In a ransomware campaign Zscaler ThreatLabz tracked for one month, 62% of victims held manager-level titles or higher. Zscaler's researchers suggested that "the victims were not selected at random," and the company carried the finding into its ThreatLabz 2026 Ransomware Report, published September 30, 2026.

The accounts attackers went after belonged to people who approve payments, manage vendors, and sit close to sensitive records, which puts them on a security team's high-risk list even though, as Zscaler noted, "these employees do not need administrator rights to create serious business exposure."

What was measured

Over one month, ThreatLabz identified 351 compromised victims across 334 organizations, all linked to a single threat actor that specializes in gaining initial access, stealing large volumes of corporate data, and selectively encrypting critical systems.

Within that group, 62% held manager-level titles or higher, and roughly 75% worked in five functions: accounting and finance, sales, operations, HR, and marketing. Healthcare organizations accounted for 6.0% of victims, according to Zscaler's research brief.

"Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units," wrote Brett Stone-Gross, Senior Director of Threat Intelligence at Zscaler.

How these intrusions start

According to Zscaler, attackers flood a target's inbox with spam, then contact them through Microsoft Teams posing as the help desk and steer them into a legitimate remote support tool such as Quick Assist, so the break-in looks like routine IT support.

From there, the attacker has a session on a manager's machine, with that manager's access to finance systems, shared drives, and mail. Zscaler's report ties the same pattern to reconnaissance, persistence, lateral movement, data theft, and encryption.

A data theft and extortion cluster tracked as PREY-0058 shows the same preference for senior targets, calling directors and vice presidents while posing as internal IT, with healthcare and pharmaceuticals among the five most affected sectors.

Microsoft disclosed a campaign that, in early August, impersonated company CEOs to push accounts payable staff into fraudulent transfers.

Related: Stopping executive impersonation with ExecProtect

Why stolen data drives the payment

ThreatLabz identified a healthcare organization that "paid $2 million in ransom solely to prevent stolen data from appearing on a leak site. No encryption ever occurred," according to a Zscaler analysis published October 1, 2026.

The same analysis reports that during negotiations, ransomware groups "routinely cite HIPAA, SEC disclosure requirements, and GDPR to intensify pressure on victims." For a healthcare organization, stolen patient data brings breach notification questions into the negotiation the moment it leaves the network.

Where early warning breaks down

Paubox's 2026 Healthcare Email Security Report analyzed 170 email-related breaches reported in 2025, and 41% of the organizations reviewed were assessed as high risk, up from 31% in 2024.

Paubox survey data also shows 68% of healthcare leaders faced a phishing attack in the past year, while healthcare IT leaders estimate that only 5% of known phishing attacks are reported by employees to their security teams.

That reporting gap matters more when attackers concentrate on managers. A spam flood followed by a Teams call from "IT" is designed to feel like help arriving, so the person being targeted has little reason to report it until after access is granted.

Go deeper: HIPAA compliant email

What to change for your senior staff

Build a protected list from the org chart

Start with the roles Zscaler found most targeted: finance, sales, operations, HR, and marketing leads, plus anyone with payment or vendor approval authority.

Inbound controls that check whether a message using a protected name actually comes from that person's approved address catch the display-name spoofing these campaigns rely on. Paubox Inbound Email Security includes ExecProtect+ for this.

Close the external collaboration channel

Zscaler recommends blocking unsolicited messages and calls from external users on Microsoft Teams and Slack. If your tenant allows any external account to message staff, the vishing step in this campaign has an open door.

Give staff one way to verify IT requests

Train employees to confirm any unexpected request from "IT" through the company directory or a known internal number before installing or approving anything. Make the reporting path a single click, since a manager on a full schedule usually skips a process that requires forwarding a message and writing an explanation.

Limit what one manager account can reach

Least-privilege access and segmentation reduce how far a compromised identity can move. Review standing access for the roles on your protected list first, since they are where attackers in this campaign started.

Plan for extortion without encryption

Incident response plans built around restoring from backup do not address a demand where the data is already gone. Add an exfiltration scenario to your tabletop exercises, including how your team would assess HIPAA breach notification obligations.

Start with the names attackers already have

The reconnaissance for this kind of campaign starts with public information: leadership pages, professional profiles, and job titles. Your team already has a better version of that list in the org chart, and putting it to work on inbound filtering, collaboration settings, and access reviews covers the employees this research shows attackers are choosing.