When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets.New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization.This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. Key Findings At a GlanceOver a one-month period, ThreatLabz identified 351 victims across 334 organizations linked to a single ransomware campaign.62% of victims held manager-level titles or higherRoughly 75% of victims worked in accounting and finance, sales, operations, human resources, or marketing44% of victims were members of Generation X; the average victim age was 4650% worked for companies in the industrial or information technology sectorMore than a dozen organizations had multiple employees compromised The Common Denominators: Management, Money, and Business AccessThe findings suggest the victims were not selected at random. A majority held managerial positions or worked in business areas that may provide useful access for establishing a foothold, reaching additional users and systems, stealing sensitive information, and increasing pressure through data extortion and encryption. Manager-level employees were most targeted: 62%Nearly two-thirds of victims had managerial titles or above. Security teams often define privileged users as administrators and others with elevated access. Ransomware attackers also pursue employees with business privilege—access and authority created by their roles and relationships.The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units.Gen X represented the largest share of victims: 44%Victims ranged from 23 to 70 years old, with an average age of 46. The larger share of Gen X victims may be less about age itself and more about where many are in their careers. Gen X employees are more likely to hold established managerial or higher-level positions described above, giving attackers access to valuable systems, data, and decision-making authority. Most victims worked in five core business areas: 75%Roughly three-quarters of victims worked in five business functions: accounting and finance, sales, operations, human resources, and marketing.Accounting and finance (17.7%) employees may have access to invoices, payments, approvals, banking details, and vendor records. Sales (17.4%) teams work with customer accounts, pricing, contracts, and active deals. Operations (16.8%) teams often coordinate across suppliers and business units. Compromised users in these roles can give attackers insight into sensitive data including financial information, payment systems, and contracts that are critical to the organization. Half of victims worked in industrials or IT: 50%The industry breakdown of victims spans several sectors, with industrials and IT representing 35.5% and 14.6%, respectively.For ransomware groups, employees in industrial organizations may provide paths to critical systems that support manufacturing, distribution, or logistics. In information technology, compromised accounts may expose intellectual property and platforms used to deliver digital services. Disrupting these systems can quickly create both operational and financial pressure. Encrypting a production, logistics, or service delivery platform could disrupt business activity and revenue, while stolen operational or technical data could be used to strengthen extortion demands. What the Victims Look LikeThe following profiles are real-world examples of the victims represented in the research.Regional Sales ManagerIndustry: IndustrialsWhy the role may be targeted: Access to customer accounts, contracts, pricing, revenue forecasting, and sales communications, jeopardizing major orders and service or equipment contracts and putting customer relationships and revenue at risk. Accounts Payable ManagerIndustry: Information TechnologyWhy the role may be targeted: Access to invoices, payment data, financial approvals, and vendor records, potentially disrupting payments to critical suppliers and affecting the delivery of technology products and services across the business. Senior Project ManagerIndustry: Consumer DiscretionaryWhy the role may be targeted: Access to project budgets, roadmaps, and sensitive files or documents, delaying product launches or location openings, increasing project costs, and causing the business to miss critical revenue opportunities.Property Manager Industry: Real Estate Why the role may be targeted: Access to lease agreements, vendor invoices, contracts, client data, and financial information, creating potential for tenant service interruptions, legal exposure, and loss of property income.These employees do not need administrator rights to create serious business exposure. Their everyday access can provide attackers with a path to sensitive data, financial and operational processes, enterprise applications, and internal communications. Strengthen Ransomware Defenses Around Manager RolesManagerial roles require protections that address how attackers approach employees and what they can access after an account is compromised. As AI makes reconnaissance, personalization, and impersonation faster and more convincing, ransomware actors can target these employees with fewer obvious warning signs. To this end, key priorities for security teams include: Restrict external communications on collaboration platforms. Block unsolicited messages and calls from external users on platforms such as Microsoft Teams and Slack.Prepare employees for impersonation attempts. Train users to verify unusual requests from purported IT personnel through trusted internal communication channels and company directory information before taking action. Deploy inline network threat and endpoint security protection. Use AI-powered network and endpoint detection solutions to identify malicious content, suspicious behavior, and attack activity before it can progress.Continuously monitor activity for signs of compromise. Look for unusual behavior across users, devices, applications, data transfers, and remote access tools. In this campaign, more than a dozen organizations had multiple victims, underscoring the need to monitor and investigate beyond the first affected account.Enforce least-privilege access. Limit each employee’s access to the applications, systems, and data required for their role, reducing what attackers can reach through a compromised account. Implement a Zero Trust architecture to contain attacks. Segment access to prevent attackers from moving laterally and reaching additional systems after gaining an initial foothold. Stay Tuned: More Ransomware Research AheadUnderstanding which employees ransomware groups are targeting provides important insight into where business access creates exposure. It also reveals where stronger protections are needed to prevent one compromised account from leading to data theft, encryption, or wider disruption.View the brief for an at-a-glance summary of the findings in this research.Follow ThreatLabz on X and our security research blog to stay informed about the latest threat discoveries, campaign analysis, and security insights.Watch for the upcoming ThreatLabz 2026 Ransomware Report to learn more about the victims in this campaign, along with in-depth research on ransomware activity over the past year, the groups driving it, evolving data theft and extortion trends, and more.
