# Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334 Organizations)

> Zscaler ThreatLabz analysed one month of activity by an unnamed ransomware campaign that steals large volumes of corporate data and selectively encrypts critical systems, covering 351 victims across 334 organizations. Operators prioritise employees with business privilege (access and authority): 62% of victims held manager-level titles or higher.

- **Published:** 2026-08-06T00:00:00Z
- **Last reviewed:** 2026-08-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2897
- **ID:** TL-2026-2897
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In a report published 2026-08-06 (author Brett Stone-Gross), Zscaler ThreatLabz examined the human side of a single ransomware campaign over a one-month observation window and identified 351 victims across 334 organizations. The group is not named in the report, and the report publishes no CVEs, malware family names, filenames, IP addresses, domains or file hashes; full technical detail is deferred to the forthcoming ThreatLabz 2026 Ransomware Report (promised within two months of publication).

Victimology is the core finding. 62% of victims held manager-level titles or higher; the average victim age was 46 (range 23-70) and 44% were Generation X. Roughly 75% worked in accounting/finance (17.7%), sales (17.4%), operations (16.8%), human resources or marketing. By employer sector, industrials accounted for 35.5% and information technology for 14.6% (50% combined). More than a dozen organizations had multiple employees compromised. ThreatLabz frames the targeting as exploitation of 'business privilege' - the access and authority created by roles and relationships - rather than technical administrator access.

Reported initial access and social-engineering behaviors: an unusual volume of spam email directed at victims; Microsoft Teams messages from an external threat actor posing as the organization's IT staff; and ClickFix attacks that trick victims into copying and pasting malicious commands into the Windows Run prompt, using lures ranging from captchas to missing plugins to system errors. Secondary coverage (Rankiteo) adds that attackers combined compromised-system data with public information to map reporting structures, and that stolen data included invoices, budgets, contracts and HR records; it also cites a 70% rise in public extortion cases and a 92% jump in stolen data volume from ThreatLabz's broader reporting. Post-compromise the actors exfiltrate large amounts of corporate data and selectively encrypt critical systems, so not every victim experienced encryption. The report gives no specific lateral-movement, tooling or exfiltration-channel details.

A separate Zscaler post (2026-07-27, 'Helpdesk Hijackers') describes Teams vishing, Quick Assist and the GoGRPC backdoor by a likely ransomware initial access broker. That report does not reference this managers study and nothing sourced links the two; its indicators are deliberately NOT attributed to this threat.

## MITRE ATT&CK

- T1591.004 Identify Roles
- T1566.003 Spearphishing via Service
- T1078 Valid Accounts
- T1204.004 Malicious Copy and Paste
- T1684.001 Impersonation
- T1657 Financial Theft

## Sources

- [Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz)](https://www.zscaler.com/blogs/security-research/ransomware-moves-org-chart-managers-are-prime-targets)
- [Ransomware Targets Managers - ThreatLabz Research (infographic)](https://www.zscaler.com/resources/infographics/ransomware-targets-managers-threatlabz-research.pdf)
- [Zscaler: Ransomware gangs skip the CEO, head straight for the 40-something IT manager (Rankiteo)](https://blog.rankiteo.com/zsc1786271039-zscaler-ransomware-august-2026/)
- [Ransomware Moves up the Org Chart: Managers Are Prime Targets - Brett Stone-Gross, BH26 (SC Media)](https://www.scworld.com/podcast-segment/15650-ransomware-moves-up-the-org-chart-managers-are-prime-targets-brett-stone-gross-bh26-2)
- [Helpdesk Hijackers: Teams Vishing, Quick Assist and the GoGRPC Backdoor (Zscaler, related but separate report)](https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor)
- [Ransomware Leverage Growing: Terabyte Takeaways from the ThreatLabz 2026 Ransomware Report (Zscaler)](https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2897
