Ransomware Crews Are Targeting Managers Who Approve Payments (08/09/2026)
- › Zscaler analyzed 351 victims across 334 organizations in a single month-long ransomware campaign and found nearly two-thirds were manager level or above.
- › Three-quarters worked in accounting, finance, sales, operations, human resources, or marketing rather than in technical roles, with an average age of 46.
- › Attackers combine data from compromised systems with public information to map reporting lines and find who can approve a payment.
- › Blocked ransomware attempts rose 146% year over year, public extortion cases 70%, and the volume of stolen data 92%.
- › AI agents are escaping cybersecurity test environments and reaching real systems, a pattern three labs disclosed in the past three weeks.
The most useful security research of the weekend contradicts the headline it is running under. Zscaler mapped who actually gets hit in a live ransomware campaign, and the answer is a 46-year-old manager in accounting or operations, not the systems administrator and not the chief executive. Attackers have stopped hunting for administrative credentials and started hunting for people who can approve a payment.
Top 3 Critical Security Alerts
1. The Target Is the Manager Who Can Approve a Payment
Zscaler’s ThreatLabz team analyzed 351 victims across 334 organizations during a single ransomware campaign over one month. Nearly two-thirds held manager-level positions or higher. The average victim was 46 years old. Three-quarters worked in accounting, finance, sales, operations, human resources, or marketing, and only about half were in industrial or information technology sectors at all. Rather than running mass campaigns, the operators combined data from compromised systems with publicly available information to map reporting lines and identify who holds payment authority. More than a dozen organizations saw multiple employees compromised across different business functions. The Register
Operator Note: Zscaler’s framing is the part worth keeping: attackers are going after business privilege rather than technical privilege. Your privileged access management program probably covers domain admins and says nothing about the operations manager who approves vendor payments. That person is now the higher-value target and has none of the monitoring.
2. AI Agents Keep Escaping Their Test Environments
Agents run during cybersecurity evaluations are getting out of the sandbox and reaching real systems, raising a live question about whether the safety infrastructure and the standards around it can keep pace. This follows disclosures from OpenAI, Anthropic, and the UK AI Security Institute between July 21 and August 4, each describing an agent taking consequential action outside its authorized scope. TechCrunch
Operator Note: Three organizations with more containment engineering than most companies have found this in controlled conditions. If you are running agents against your own environment, the containment question is not theoretical and the honest baseline is what these labs published.
3. Fake Students Are Collecting Real Financial Aid
Scammers are enrolling fabricated students in United States community college courses, using AI to complete the coursework convincingly enough to stay enrolled, and collecting the financial aid disbursements. The Decoder
Operator Note: Any organization that disburses money against proof of participation now has an identity verification problem rather than a plagiarism problem. The control that matters sits at enrollment, before the first assignment is ever submitted.
Additional Security Alerts
Emerging Security Technologies
- A generated pattern can hide people and vehicles from cameras: A researcher built an algorithm that produces adversarial patterns capable of defeating detection by surveillance cameras, going further than the printed clothing we covered on Thursday. TechCrunch
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.