Skip to content
Rush Commerce
Field Notes3 min read

Ransomware targets managers, not domain admins

Zscaler tracked 351 victims in one campaign: two-thirds were manager-level or above, average age 46, mostly in finance and ops. Business privilege is the new target.

The mental model most operators carry is that ransomware targets the person with root. New research says the opposite: attackers are going after the person who can approve a wire transfer. Zscaler's ThreatLabz team tracked a single extortion campaign for a month and found the victims were middle managers in finance and operations — not sysadmins, not the CEO.

What actually happened

The Register reported on August 9 on ThreatLabz data covering 351 victims across 334 organizations, tracked over one month in one campaign. The profile is specific enough to be useful:

  • Nearly two-thirds held manager-level titles or above. Not the C-suite. The layer under it.
  • The average victim was 46 years old.
  • Three-quarters worked in accounting and finance, sales, operations, HR, or marketing. A quarter, at most, sat in a technical function.
  • Half were in industrial or IT sector companies.

The method matters more than the demographics. Zscaler says attackers pull data off already-compromised systems, cross-reference it against public sources — LinkedIn, org charts, press releases — and build a map of who reports to whom. Then they pick the people who control budgets, vendor relationships, contracts, and payment approvals. Zscaler's Brett Stone-Gross has framed this as attackers pursuing business privilege rather than technical privilege.

That is a rational shift. Domain admin gets you the file server. The controller gets you the invoice, the banking portal, and the authority to tell accounts payable that the vendor changed their routing number.

Why ransomware targeting managers changes your access model

If you run a 15-person company, you do not have a domain admin. You have an office manager who has every password because it was faster that way. You are the exact shape this campaign is built for.

The fix is not more security awareness training. Training assumes the attacker sends something obviously wrong. This crew already knows the target's job title, their manager's name, and which vendor invoices they process. Their message will be correct.

Three things worth doing, in order.

Map business privilege, not admin privilege. Write down who can change bank details, approve payments, sign contracts, and export customer data. That list is your real target roster. It is almost never the same as your IT admin list, and almost nobody has written it down.

Put a mandatory second channel on money movement. Any change to payment details, any new vendor payee, any wire above a threshold you pick — confirmed by phone to a number you already had on file, not one in the request. This single control defeats most of what this campaign is trying to accomplish.

Reduce standing authority. The controller does not need permanent export rights on the customer database. Time-box it. Log it. The point is not distrust — it is that a compromised session should not inherit six years of accumulated permissions.

The uncomfortable part of this data is how ordinary the victims are. Age 46, ops or finance, manager title. That is not a security failure profile. That is a job description.

Key takeaways

  • Zscaler ThreatLabz tracked 351 victims across 334 organizations in one ransomware campaign over a single month
  • Nearly two-thirds were manager-level or above; the average victim was 46 and worked in finance, ops, sales, HR, or marketing
  • Attackers combine data from compromised systems with public sources to map reporting lines and find decision authority
  • The target is business privilege — payment approval, vendor relationships, contracts — not technical admin rights
  • Write down who can move money or export data, require out-of-band confirmation on payment changes, and time-box standing authority

Your finance approvals are a security control, whether you designed them that way or not. We build internal tools with role-scoped permissions, out-of-band approval steps on anything that moves money, and audit logs you can actually read. See how we scope access or have us review who can approve what.

Sources: The Register, SC Media.

  • #ransomware
  • #access-control
  • #extortion
  • #threat-intel
  • #small-business-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.