Cookie Consent by Free Privacy Policy Generator

Ransomware groups shift focus to mid-level IT managers with privileged access

Ransomware gangs are shifting their social engineering tactics away from targeting CEOs and senior executives, instead focusing on IT managers, typically in their 40s, who have privileged access to systems but may be less prepared for sophisticated phishing or vishing attacks. The Register reports that these mid-level technical staff often have administrative credentials, access to backup systems and the ability to disable security controls, making them valuable targets. Attackers are using increasingly convincing pretexts, including fake IT support calls, vendor impersonation and urgent requests that exploit the pressure and workload these individuals face. The article explains that this shift reflects a more operationally aware approach from ransomware groups, who understand that technical staff with day-to-day system access are often easier to manipulate than board-level executives who are more likely to have received targeted security awareness training.

Why this matters for UK organisations

This shift in attacker behaviour highlights a gap in how security awareness and incident response preparedness is distributed across UK organisations. IT managers are often expected to be the first line of defence, yet they may not receive the same level of support, training or scrutiny as senior leadership when it comes to recognising and responding to social engineering attempts. The operational reality is that these individuals are under significant pressure, often working long hours, managing multiple priorities and dealing with constant interruptions. This makes them particularly vulnerable to attacks that exploit urgency, authority or the assumption that a request must be legitimate because it appears to come from a trusted source. For organisations, this means that security awareness training needs to be more than an annual compliance exercise. It needs to reach the people who hold privileged access, be relevant to the types of attacks they are likely to face, and be reinforced by a culture where questioning unexpected requests is encouraged rather than seen as obstructive or distrustful.

What to review

Organisations should review whether security awareness training, phishing simulation and incident response guidance is reaching technical and operational staff who hold privileged access. Consider whether IT managers know how to verify unexpected requests, whether they feel able to challenge urgent demands without fear of blame, and whether there are clear escalation routes when something feels wrong. Review whether there are technical controls in place to limit the damage that can be done if a privileged account is compromised, such as multi-factor authentication, privileged access management, and monitoring for unusual administrative activity. Consider whether incident response plans account for the possibility that an attacker may have gained access through a trusted insider, and whether there are processes in place to quickly revoke access, isolate affected systems and preserve evidence. Ensure that security awareness training is tailored to the specific risks faced by technical staff, including vishing attacks, vendor impersonation and social engineering techniques that exploit operational pressure and trust.

Source: The Register

News and blog posts
Today's brief reflects the growing operational complexity organisations face as...
OpenAI has announced it is pausing some internal activities involving its...
Ransomware gangs are shifting their social engineering tactics away from...
Beacon, a widely used customer relationship management (CRM) platform for...