惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
GbyAI
GbyAI
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 叶小钗
A
About on SuperTechFans
M
MIT News - Artificial intelligence
宝玉的分享
宝玉的分享
雷峰网
雷峰网
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Martin Fowler
Martin Fowler
Google DeepMind News
Google DeepMind News
博客园 - Franky
B
Blog RSS Feed
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
罗磊的独立博客
Apple Machine Learning Research
Apple Machine Learning Research

Security Research | Blog

Operation RapidRust: New APT36 Malware Tools | ThreatLabz SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabz Microsoft Exchange Vulnerability: What Admins Should Do C2Looper Backdoor Uses GitHub for C2 | ThreatLabz Midnight Blizzard launches CaptiveCrunch | ThreatLabz ChainDrop NPM Worm Analysis | ThreatLabz Abyssos Modular RAT Analysis | ThreatLabz Frontier AI and Enterprise Readiness | Zscaler Targeted Attack on Middle East Govts (Part 2) | ThreatLabz Technical Analysis of GoGRPC | ThreatLabz Targeted Attack on Middle East Govts (Part 1) | ThreatLabz ClaudeFix: Shared Claude Chats Meet ClickFix | Zscaler Why Do F1 Teams Need Cybersecurity, and What Is AI’s Role? Indirect Prompt Injection Targets AI Agents | ThreatLabz Splunk Enterprise RCE (CVE-2026-20253) | ThreatLabz Edgecution: Malicious Edge Extension Backdoor | ThreatLabz SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler Shai-Hulud: Miasma, Hades, & AI Scanner Evasion | ThreatLabz Zscaler ThreatLabz 2026 Phishing and Initial Access Report Technical Analysis of MLTBackdoor | ThreatLabz When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing | Zscaler OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz Tropic Trooper: AdaptixC2 + Custom Beacon | ThreatLabz Do not delete blog (testing) | Zscaler Payouts King Takes Aim at the Ransomware Throne | ThreatLabz The Alibaba Incident and Why Zero Trust Matters More Than Ever In-Memory Loader Drops ScreenConnect | ThreatLabz Supply Chain Attacks Surge in March 2026 | ThreatLabz
Ransomware Victims Research | ThreatLabz
Brett Stone-Gross · 2026-08-06 · via Security Research | Blog

Zscaler Blog

Get the latest Zscaler blog updates in your inbox

When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets.

New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization.

This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next.

Key Findings At a Glance

Over a one-month period, ThreatLabz identified 351 victims across 334 organizations linked to a single ransomware campaign.

  • 62% of victims held manager-level titles or higher
  • Roughly 75% of victims worked in accounting and finance, sales, operations, human resources, or marketing
  • 44% of victims were members of Generation X; the average victim age was 46
  • 50% worked for companies in the industrial or information technology sector
  • More than a dozen organizations had multiple employees compromised

The Common Denominators: Management, Money, and Business Access

The findings suggest the victims were not selected at random. A majority held managerial positions or worked in business areas that may provide useful access for establishing a foothold, reaching additional users and systems, stealing sensitive information, and increasing pressure through data extortion and encryption.

Manager-level employees were most targeted: 62%

Nearly two-thirds of victims had managerial titles or above. Security teams often define privileged users as administrators and others with elevated access. Ransomware attackers also pursue employees with business privilege—access and authority created by their roles and relationships.

The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units.

Gen X represented the largest share of victims: 44%

Victims ranged from 23 to 70 years old, with an average age of 46. The larger share of Gen X victims may be less about age itself and more about where many are in their careers. Gen X employees are more likely to hold established managerial or higher-level positions described above, giving attackers access to valuable systems, data, and decision-making authority.

Most victims worked in five core business areas: 75%

Roughly three-quarters of victims worked in five business functions: accounting and finance, sales, operations, human resources, and marketing.

ThreatLabz research ransomware victims business function

Accounting and finance (17.7%) employees may have access to invoices, payments, approvals, banking details, and vendor records. Sales (17.4%) teams work with customer accounts, pricing, contracts, and active deals. Operations (16.8%) teams often coordinate across suppliers and business units. Compromised users in these roles can give attackers insight into sensitive data including financial information, payment systems, and contracts that are critical to the organization.

