Skip to content
Security Article

Ransomware's New Favorite Target Is Middle Management

Victim data and FBI advisories converge on a blind spot: broad access, thin scrutiny, mid-level accounts.

Ji-ho Choi
Ji-ho Choi
Security & Cloud Editor · Aug 9, 2026 · 4 min read
Ransomware's New Favorite Target Is Middle Management

Ransomware crews have quietly rebuilt their targeting model, and it doesn't point at the CEO. When Zscaler ThreatLabz researchers tracked a single ransomware campaign for one month, they counted 351 victims across 334 organizations — and nearly two-thirds of them held manager-level titles or above. The average victim was 46. The headline framing making the rounds is "they're coming for the IT manager," but the data says something more uncomfortable: three-quarters of those victims worked in accounting and finance, sales, operations, HR, or marketing. Attackers aren't hunting a job title. They're hunting what Zscaler calls business privilege — the approval authority and cross-department access that pools in the middle of the org chart.

That's a real shift, and it breaks an assumption baked into most security programs: that the people worth protecting hardest are executives and admins.

Why the middle of the org chart is the sweet spot

Think about what a mid-level finance or operations manager's account actually holds. Payment approval workflows. Vendor records. Shared mailboxes and drives that span teams. Enough organizational context to know who signs off on what. A CFO's account is heavily watched and lightly used day-to-day; a manager's account is lightly watched and touches everything.

The recon to find these people is trivially cheap now. Attackers cross-reference data from already-compromised systems with public sources — LinkedIn alone reconstructs most reporting structures — to map who can approve a payment or reset an account before sending a single message. That's the operational change worth internalizing: extortion campaigns that used to blast identical emails across a company are now front-loading targeting work, the way red teams always have.

The macro numbers frame why crews are investing in that precision. Zscaler's 2025 ransomware report logged a 146% year-over-year jump in blocked ransomware attempts, a 70% rise in public extortion cases, and exfiltrated data volumes nearly doubling to 238 TB across ten major groups. Encryption is increasingly optional; the business model is stolen data plus a credible threat, and the fastest path to both runs through someone with broad access who isn't treated as a VIP.

The IT-impersonation pincer

The manager-targeting data lands alongside a second, well-documented trend, and the two form a pincer. While some crews target managers directly, others impersonate IT to get to them. An FBI FLASH advisory from May 2026 (IC3) details Silent Ransom Group — also tracked as Luna Moth and UNC3753 — calling employees while posing as their own IT department, talking them into granting remote access, then running pure data-theft extortion against law firms and financial-services shops. No encryptor, no malware to detect. Just a convincing phone call.

None of this is new tradecraft so much as newly mainstream tradecraft. Scattered Spider used helpdesk impersonation — in both directions, calling the helpdesk as an employee and calling employees as the helpdesk — against MGM Resorts in 2023 and UK retailers in 2025, well-documented in CISA's advisory on the group. Black Basta affiliates spent 2024 email-bombing inboxes and then calling victims over Teams as "IT support" offering to fix the flood they'd caused. What's changed is who picks up the phone. A 46-year-old operations manager fields legitimate IT requests constantly, has the authority to make an exception, and has almost certainly never been through the exec-protection training the C-suite gets.

Your controls are aimed at the wrong floor

Most organizations defend the org chart at its two extremes. Executives get whaling awareness, impersonation monitoring on their names, sometimes dedicated account hardening. Rank-and-file staff get the annual phishing simulation with the fake package-delivery lure. The middle tier — people with real approval authority and sprawling access — typically gets neither, and their accounts accumulate permissions for years because nobody wants to break a workflow.

If you own identity or security engineering, the fixes are concrete and mostly unglamorous:

  • Kill the helpdesk trust gap in both directions. Password and MFA resets for any account with payment or admin privileges should require verification that a caller can't social-engineer — a callback to a number on file, a live video check against HR records, or an in-person or manager-confirmed flow. This is the single control that would have blunted Scattered Spider and Silent Ransom Group alike.
  • Move business-privileged users to phishing-resistant MFA. FIDO2 hardware keys or passkeys for everyone who can approve payments or touch HR data, not just domain admins. Push-based MFA is exactly what these vishing flows are built to defeat.
  • Lock down external access in Teams and Slack. Black Basta's Teams-call lure worked because external tenants could ring employees directly. Restrict external federation to allowlisted domains and alert on unsolicited external calls. The trade-off is real — vendor collaboration gets clunkier — but "anyone on the internet can start a Teams call with your AP manager" is not a defensible default.
  • Run least-privilege reviews on manager accounts, not just admin accounts. The whole reason these accounts are targets is accumulated cross-team access. Time-bound the exceptions.
  • Retarget your phishing simulations. If your sims never impersonate your own IT department or exercise a payment-approval pretext against the people who actually approve payments, you're rehearsing the wrong attack.

Genuine shift, with one caveat

The honest read: this is a real change in targeting economics, not vendor hype. The FBI advisory, the documented Scattered Spider and Black Basta playbooks, and Zscaler's victim demographics all point the same direction independently. The caveat is that the flagship dataset — 351 victims, one unnamed campaign, one month, one vendor's telemetry — is a narrow window, and Zscaler is selling the zero-trust remedy it prescribes. Treat the precise percentages as directional.

But the underlying logic doesn't need the stats to hold. Attackers go where access is broad and scrutiny is thin, and for years that's described middle management perfectly. The C-suite got bodyguards; the people who actually run the company got the annual training video. Ransomware crews noticed first.

Sources & further reading

  1. Ransomware gangs skip the CEO, head straight for the 40-something IT manager — theregister.com
  2. Ransomware Surges as Attempts Spike 146% Amid Aggressive Extortion Tactics — zscaler.com
  3. FBI FLASH: Silent Ransom Group Impersonating IT Personnel Through Social Engineering — ic3.gov
  4. Scattered Spider Cybersecurity Advisory AA23-320A — cisa.gov
Ji-ho Choi
Written by
Ji-ho Choi · Security & Cloud Editor

Ji-ho covers the increasingly tangled overlap between cloud architecture and security, drawing on a background as a penetration tester to keep his reporting grounded in real-world attack paths. He never lets a vendor claim go unquestioned and insists that every buzzword come with a proof of concept.

Discussion 0

Join the discussion

Sign in or create an account to comment and vote.

No comments yet

Be the first to weigh in.

Related Reading