Zscaler ThreatLabz reported that a real-world ransomware campaign disproportionately compromised employees with business authority rather than only users with obvious technical privilege. In a one-month sample tied to a single ransomware operation, researchers identified 351 victims across 334 organizations, with 62% of victims holding manager-level titles or higher. The campaign was linked to a group known for gaining initial access, stealing large volumes of corporate data, and selectively encrypting critical systems.
The victim set was concentrated in functions that can unlock sensitive business processes: roughly 75% worked in accounting and finance, sales, operations, human resources, or marketing, while 50% were in industrials or information technology. ThreatLabz said these roles can expose payments, contracts, vendor relationships, sensitive records, and cross-business communications that help attackers move laterally and increase extortion pressure. The researchers said organizations should tighten external collaboration controls, strengthen impersonation-focused training, deploy inline network and endpoint detection, monitor for compromise, enforce least privilege, and apply Zero Trust segmentation.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz published research examining employees compromised at the start of a real-world ransomware attack rather than focusing only on the breached organizations and encrypted systems. The research said these victims' roles and authority could help attackers move deeper into organizations.
Over a one-month period, Zscaler ThreatLabz linked 351 victims across 334 organizations to a single ransomware campaign. The researchers found the victims were disproportionately employees with business authority, including 62% with manager-level titles or higher.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcezdnet.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcetheregister.com
Open sourcemalware.news
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.