Half of victims worked in industrials or IT: 50%

The industry breakdown of victims spans several sectors, with industrials and IT representing 35.5% and 14.6%, respectively.

Image

For ransomware groups, employees in industrial organizations may provide paths to critical systems that support manufacturing, distribution, or logistics. In information technology, compromised accounts may expose intellectual property and platforms used to deliver digital services. Disrupting these systems can quickly create both operational and financial pressure. Encrypting a production, logistics, or service delivery platform could disrupt business activity and revenue, while stolen operational or technical data could be used to strengthen extortion demands.

What the Victims Look Like

The following profiles are real-world examples of the victims represented in the research.

Regional Sales Manager
Industry: Industrials
Why the role may be targeted: Access to customer accounts, contracts, pricing, revenue forecasting, and sales communications, jeopardizing major orders and service or equipment contracts and putting customer relationships and revenue at risk.  

Accounts Payable Manager
Industry: Information Technology
Why the role may be targeted: Access to invoices, payment data, financial approvals, and vendor records, potentially disrupting payments to critical suppliers and affecting the delivery of technology products and services across the business. 

Senior Project Manager
Industry: Consumer Discretionary
Why the role may be targeted: Access to project budgets, roadmaps, and sensitive files or documents, delaying product launches or location openings, increasing project costs, and causing the business to miss critical revenue opportunities.

Property Manager  
Industry: Real Estate 
Why the role may be targeted: Access to lease agreements, vendor invoices, contracts, client data, and financial information, creating potential for tenant service interruptions, legal exposure, and loss of property income.

These employees do not need administrator rights to create serious business exposure. Their everyday access can provide attackers with a path to sensitive data, financial and operational processes, enterprise applications, and internal communications.

Strengthen Ransomware Defenses Around Manager Roles

Managerial roles require protections that address how attackers approach employees and what they can access after an account is compromised. As AI makes reconnaissance, personalization, and impersonation faster and more convincing, ransomware actors can target these employees with fewer obvious warning signs. To this end, key priorities for security teams include: 

  • Restrict external communications on collaboration platforms. Block unsolicited messages and calls from external users on platforms such as Microsoft Teams and Slack.
  • Prepare employees for impersonation attempts. Train users to verify unusual requests from purported IT personnel through trusted internal communication channels and company directory information before taking action.  
  • Deploy inline network threat and endpoint security protection. Use AI-powered network and endpoint detection solutions to identify malicious content, suspicious behavior, and attack activity before it can progress.
  • Continuously monitor activity for signs of compromise. Look for unusual behavior across users, devices, applications, data transfers, and remote access tools. In this campaign, more than a dozen organizations had multiple victims, underscoring the need to monitor and investigate beyond the first affected account.
  • Enforce least-privilege access. Limit each employee’s access to the applications, systems, and data required for their role, reducing what attackers can reach through a compromised account.  
  • Implement a Zero Trust architecture to contain attacks. Segment access to prevent attackers from moving laterally and reaching additional systems after gaining an initial foothold.

Stay Tuned: More Ransomware Research Ahead

Understanding which employees ransomware groups are targeting provides important insight into where business access creates exposure. It also reveals where stronger protections are needed to prevent one compromised account from leading to data theft, encryption, or wider disruption.

View the brief for an at-a-glance summary of the findings in this research.

Follow ThreatLabz on X and our security research blog to stay informed about the latest threat discoveries, campaign analysis, and security insights.

Watch for the upcoming ThreatLabz 2026 Ransomware Report to learn more about the victims in this campaign, along with in-depth research on ransomware activity over the past year, the groups driving it, evolving data theft and extortion trends, and more.

form submtited

Thank you for reading

Was this post useful?

Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.

Explore more Zscaler blogs

A person typing at their computer

Latest Xloader Obfuscation Methods and Network Protocol

An eye peering from inside a cloud.

Technical Analysis of GuLoader Obfuscation Techniques

Multiple purple and pink blocks.

Technical Analysis of MLTBackdoor

Get the latest Zscaler blog updates in your inbox

By submitting the form, you are agreeing to our privacy policy.