Zscaler's latest ransomware report puts hard numbers on a shift that security teams have been watching: ransomware targeting managers and executives is no longer a niche tactic. According to the report, managers and above accounted for 62% of victims, data theft rose by more than 275%, and blockchain transactions tied to ransomware payments reached $328 million. The average ransom was $431,995.
Those figures are worth unpacking, both for what they say about attackers and for what they suggest about which defenses matter most.
What the Zscaler Report Found
The report highlights four headline numbers:
- $328 million in blockchain transactions tied to ransomware payments
- 62% of victims were managers and above
- More than 275% growth in data theft
- $431,995 as the average ransom
The data theft figure stands out. It points to attackers placing growing emphasis on stealing information, not only locking systems. Stolen data gives criminals leverage even when a victim can restore from backups, because they can threaten to leak or sell what they took.
The report's title also refers to AI-assisted attackers, which suggests the tools behind these campaigns are speeding up. The source material provided here does not go deeper on the methods, so we won't speculate beyond the published numbers.
For more demographic detail, our earlier coverage of Zscaler data showing ransomware gangs target 46-year-old managers explores who sits in attackers' sights.
Why Managers and Executives Are Prime Ransomware Targets
A 62% share of victims in management roles suggests attackers are choosing people, not just systems. While the report figures do not spell out motives in the material we reviewed, the general logic is easy to follow: people in management positions tend to hold broader access to files, approvals, financial processes and internal communications than frontline staff.
That access is valuable in two ways. First, a compromised manager account can open doors to sensitive data, which feeds the data theft trend. Second, managers often have the authority to act quickly on requests, which can make convincing messages more effective.
This also reflects a change from older security awareness thinking, which centered on protecting the C-suite. The numbers suggest the target group is wider than that, and that mid-level roles deserve the same attention as top executives.
Where VPNs, Encryption and Access Controls Help (and Where They Don't)
Readers of a VPN-focused site will naturally ask whether a VPN stops this. The honest answer is: partly, and not by itself.
Where they help:
- A VPN encrypts traffic between your device and the VPN server, which protects data on untrusted networks such as public Wi-Fi.
- Encrypted storage and devices limit what a thief can read if a laptop or drive is lost.
- Strong access controls, such as multi-factor authentication and least-privilege permissions, limit how far an attacker can move after compromising one account.
Where they don't:
- A VPN does not stop you from opening a malicious attachment or entering a password on a fake login page.
- It does not protect an account whose credentials were already stolen.
- It cannot undo data theft that happens after an attacker gains legitimate access.
In short, a VPN secures the connection, while the ransomware pattern described in the report revolves around access, accounts and the people who hold them. Remote-access setups deserve particular care: any entry point into a work network should be protected by multi-factor authentication and kept up to date.
How Individuals Can Reduce Their Exposure
You do not need to be a CEO to benefit from these steps, and the report suggests you should not assume you are too junior to be targeted.
- Turn on multi-factor authentication for work and personal accounts, preferring app-based or hardware methods over SMS where possible.
- Use a password manager and unique passwords so one leak does not unlock everything.
- Treat urgent requests with suspicion, especially those involving payments, credentials or file sharing. Verify through a separate channel.
- Keep devices and software updated, including any remote-access tools.
- Limit what you store and share. Since data theft is growing, less sensitive data in email and shared drives means less to steal.
- Keep offline or separate backups, while recognizing that backups do not solve the leak threat.
- Use a VPN on untrusted networks as one layer, not the whole plan.
What This Means For You
If you hold any role with access to money, data or approvals, you fit the profile the report describes. The 275% rise in data theft means the risk is not only losing access to your files but also having information exposed. Focus on protecting accounts and verifying requests first, then add network-level protections like a VPN as a supporting layer.
Takeaways
The Zscaler findings show that ransomware targeting managers and executives is a measurable, growing pattern, not a hypothetical one. Review your account security this week: check that multi-factor authentication is on, audit who has access to what, and tighten how you connect remotely. For a closer look at who attackers are choosing, read our coverage of ransomware gangs targeting mid-level managers, then use it to start a conversation with your team about shared habits.




