Ransomware gangs skip the CEO, head straight for the 40-something IT manager

4 hours ago (theregister.com)

Hey! As a 46 year old I am offended by this - I am definitely not Gen X. We’re a weird X/Millenial hybrid I’ve seen referred to as Xennials.

Also F ZScaler - we use this officially sanctioned MTM attack at work and all it does is make my job harder.

The article is unclear: Do they "attack" the GenX managers and encrypt their stuff, or do they simply contact GenX managers in order to get paid faster?

In that case, the managers aren't "victims" and aren't "attacked", that would be the company..

  • If the article was written by an actual human, we may have had the answer. Instead, we got this non-sense

    > By the time the ransom note lands, the crooks may already know who approves invoices, who signs contracts, who runs HR, and who reports to whom. The encryption is just the bit that victims notice.

Companies hope that training will protect them from cyber threats, while ignoring that their most vulnerable employees are the ones that lost the motivation to care about their job.

  • Training is basically just for legal and insurance reasons... If not there would be no reason to do yearly training of the same bs courses.

> Zscaler says they combine information from compromised systems with publicly available data to map reporting lines and identify the employees most likely to influence a company's response.

And commercially-available data: enterprise salespeople, for example, can buy this intel from data brokers (directly, or with layered services catering to sales funnels specifically).

It's another way that surveillance capitalism can be a national security threat against the US. You have countless US companies collectively mapping out people networks and assembling often intimate dossiers on individuals... and saving international organized crime and geopolitical adversaries a ton of work, which they might not have the resources to otherwise do.

  • They've learned from how real businesses operate. Ever talked to a salesperson? Notice how much the initial conversation is geared to trying to figure out whether you have any real purchasing authority, and who does if it isn't you?

  • So why is this only a threat to US companies and not for businesses in other parts of the world?

    • US consumers are more valuable which makes their data more valuable and therefore collected. It applies to other first world nations without robust enough data protections.