A new Zscaler report points to a clear shift in how extortion gangs operate. AI-assisted ransomware targeting remote workers, especially those with managerial titles, is producing larger payouts and relying on tools that employees already trust. For anyone who works from home or logs in from a coffee shop, the findings are a useful reminder that the most dangerous message may arrive through an app your company approved.

What the Zscaler report found

The headline figures from the report are straightforward. The average ransom payment rose 5.3% year over year to $431,995. Manager-level titles and above accounted for 62% of victims in the attacks Zscaler examined, which suggests attackers are deliberately choosing employees with privileged roles and business influence.

The report also describes a broader change in tactics. Zscaler says threat actors are using AI to assist their operations and are moving toward large-scale data theft, not just encrypting files. Stealing data first gives criminals a second source of pressure: even if a company can restore systems from backups, the threat of publishing sensitive information remains.

The source material available to us is limited to a summary of the report, so we are sticking to the figures and claims that Zscaler has made public rather than filling in details it has not.

How Teams and Quick Assist are being abused

One of the most practical findings is that attackers are increasingly abusing trusted enterprise tools, including Microsoft Teams and Quick Assist. According to the report, these tools are being used to enable social engineering, lateral movement, data theft, and file encryption.

The logic is easy to follow. A message in Teams looks like ordinary workplace chatter. A Quick Assist session looks like routine IT support. Neither triggers the suspicion that a strange email attachment might. When an attacker can get a busy employee to accept a chat request or a remote-support prompt, they may gain a foothold without ever needing to break through a firewall.

This is also why these tools are hard to police with simple blocklists. They are legitimate software that many organizations depend on every day. The risk sits in how they are used, and who is on the other end of the conversation.

Why managers are the main targets

With managers and above making up 62% of victims, the pattern is hard to ignore. People in these roles tend to have broader access to files, approvals, and internal systems. They are also more likely to be trusted by colleagues, which makes a convincing impersonation more valuable to an attacker.

This aligns with earlier coverage on the site. Our look at how ransomware gangs are targeting mid-career managers describes a move away from the old focus on the C-suite alone, and the new report reinforces that attackers are paying attention to the people who sit in the middle of daily business operations.

AI appears to make this targeting cheaper and faster. Zscaler describes AI-assisted attackers, and while the summary does not detail every technique, the general direction is clear: better-tailored messages and quicker operations mean less effort per victim.

What a VPN does and doesn't protect against

A VPN encrypts traffic between your device and the VPN server, and it can reduce exposure on untrusted networks such as public Wi-Fi. That is valuable, but it addresses a different problem than the one described in this report.

If an attacker persuades you to accept a Teams request or start a Quick Assist session, the connection is one you chose to open. Encrypted traffic does not help when the person on the other end is the threat. A VPN also does not stop you from handing over credentials, approving a remote-control request, or running a file you were told to open.

In other words, a VPN is one layer of privacy protection, not a defense against social engineering inside legitimate platforms. Treat it as a complement to good account and device habits, not a substitute for them.

What This Means For You

If you work remotely, especially in a role with approval power or wide file access, you fit the profile the report describes. The practical takeaway is to slow down at the moment someone asks you to grant access.

  • Treat unexpected Teams messages from unfamiliar or external accounts with caution, even if they mention IT or a known colleague.
  • Never start a Quick Assist session unless you initiated the support request through a channel you verified yourself.
  • Confirm unusual requests by contacting the person through a separate, known method.
  • Use unique passwords and multi-factor authentication on work and personal accounts.
  • Report suspicious contacts to your IT or security team quickly, even if you are unsure.

Takeaways

The Zscaler findings show that AI-assisted ransomware targeting remote workers is less about exotic exploits and more about persuading the right person to open the door. A $431,995 average payment and a 62% share of manager-level victims make the incentive obvious.

Take a few minutes this week to review how you handle remote-access requests and credential hygiene: check which tools can control your device, tighten your multi-factor authentication, and agree on a verification habit with your team. For more context on who is being hit and why, read our earlier coverage of ransomware gangs targeting mid-level managers.