AI News Feed
Market watch
Products & Applications

Ransomware attackers target managers and backups, research finds

New research shows ransomware attackers are singling out managers for elevated access and deleting backups to block recovery, highlighting the need for recovery readiness.

A ThreatLabz analysis of a single ransomware campaign, reported by ZDNet, found that 62% of the targeted employees held manager-level titles or higher. The attackers stole large amounts of corporate data and encrypted critical systems across 334 organizations, with 351 victims identified over one month.

About three-quarters of the targeted managers worked in accounting and finance, sales, operations, human resources, or marketing. Half of the affected organizations were in the industrial or information technology sector, and multiple employees were targeted in more than a dozen organizations.

The reason managers are attractive targets, the researchers said, is that they typically hold higher network and business privileges and are responsible for approving payments, overseeing budgets, reviewing contracts and coordinating across departments. A compromised managerial account can therefore give attackers access to sensitive records and a way to target other business units.

Specific roles identified in the campaign included a regional sales manager with access to customer accounts and contracts, an accounts payable manager with access to invoices and financial approvals, a senior project manager with access to budgets and roadmaps, and a property manager handling lease agreements and vendor invoices.

In a separate article on ZDNet, experts warned that more than 90% of ransomware attacks now attempt to delete or tamper with backups before the payload fires, and nearly 60% of those attempts succeed. Many organizations mistakenly treat backups as a recovery strategy, even though backup is not the same as being able to restore operations quickly.

Citing a U.S. Chamber of Commerce report, the article noted that 94% of surveyed small-business leaders believed their enterprise would survive a disaster, but only a quarter had the recovery infrastructure in place. An organization that protects data but fails to plan for recovery still faces extended downtime, lost revenue and damage to customer trust.

Attacks increasingly rely on identity-based methods: about four in five ransomware attacks begin with identity-based approaches, according to the article. In 2025, 69% of SaaS accounts monitored were guest accounts, and only 27% of SMBs were actively enforcing multi-factor authentication, citing Kaseya's 2026 SaaS Security Report.

The article also pointed to a Redmond/Kaseya survey of 200 IT professionals, in which only one in five organizations reported unified backup protection across hybrid environments. More than half said they were only somewhat confident they could restore their environment, and just 18% test that assumption monthly.

To address the risk, ThreatLabz recommends limiting external communications via collaboration tools, training employees to verify requests from alleged IT staff, deploying AI-powered network and endpoint protection, watching for signs of compromise, implementing least-privilege access, and taking a zero-trust approach to segment network access. On the recovery side, the separate ZDNet article suggests using immutable, isolated backups and dedicated recovery tools that verify backups can actually boot, such as screenshot verification.