Ransomware gangs skip the CEO, head straight for the 40-something IT manager
What happened
Zscaler researchers tracked a ransomware campaign that deliberately targeted mid-level managers who handle invoices, budgets, and vendor access. The campaign profile indicates attackers do reconnaissance to map approval authority before extortion, which makes supplier-facing approvers higher-value targets and operationally real for procurement teams to harden
Why the category manager should care
Treat manager-level approvers and supplier contacts as a priority control point because attackers are profiling and targeting those roles to accelerate ransom outcomes
Key facts
- Zscaler tracked 351 victims across 334 organizations in a month
- Attackers focused on manager-level roles tied to invoices, budgets, and vendor access