Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions.

Attackers are compromising managers whose accounts can open doors to contracts, payments, customer records, and internal teams. Their job titles can make a fraudulent request appear more credible.

An account with ordinary workplace access may still let criminals study a company, collect sensitive files, contact colleagues, and prepare a wider attack that ends in data theft or encryption.

Analysts at Zscaler identified this pattern while examining a real-world campaign tied to a ransomware group known for gaining initial access, taking large volumes of corporate data, and selectively encrypting critical systems.

It tracked 351 victims across 334 organizations in one month. The campaign shows how ransomware crews turn trusted business access into a route through a corporate network.

Zscaler said in a report shared with Cyber Security News (CSN) that more than a dozen affected organizations had multiple employees compromised, increasing the chance of a deeper breach. The pattern is deliberate.

Ransomware Attackers Target Managers

The clearest finding is that managers were not accidental victims. Sixty-two percent of those identified held manager-level titles or higher, suggesting attackers prize business influence as much as technical privileges.

Managers can approve payments, oversee vendors, review budgets, access records, and coordinate work between departments.

Victim graph (Source – Zscaler)

Recent reporting on corporate-network entry malware shows how an initial foothold can become lasting access and movement across internal systems.

The largest share of victims, 44 percent, belonged to Generation X, with an average age of 46 across a range from 23 to 70. Many people in this group are established in senior roles, where access and decision-making authority are concentrated.

Business function also mattered. About 75 percent of victims worked in accounting and finance, sales, operations, human resources, or marketing.

Finance staff may see invoices, approvals, bank details, and vendor records, while sales teams work with contracts and customer deals. Operations and HR accounts can expose internal processes and communications.

Industrial companies accounted for 35.5 percent of victims, followed by information technology organizations at 14.6 percent. In these settings, stolen access can reach systems supporting factories, distribution, logistics, intellectual property, or digital services.

Stopping a Single Account Breach

The findings underline why companies should protect roles based on what they can do, not just whether they have administrator rights.

The risk becomes sharper when an attacker impersonates internal support staff, a tactic seen in Teams helpdesk impersonation attacks.

Organizations should limit unsolicited messages and calls from outside users on collaboration platforms, and train employees to verify unusual IT requests through trusted internal channels.

That basic check can interrupt social engineering before a criminal gains remote access or steals credentials.

Security teams should also watch for unusual activity involving users, devices, applications, remote-access tools, and large data transfers.

Investigators should look beyond the first affected employee because multiple compromises may signal a coordinated campaign.

The importance of tracing those steps is clear in ransomware network movement investigations, where attackers used stolen access to map systems and reach key servers.

Restricting each employee to the data and systems needed for their job can reduce harm from a compromised account. It also reduces the reach of stolen credentials.

Teams should pair these controls with network and endpoint monitoring that can spot malicious files, suspicious behavior, and active attack activity early. That makes early detection especially important.

Finally, organizations need an incident plan that treats a manager’s account compromise as a potential enterprise-wide event.

Rapid password resets, session reviews, access checks, and a search for related accounts can limit data loss and stop encryption before it spreads.

The core lesson is simple: trusted business access is a high-value target and deserves the same attention as privileged technical access.

The defenders should continuously monitor for compromise, enforce least-privilege access, and segment access to contain attacks after an initial foothold.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world