// ZDNET — CYBERSECURITY
Why managers are ransomware's top targets now - and 6 ways to stay safe
Follow ZDNET: Add us as a preferred source on Google.
Ransomware attacks don't just target specific organizations but also specific employees. Those employees are often the ones with special privileges or higher levels of access that attackers can exploit to reach confidential resources. That's why managers often end up being in the crosshairs of such attacks.
In new research, "Ransomware Moves up the Org Chart: Managers Are Prime Targets," Zscaler's ThreatLabz threat intelligence unit analyzed the early stage of a real-world ransomware attack. Part of Zscaler's upcoming ThreatLabz 2026 Ransomware Report, the research looked for details among one specific campaign to try to find common clues and signals.
Also: Why this fully agentic ransomware attack is giving researchers nightmares
The ransomware group that staged the campaign was known for capturing initial access, stealing a huge amount of corporate data, and then encrypting certain critical systems. Over a period of one month, ThreatLabz identified 351 victims across 334 organizations targeted by this single campaign.
The initial analysis did uncover several commonalities. Some 62% of the targeted employees held manager-level titles or higher. Around three-quarters of them worked in accounting and finance, sales, operations, human resources, or marketing. Half of the organizations were in the industrial or information technology sector. And multiple employees were targeted across more than a dozen of the organizations.
Cybercriminals target managers and other higher-level employees for a couple of reasons.
First, managers typically hold higher network and business privileges. That means they not only have access to sensitive records and resources but they also control different roles and relationships within the organization.
Also: What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
Second, they handle a variety of business tasks, including approving payments, overseeing budgets, reviewing contracts, and coordinating work across different departments. This means that a compromised managerial account can be used by the attacker to target different business units and employees.