Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Ransomware Gangs Are Now Hunting Managers, Not Just IT Admins, Zscaler Research Finds

Ransomware gangs used to go after system administrators and IT staff first. Attackers are now increasingly targeting managers instead.
Zscaler's ThreatLabz threat intelligence unit analyzed the early stages of one real-world ransomware campaign and found something specific: attackers are targeting managers, not the tech department, according to research published as part of the company's upcoming ThreatLabz 2026 Ransomware Report.
Over the course of one month, ThreatLabz identified 351 victims across 334 organizations hit by this single campaign. That's a wide net for one operation.
The numbers tell the story
Of the employees targeted, 62% held manager-level titles or higher, according to Zscaler. That's the headline number, and it represents a meaningful shift from the old playbook of chasing domain admins and help-desk credentials.
Roughly three-quarters of the targeted managers worked in accounting and finance, sales, operations, human resources, or marketing, ThreatLabz found. These aren't the people running the network. They're the people running the budget, the deal pipeline, or the hiring process.
Half of the affected organizations were in the industrial or information technology sectors, according to the research. In more than a dozen of the organizations, attackers targeted multiple employees at once, not just a single point of entry.
Why managers, specifically
The logic here isn't complicated. Zscaler's researchers point to two reasons attackers have shifted their sights up the org chart.
First, managers carry higher network and business privileges than a typical employee. They can access sensitive financial records, HR files, and client data that a front-line worker simply doesn't touch.
Second, managers approve things. They sign off on payments, oversee budgets, review contracts, and coordinate across departments. A compromised manager's account isn't just a foothold. It's a lever attackers can pull to move laterally into other business units and other people's inboxes.
That combination, according to ThreatLabz, makes a manager's credentials more valuable to an attacker than a random employee's, and in many cases more valuable than a low-level IT account that only unlocks technical systems.
What the campaign actually did
The group behind this specific campaign followed a familiar three-step pattern, per Zscaler: get initial access, steal a large volume of corporate data, then encrypt select critical systems. That's the standard double-extortion model—ransomware, plus theft, plus the threat of leaking the stolen data if the ransom isn't paid.
ThreatLabz documented four real victim examples from the campaign to illustrate how the targeting played out in practice, though the research doesn't name the specific companies involved.
What the report recommends
ThreatLabz offers six recommendations for organizations trying to protect their managers from becoming the entry point for one of these attacks. The core themes, based on the research, center on limiting how much access any single manager account can have, monitoring for unusual login or data-transfer behavior tied to privileged accounts, and training managers specifically, not just IT staff, on phishing and credential-theft tactics because they're the ones now in the crosshairs.
What's still unclear
The research is drawn from one campaign, not the entire ransomware landscape, so it's a data point rather than a universal law. Whether this manager-targeting pattern holds across other ransomware groups and other reporting periods is something the full ThreatLabz 2026 Ransomware Report, still forthcoming, will need to address with broader data.
The category "manager-level or higher" is also broad. The research doesn't break down how many of the 62% were, say, a regional sales manager versus a CFO, which matters for understanding exactly how much damage a single compromised account could do.
For any company that assumes ransomware is an IT problem to be solved by the security team alone, this research offers a pointed correction. The accounting manager approving vendor payments and the sales director sitting on the customer database are now targets just as much as the domain admin, according to Zscaler's findings, and their training and access controls need to reflect that.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.