyzed the early stage of a real-world ransomware attack. Part of Zscaler’s upcoming ThreatLabz 2026 Ransomware Report, the research looked for details among one specific campaign to try to find common clues and signals.

    Also: Why this fully agentic ransomware attack is giving researchers nightmares

    The ransomware group that staged the campaign was known for capturing initial access, stealing a huge amount of corporate data, and then encrypting certain critical systems. Over a period of one month, ThreatLabz identified 351 victims across 334 organizations targeted by this single campaign.

    Why do cybercrooks target managers?

    The initial analysis did uncover several commonalities. Some 62% of the targeted employees held manager-level titles or higher. Around three-quarters of them worked in accounting and finance, sales, operations, human resources, or marketing. Half of the organizations were in the industrial or information technology sector. And multiple employees were targeted across more than a dozen of the organizations.

    Cybercriminals target managers and other higher-level employees for a couple of reasons.

    First, managers typically hold higher network and business privileges. That means they not only have access to sensitive records and resources but they also control different roles and relationships within the organization.

    Also: What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    Second, they handle a variety of business tasks, including approving payments, overseeing budgets, reviewing contracts, and coordinating work across different departments. This means that a compromised managerial account can be used by the attacker to target different business units and employees.

    In its research, ThreatLabz identified four examples of real victims hit by this single campaign.

    1. Regional sales manager in an industrial company. This person was a target because they have access to customer accounts, contracts, pricing, revenue forecasting, and sales communications. With this type of account, an attacker can impact product and service orders and put customer relationships at risk.
    2. Accounts payable manager in the IT field. This type of manager was a prime victim as they have access to invoices, payment data, financial approvals, and vendor records. Here, an attacker could disrupt payments to suppliers, affecting the delivery of needed products and services.
    3. Senior project manager in a consumer company. This role can be targeted for its access to budgets, roadmaps, and sensitive files. Here, an attacker could delay product launches or openings of new locations, creating havoc with the company’s revenue sources.
    4. Property manager in real estate. In this role, a manager has access to lease agreements, vendor invoices, contracts, client data, and financial information. That means an attacker could create interruptions in service, expose the agency to legal problems, and impact property income.

    6 defenses against ransomware attacks

    To help protect your managers and your organization from targeted ransomware attacks, ThreatLabz offers the following six recommendations:

    1. Limit external communications via collaboration tools. Block any unsolicited, external calls and messages on such platforms as Microsoft Teams and Slack.
    2. Teach employees to spot impersonation attempts from IT. Make sure employees know how to verify unusual requests from alleged IT personnel before they follow any requests.
    3. Set up network threat and endpoint security protection. Use AI-powered network and endpoint detection tools to spot malicious content, suspicious behavior, and potential attacks.
    4. Be on the lookout for signs of compromise. Watch for atypical actions and behaviors among users, devices, applications, data transfers, and remote access tools. If one account is compromised, monitor for any similar activity that might hit other accounts.
    5. Adopt least-privilege access. Give each employee access only to the applications, systems, and data needed for their jobs. This limits what an attacker can do with a compromised account.
    6. Take a zero trust approach. Segment network access to stop attacks from moving laterally and hitting other systems after the initial access point.

    managers ransomwares Safe stay targets top ways
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Polanski says he does not need to win ‘50/50’ byelection to stay Green leader | Green party

    Tesla sustains its EV sales momentum despite US troubles

    If a data center is camouflaged in the woods, will anyone hate it?

    OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

    Election Deniers Think the GOP’s Terrible Midterm Polling Is a ‘Psyop’

    As fires spread, Indonesia’s rubber growers draw on traditional ways to fight back

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Oregon Housing Director Failed to Report Husband’s Related Business Interests — ProPublica

    October 2, 2026

    Brazil Election: Lula, Flávio Bolsonaro Vie for Swing Votes in Final Days

    October 2, 2026

    Did water levels at Yellowstone Lake drop 11 feet overnight?

    October 2, 2026

    Netanyahu warns of ‘very heavy price’ if any country found to be behind FlyDubai incident

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Oregon Housing Director Failed to Report Husband’s Related Business Interests — ProPublica

    October 2, 2026

    Brazil Election: Lula, Flávio Bolsonaro Vie for Swing Votes in Final Days

    October 2, 2026

    Did water levels at Yellowstone Lake drop 11 feet overnight?

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.