Ransomware gangs skip the CEO to target 40-something managers

Ransomware gangs skip the CEO to target 40-something managers

Want a payout fast? Don't email the CEO—phish the 46-year-old manager who actually holds the keys.

Security researchers at Zscaler tracked a month-long campaign that hit 351 victims across 334 organizations. Instead of spraying phishing emails at C-level executives, attackers mapped out internal reporting lines to target mid-level staff. Nearly two-thirds of victims held manager titles or higher, with an average victim age of 46.

Why it matters: Security teams usually focus on protecting root admin accounts and executive inboxes. But extortion syndicates are chasing "business privilege" over pure technical access. A compromised manager gives attackers direct visibility into invoices, vendor contracts, and budget approvals—the exact pressure points needed to speed up a payment decision.

Know this: Zscaler reports blocked ransomware attempts jumped 146% over the past year, while stolen data volume climbed 92%. In over a dozen targeted companies, attackers compromised multiple employees across different departments to widen their reach.

Next time you get a suspicious email, remember: the attackers probably read your LinkedIn before hitting send.