Skip to content

Notes ·

Ransomware Gangs Learned to Target the Org Chart

The Register reports on a notable change in how ransomware groups choose their victims.

They are optimizing for return on investment.

Zscaler ThreatLabz analyzed 351 victims across 334 organizations connected to one ransomware campaign over a single month. 62 percent held manager-level positions or higher, and the average victim was 46 years old.

But these attackers are not simply hunting administrators with powerful technical accounts.

They are looking for what Zscaler calls business privilege.

About 75 percent of victims worked in accounting and finance, sales, operations, HR or marketing. These are people who may approve payments, manage vendors, access contracts, know customers and suppliers, or influence how a company responds during a crisis.

That makes a manager potentially more valuable than the CEO.

Executives tend to receive additional security attention. A mid-level manager may have broad access to important information, understand how money moves through the company and still be reachable through ordinary email, Teams, Slack or other systems.

Attackers are also researching organizations before striking. They can combine public information with data gathered during an intrusion to understand reporting structures and identify the people most useful for increasing pressure on the company. More than a dozen organizations in Zscaler's sample had multiple employees compromised.

That is a notable evolution in ransomware.

The goal is no longer simply:

Find the computer with the most permissions.

It is increasingly:

Find the human who gives the intrusion the most business leverage.

Cybercrime is becoming more professionalized in exactly the way we should expect. Ransomware groups are studying organizations, identifying valuable roles and concentrating their effort where the expected return is highest.

Unfortunately, they appear to be getting better at running their businesses too.

Read “Ransomware gangs skip the CEO, head straight for the 40-something IT manager.”

Read the Zscaler ThreatLabz research.

All notes