Fetching from the wire…
Public story · 2026-08-10 · high
Zscaler's ThreatLabz found two-thirds of 351 ransomware victims held manager titles, three-quarters worked outside IT.
Why now: The Register's write-up of Zscaler's findings lands as ransomware crews keep moving off executives toward staff with business access.
Zscaler ThreatLabz combed through 351 ransomware victims across 334 organizations and found most weren't executives or IT staff, per The Register.
Nearly two-thirds held manager titles or higher, and three-quarters worked outside IT, in roles like accounting, finance, sales, operations, HR, or marketing. The average victim was 46, a different profile than the CEO or systems administrator most phishing training assumes is the target.
The shift shows up in the numbers too. Blocked attack attempts rose 146% year over year, public extortion cases climbed 70%, and data theft volume jumped 92%.
The framing from the analysis is that attackers optimize for business privilege over technical access. A mid-career manager in accounting or operations sits closer to the money and the paperwork than someone in the security team. That's the calculation driving the shift.
Watch whether upcoming breach reports keep showing this same middle-management pattern. If they do, awareness training built around org-chart seniority needs a rewrite.
Each link below shares sources, entities, or timing with this story.
Satya Nadella said companies routing everything through a single proprietary lab may not survive. His argument: you hand that lab your most sensitive business context, and the lab can turn it against you as a competitor. His prescription is an orchestration layer — keep the ha...
CrowdStrike's 2026 Global Threat Report shows 89% YoY increase in AI-enabled attacks, with average breakout time falling to 29 minutes (65% faster than 2024). Fastest recorded: 27 seconds. Data exfiltration began within 4 minutes in one case. Critically for builders: attackers...
garrytan/gstack packages 23 opinionated Claude Code tools cast as CEO, Designer, Eng Manager, Release Manager, Doc Engineer and QA roles, at 131,043 stars five months after its March 11 creation. Splitting its 849 open issue count gives 534 PRs to 315 issues, meaning contribut...
The submission titled "CEO fired developers to make room for AI. Developers create open source AI CEO" pointed at SenteLabsAI/OpenExecutive, an Apache-2.0 FastAPI and Next.js 15 app running eight specialist Claude agents (CSO, CFO, CHRO, General Counsel, COO, CMO, CPO, Board C...
At $11.4B revenue run-rate (+24% YoY), Next-Gen Security ARR grew 60% (28% organic) with 120% NRR and single-digit churn, but only among ~2,280 multi-product accounts, targeting 4,000 by 2030 (SaaStr). The $25B CyberArk acquisition closed February 2026, beat internal targets b...
This is the most consequential architecture decision in enterprise software since cloud versus on-prem, and it happened quietly across three vendor announcements. PYMNTS connected the dots first. SAP blocks. Its API Policy v4/2026, published in late April, prohibits using SAP...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.