SAN JOSE, 10 AUG 2026 — Ransomware operators tracked through one month of a single campaign did not go after administrators. They went after a 46-year-old manager in accounts, and they did it 351 times.
Zscaler's ThreatLabz published the breakdown on 6 August. The 351 compromises occurred across 334 organisations, and the pattern looks less like random clicking and more like a targeting doctrine.
Who was actually hit
Ages ran from 23 to 70 and averaged 46. Generation X made up 44% of victims, the largest single block. Sixty-two per cent held a title of manager or above.
The targets' departments show the attackers' reasoning:
Note what that does to the shorthand. This campaign has been summarised as going after the IT manager, and information technology is 14.6% of it. Industrials is two and a half times larger. The modal victim is not in the technology department at all — they are a manager in a manufacturing or logistics business who approves invoices.
Business privilege is the actual target
ThreatLabz gives the idea a name worth borrowing: business privilege, as distinct from technical privilege.
Security programmes are built around the second one. Domain administrators get hardware keys, privileged access management, session recording, quarterly reviews. The finance manager gets a password policy and an annual training video, because on the org chart she is not privileged.
On the org chart. In practice she can see supplier contracts, customer accounts, payment approvals and the mailbox that everyone in the company trusts. Nothing in that list requires special permissions to abuse, so it is not monitored with the same rigour.
An attacker who wants money does not need root. They need somebody whose instruction to pay an invoice will not be questioned, and whose email carries authority across departments. That person is cheaper to reach and worth more per compromise than the administrator everybody is watching.
Age 46 is not a story about older workers
The average age gets the headlines, but it is easily misread as a knock on Gen X's security competence.
It is a seniority artefact. Sixty-two per cent of victims held a manager title or above, and the age at which people hold those titles is the mid-forties. The finding is not that this cohort is worse at spotting phishing; it is that the campaign selected for authority, and authority correlates with age. If it had selected for administrator access the average would have been lower, and nobody would have concluded anything about millennials.
Get that the wrong way round and you buy training for the wrong people.
The multi-victim organisations
More than a dozen organisations had several employees compromised — a detail that should shape any defensive review.
ThreatLabz describes attackers combining what they take from a compromised system with public information to map reporting lines and pick the people most able to shape a company's response. That is not opportunism; it is target development inside an organisation you already hold, and it means the second victim is chosen using what the first one gave up.
In practice, an alert on one compromised business account should be treated as the start of an internal campaign, not an isolated event to be closed with a password reset. The question to ask is not what did they get from her, but who does she talk to.
Why the target moved up the org chart
Targeting authority rather than access makes more sense the less the business model depends on encryption.
Zscaler's wider figures, reported alongside this research, describe ransomware attempts blocked rising 146% year on year, public extortion cases up 70%, and the volume of stolen data up 92%. These figures are context from Zscaler's broader telemetry, not findings from this campaign's 351 victims.
Taken as context, they point one way. When the leverage is stolen data and the threat of publication, an attacker needs embarrassing material more than the machine that runs the backups. They want contracts, payroll, customer records, and the mailbox where a merger was discussed. A manager in finance or HR holds more of that than a domain administrator does, and reaching her does not require defeating the controls that guard the administrator.
That also explains the multi-victim organisations. If the goal is a collection of documents rather than a foothold on a server, more compromised business accounts is directly more product.
What defends against this
ThreatLabz's own recommendations run to restricting communication on external collaboration platforms, training against impersonation specifically, monitoring for signs of compromise, enforcing least privilege and moving to zero-trust architecture. The last two are multi-year programmes, so the ranking matters.
The cheapest change is to extend the controls you already bought. Phishing-resistant authentication and conditional access exist in most organisations and are usually scoped to technical administrators; the finding here says scope them by business authority instead — anyone who can approve a payment, change bank details on a supplier record, or send instructions the finance team will act on.
The second is a process control rather than a security one, and it is the one that actually stops the loss: an out-of-band verification step for changes to payment details, which does not care whether the request came from a compromised account.
Impersonation training is worth more than generic phishing training here, but keep expectations calibrated. The people being caught are experienced and senior, which suggests the messages were good rather than the targets careless.
What to watch
Whether the pattern holds beyond one campaign and one month. This is a single operation's victim set, and a doctrine inferred from it could be one crew's habit rather than a market-wide shift.
Whether the sector skew survives a wider sample. Industrials at 35.5% may reflect this campaign's lure material as much as any structural weakness in manufacturing.
And whether anyone publishes the counterfactual: how many people at those 334 organisations were approached and did not fall for it. Without a denominator, a victim profile describes who was hit, not who is vulnerable.