Ransomware actors are increasingly setting their sights on middle management rather than the C-suite. New research from Zscaler's ThreatLabz unit found that nearly two-thirds of ransomware victims — 62 per cent — held managerial titles or above, with an average age of 46. Over a single month, ThreatLabz tracked 351 victims spread across 334 organisations, revealing a deliberate and data-driven targeting strategy that prioritises access over seniority.

Why middle managers, not the CEO?

The logic is straightforward: mid-level managers carry substantial business access without the same level of security scrutiny applied to executives. According to ThreatLabz: "The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or co-ordinate work across business units."

A compromised manager's account can give attackers everything they need — financial data, vendor relationships, internal communications, and the authority to approve transactions — without ever touching the CEO's inbox.

Victims are not selected at random

The research makes clear that targeting is methodical, not opportunistic. Roughly three-quarters of victims worked in five key business functions: accounting and finance, sales, operations, human resources, or marketing. Half worked at companies in the industrial or information technology sector.

Breaking down the numbers by department:

  • Accounting and finance (17.7%): Access to invoices, payments, banking details, approvals, and vendor records makes these employees especially valuable. A single compromised finance account can enable fraudulent transfers or expose payment systems.
  • Sales (17.4%): Sales teams hold customer accounts, active contracts, pricing information, and deal pipeline data — intelligence that can be used for extortion or sold to competitors.
  • Operations (16.8%): Operations staff routinely co-ordinate across suppliers and internal business units, giving attackers a lateral pathway into multiple parts of an organisation.

AI is accelerating the threat. Ransomware operators are now using artificial intelligence tools to automate reconnaissance, personalise phishing lures, and impersonate colleagues or IT staff more convincingly — making it harder for even well-trained employees to spot an attack before it lands.

What organisations should do now

ThreatLabz and Zscaler outline several immediate steps organisations should take to reduce exposure:

  • Restrict external communications on collaboration platforms such as Microsoft Teams and Slack. Lock or flag unsolicited messages and calls from external users by default — a common initial access vector for social engineering attacks.
  • Verify unusual IT requests through trusted internal channels. Employees should be trained to confirm any request from purported IT personnel using the company directory before taking action, rather than responding directly to inbound messages.
  • Enforce least-privilege access. Each employee should have access only to the applications, systems, and data required for their specific role. Limiting access scope directly limits what an attacker can reach through a single compromised account.
  • Implement Zero Trust architecture. A Zero Trust model assumes no user or device is trusted by default, and requires continuous verification. It also segments system access so that even if an attacker gains an initial foothold, lateral movement is contained.

The broader picture

This research fits a wider pattern of ransomware groups professionalising their operations. Victim selection is increasingly driven by data — which roles have the most valuable access, which industries carry the most sensitive information, and which employees are least likely to be protected by elevated security controls. The middle of the org chart has quietly become the most exposed part of it.

For organisations still focused primarily on protecting executive accounts, the ThreatLabz findings are a prompt to recalibrate. The employees most at risk are the ones running the day-to-day business — and attackers know it.