conv.

All stories
SecurityRunning 2d

Zscaler: Ransomware gangs target mid-level managers over executives

Research finds attackers increasingly focus on 46-year-old Gen X managers with business authority rather than C-suite executives.

Conversation activity · last 3 days peak 2/hr

Peak 2 items in one hour at Aug 9, 3 PM; 6 items over 3 days Aug 7, 12 PM — 1 itemAug 7, 1 PM — no itemsAug 7, 2 PM — no itemsAug 7, 3 PM — no itemsAug 7, 4 PM — no itemsAug 7, 5 PM — no itemsAug 7, 6 PM — no itemsAug 7, 7 PM — no itemsAug 7, 8 PM — no itemsAug 7, 9 PM — no itemsAug 7, 10 PM — no itemsAug 7, 11 PM — no itemsAug 8, 12 AM — no itemsAug 8, 1 AM — no itemsAug 8, 2 AM — no itemsAug 8, 3 AM — no itemsAug 8, 4 AM — no itemsAug 8, 5 AM — no itemsAug 8, 6 AM — no itemsAug 8, 7 AM — no itemsAug 8, 8 AM — no itemsAug 8, 9 AM — no itemsAug 8, 10 AM — no itemsAug 8, 11 AM — no itemsAug 8, 12 PM — no itemsAug 8, 1 PM — no itemsAug 8, 2 PM — no itemsAug 8, 3 PM — no itemsAug 8, 4 PM — no itemsAug 8, 5 PM — no itemsAug 8, 6 PM — no itemsAug 8, 7 PM — no itemsAug 8, 8 PM — no itemsAug 8, 9 PM — no itemsAug 8, 10 PM — no itemsAug 8, 11 PM — no itemsAug 9, 12 AM — no itemsAug 9, 1 AM — no itemsAug 9, 2 AM — no itemsAug 9, 3 AM — no itemsAug 9, 4 AM — no itemsAug 9, 5 AM — 2 itemsAug 9, 6 AM — no itemsAug 9, 7 AM — no itemsAug 9, 8 AM — no itemsAug 9, 9 AM — no itemsAug 9, 10 AM — no itemsAug 9, 11 AM — no itemsAug 9, 12 PM — no itemsAug 9, 1 PM — no itemsAug 9, 2 PM — no itemsAug 9, 3 PM — 2 itemsAug 9, 4 PM — no itemsAug 9, 5 PM — 1 itemAug 9, 6 PM — no itemsAug 9, 7 PM — no itemsAug 9, 8 PM — no itemsAug 9, 9 PM — no itemsAug 9, 10 PM — no itemsAug 9, 11 PM — no itemsAug 10, 12 AM — no itemsAug 10, 1 AM — no itemsAug 10, 2 AM — no itemsAug 10, 3 AM — no itemsAug 10, 4 AM — no itemsAug 10, 5 AM — no itemsAug 10, 6 AM — no itemsAug 10, 7 AM — no itemsAug 10, 8 AM — no itemsAug 10, 9 AM — no items 2 items · 3 PM
Aug 8Aug 9Aug 10

Summary, timeline and people extracted by Claude from 6 items across 4 sources · 15h ago. Quotes are verbatim.

Zscaler's ThreatLabz research tracked 351 victims across 334 organizations in a single ransomware campaign, finding that attackers are shifting from indiscriminate mass attacks to highly targeted extortion focusing on mid-level managers—particularly those in accounting, finance, sales, operations, HR, and marketing. Rather than targeting executives, gangs now research reporting structures and business processes to identify employees with payment approval authority and access to sensitive data, reflecting a strategic pivot from technical privilege to 'business privilege.'

  • Ransomware gangs have shifted from mass attacks to precisely targeted extortion campaigns, researching organizational hierarchies before striking.
  • Attackers now prioritize mid-level managers (average age 46) with business authority over C-suite executives, targeting those who approve payments and access sensitive data.
  • This represents a strategic move from pursuing 'technical privilege' (admin access) to 'business privilege' (decision-making authority in finance, HR, operations).
  • Ransomware ecosystem metrics show acceleration: 146% increase in blocked attempts, 70% rise in public extortion cases, and 92% growth in stolen data volumes over the past year.

How it unfolded

  1. Reaction Hacker News discussion begins

    The Register article gains traction on Hacker News with 58 points and 22 comments, attracting security-focused discussion.

  2. Report Zscaler releases targeting research findings

    Zscaler ThreatLabz publishes research on 351 victims across 334 organizations showing attackers target 46-year-old Gen X managers rather than executives.

  3. Report Key finding: 'Business privilege' over technical privilege

    Zscaler describes shift from targeting administrator-level technical access to targeting employees with business decision-making authority like payment approval and budget oversight.

    “The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns. Rather than targeting executives directly, attackers are increasingly focusing on managers and other key personnel with the authority…”

    Zscaler · Hacker News ↗
  4. Analysis Victim profile breakdown

    Nearly two-thirds held manager-level titles or above; three-quarters worked in accounting, finance, sales, operations, HR, or marketing; half in industrial or IT sectors.

  5. Analysis Attackers conduct detailed reconnaissance

    Gangs combine data from compromised systems with public sources to map reporting lines and identify employees most likely to influence payment decisions.

    “The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work…”

    Zscaler · Hacker News ↗
  6. Analysis Multi-victim compromise in single organizations

    More than a dozen organizations had multiple employees compromised, with attackers working through different business functions to reach valuable data and decision-makers.

  7. Analysis Broader ransomware ecosystem metrics

    Zscaler reports ransomware attempts blocked increased 146% year-over-year; public extortion cases rose 70%; stolen data volume climbed 92%.

  8. Report Context: Ransomware spike amid AI distraction

    The Register reports ransomware attacks spiking as the world focuses on AI development.

What people are saying verbatim

“The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns. Rather than targeting executives directly, attackers are increasingly focusing on managers and other key personnel with the authority or influence to accelerate payment decisions.”

Zscaler, Security research firm · The Register ↗ · Aug 8

“The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units.”

Zscaler, Security researcher · The Register ↗ · Aug 8

“Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops”

The Register/Carly Page, Security journalist · The Register ↗ · Aug 8