[#item_full_content] When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets.New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization.This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. Key Findings At a GlanceOver a one-month period, ThreatLabz identified 351 victims across 334 organizations linked to a single ransomware campaign.62% of victims held manager-level titles or higherRoughly 75% of victims worked in accounting and finance, sales, operations, human resources, or marketing44% of victims were members of Generation X; the average victim age was 4650% worked for companies in the industrial or information technology sectorMore than a dozen organizations had multiple employees compromised The Common Denominators: Management, Money, and Business AccessThe findings suggest the victims were not selected at random. A majority held managerial positions or worked in business areas that may provide useful access for establishing a foothold, reaching additional users and systems, stealing sensitive information, and increasing pressure through data extortion and encryption. Manager-level employees were most targeted: 62%Nearly two-thirds of victims had managerial titles or above. Security teams often define privileged users as administrators and others with elevated access. Ransomware attackers also pursue employees with business privilege—access and authority created by their roles and relationships.The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units.Gen X represented the largest share of victims: 44%Victims ranged from 23 to 70 years old, with an average age of 46. The larger share of Gen X victims may be less about age itself and more about where many are in their careers. Gen X employees are more likely to hold established managerial or higher-level positions described above, giving attackers access to valuable systems, data, and decision-making authority. Most victims worked in five core business areas: 75%Roughly three-quarters of victims worked in five business functions: accounting and finance, sales, operations, human resources, and marketing.Accounting and finance (17.7%) employees may have access to invoices, payments, approvals, banking details, and vendor records. Sales (17.4%) teams work with customer accounts, pricing, contracts, and active deals. Operations (16.8%) teams often coordinate across suppliers and business units. Compromised users in these roles can give attackers insight into sensitive data including financial information, payment systems, and contracts that are critical to the organization. Half of victims worked in industrials or IT: 50%The industry breakdown of victims spans several sectors, with industrials and IT representing 35.5% and 14.6%, respectively.For ransomware groups, employees in industrial organizations may provide paths to critical systems that support manufacturing, distribution, or logistics. In information technology, compromised accounts may expose intellectual property and platforms used to deliver digital services. Disrupting these systems can quickly create both operational and financial pressure. Encrypting a production, logistics, or service delivery platform could disrupt business activity and revenue, while stolen operational or technical data could be used to strengthen extortion demands. What the Victims Look LikeThe following profiles are real-world examples of the victims represented in the research.Regional Sales ManagerIndustry: IndustrialsWhy the role may be targeted: Access to customer accounts, contracts, pricing, revenue forecasting, and sales communications, jeopardizing major orders and service or equipment contracts and putting customer relationships and revenue at risk. Accounts Payable ManagerIndustry: Information TechnologyWhy the role may be targeted: Access to invoices, payment data, financial approvals, and vendor records, potentially disrupting payments to critical suppliers and affecting the delivery of technology products and services across the business. Senior Project ManagerIndustry: Consumer DiscretionaryWhy the role may be targeted: Access to project budgets, roadmaps, and sensitive files or documents, delaying product launches or location openings, increasing project costs, and causing the business to miss critical revenue opportunities.Property Manager Industry: Real Estate Why the role may be targeted: Access to lease agreements, vendor invoices, contracts, client data, and financial information, creating potential for tenant service interruptions, legal exposure, and loss of property income.These employees do not need administrator rights to create serious business exposure. Their everyday access can provide attackers with a path to sensitive data, financial and operational processes, enterprise applications, and internal communications. Strengthen Ransomware Defenses Around Manager RolesManagerial roles require protections that address how attackers approach employees and what they can access after an account is compromised. As AI makes reconnaissance, personalization, and impersonation faster and more convincing, ransomware actors can target these employees with fewer obvious warning signs. To this end, key priorities for security teams include: Restrict external communications on collaboration platforms. Block unsolicited messages and calls from external users on platforms such as Microsoft Teams and Slack.Prepare employees for impersonation attempts. Train users to verify unusual requests from purported IT personnel through trusted internal communication channels and company directory information before taking action. Deploy inline network threat and endpoint security protection. Use AI-powered network and endpoint detection solutions to identify malicious content, suspicious behavior, and attack activity before it can progress.Continuously monitor activity for signs of compromise. Look for unusual behavior across users, devices, applications, data transfers, and remote access tools. In this campaign, more than a dozen organizations had multiple victims, underscoring the need to monitor and investigate beyond the first affected account.Enforce least-privilege access. Limit each employee’s access to the applications, systems, and data required for their role, reducing what attackers can reach through a compromised account. Implement a Zero Trust architecture to contain attacks. Segment access to prevent attackers from moving laterally and reaching additional systems after gaining an initial foothold. Stay Tuned: More Ransomware Research AheadUnderstanding which employees ransomware groups are targeting provides important insight into where business access creates exposure. It also reveals where stronger protections are needed to prevent one compromised account from leading to data theft, encryption, or wider disruption.View the brief for an at-a-glance summary of the findings in this research.Follow ThreatLabz on X and our security research blog to stay informed about the latest threat discoveries, campaign analysis, and security insights.Watch for the upcoming ThreatLabz 2026 Ransomware Report to learn more about the victims in this campaign, along with in-depth research on ransomware activity over the past year, the groups driving it, evolving data theft and extortion trends, and more.