Ransomware gangs skip the CEO, head straight for the 40-something IT manager

Ransomware gangs are shifting their focus from CEOs to mid-level IT managers who possess the authority to approve payments and access sensitive financial data. Researchers found that attackers now perform detailed reconnaissance to identify employees with the most influence over business operations.
Why it matters
This shift in cyberattack strategy forces organizations to rethink security protocols, moving beyond just protecting administrative accounts to securing business-critical managerial roles.
Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops
Turns out the fastest way to get a company to consider paying a ransom isn't calling the CEO – it's targeting the 46-year-old IT manager.
That's according to Zscaler , whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month.
The data suggests today's ransomware crews have become oddly specific about their preferred victim profile: nearly two-thirds of victims held manager-level titles or above, the average victim was a 46-year-old Gen Xer, and three-quarters worked in accounting and finance, sales, operations, HR, or marketing. Half worked in the industrial or IT sectors.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in