Ransomware gangs are changing who they target. The most valuable account may no longer belong to the CEO or a domain administrator — it may belong to the manager who can approve payments, access sensitive files and influence what happens next.
What Happened
New Zscaler ThreatLabz research examined 351 victims across 334 organisations linked to a single ransomware campaign and found that attackers were disproportionately targeting people with managerial authority rather than simply chasing executives or technically privileged accounts. Some 62% of victims held manager-level roles or above, while around three-quarters worked in finance, sales, operations, HR or marketing.
The average victim was 46 years old, but the finding appears to be more about seniority than age. Employees at that stage of their careers are more likely to control budgets, approve payments, manage suppliers, access contracts and sensitive information, and have relationships across the organisation.
Zscaler describes this as "business privilege" — access and authority that comes from someone's role rather than administrator rights. Attackers are increasingly using information obtained from compromised systems alongside publicly available information to understand organisational structures and identify people whose accounts could help them steal data, move through the organisation or increase the pressure to pay.
The research also found multiple employees compromised at more than a dozen organisations, suggesting attackers may deliberately work through different business functions rather than relying on a single account.
The Cyooda View
For years, cybersecurity programmes have concentrated heavily on the obvious high-value accounts: administrators, executives and anyone with elevated technical privileges.
Attackers are looking at the organisation differently.
They are asking who can approve an invoice, access confidential client information, change a supplier, see sensitive HR records, influence management or simply persuade somebody else to take an action.
For a law firm, that could be a finance manager, practice manager, HR manager, IT manager, senior associate or partner. None necessarily needs administrator access to cause a serious incident if their identity is compromised.
"The account with the greatest technical privilege and the person with the greatest business influence are not necessarily the same person."
That distinction matters because traditional privileged-access controls only address part of the problem. Firms should be identifying roles with significant business privilege and applying stronger controls around them: phishing-resistant MFA, tighter access to sensitive information, monitoring for unusual account behaviour and independent verification for payment or banking changes.
It also changes security awareness. Generic annual phishing training is increasingly mismatched to an attacker who has already researched the individual, understands their role and may know their colleagues, suppliers and reporting lines.
The lesson from this research isn't that 46-year-old managers suddenly became bad at cybersecurity. It is that ransomware operators are becoming much better at understanding how organisations actually work.
Your organisational chart is now part of the attack surface.
Source: The Register / Zscaler ThreatLabz
Original: Read More
Source: www.theregister.com - Articles Original: Read More
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.