Most ransomware attacks on small and mid-sized businesses don't start with a sophisticated exploit. They start with public records, a cheap credential package, and a gap in how multi-factor authentication is configured. The walkthrough below follows one realistic attack, day by day, against a fictional 22-person commercial services company, to show exactly how little it costs an attacker to get in and how far they get before anyone notices.
Every technique described here is real and current. None of the five points where it could have been stopped required new software, only better use of what most businesses this size already pay for.
Attackers running a small volume operation work from spreadsheets of prospects, often around 40 a month, favouring businesses with 10 to 50 staff. Large enterprises have security teams and lawyers that make recovery expensive for the attacker. Sole traders rarely have enough at stake to bother with. A business in the middle sits in the right zone: payroll, a customer database, project files, supplier relationships, and an owner who will pay to get it all back.
The target isn't found through a breach or a tip. It's found on public business records: state registries, federal contract awards, and county-level licensing databases publish enough detail to identify the company, estimate revenue, and pick the most useful person inside it. A clean track record, no past incidents, is itself a signal. It suggests credentials are still valid and staff haven't been trained to spot anything unusual.
About 40 minutes of browser research does most of the work. LinkedIn reveals current employees and job titles; an office manager's profile listing "accounts payable, payroll, and supplier invoicing" identifies the person who can approve a payment without a second signature. Public filings confirm the legal business name and owner. An old "meet the team" post on Facebook fills in first names, photos, and family connections. Job ads on Indeed reveal which accounting software the business runs. None of this costs the attacker a dollar.
Stealer logs are credential packages harvested by infostealer malware that infected someone's personal device, often months or years earlier. They're sold on Telegram channels and forums, searchable by company email domain. Searching the target's domain turns up two hits: the office manager's work email, with a browser-saved password, and a personal Gmail address belonging to a family member on the same home network.
The package costs £14 and takes four minutes to buy. The office manager's password follows a common pattern and appears in a retail loyalty program breach from three years earlier, unchanged since. The family member's password, reused with minor variations across a streaming service and a gaming account, also works on the company's Microsoft 365 login. The only barrier left is the second factor.
Multi-factor authentication stops a lot of attacks, but the implementation matters more than the checkbox. Simple push-notification fatigue no longer works against Microsoft 365 accounts, since Microsoft enabled number matching by default for all Authenticator push notifications in May 2023. What still works is adversary-in-the-middle (AiTM) phishing.
A phishing email designed to look like a routine password reset notification, citing the same breach the password was found in, links to a proxy page that mirrors the real Microsoft sign-in screen. When the target enters their password and approves the MFA prompt, the proxy forwards both to the real Microsoft server, captures the resulting session token, and the victim sees a normal "password updated successfully" message. Microsoft sees a valid authenticated session and treats the attacker's activity as legitimate.
A backup plan covers the case where the email isn't clicked: a phone call posing as the company's IT provider, using a name pulled from a Google review, asking a receptionist to approve a verification push. If that fails too, it costs nothing to try again later. Once inside, an inbox forwarding rule is set up quietly, and the attacker waits.
A cyber insurance policy attached to an email from the broker reveals a £250,000 sub-limit. A bank reconciliation shows roughly £180,000 in the business account. A quote template reveals the full customer list, and a message thread flags a municipal project with a deadline the business can't afford to miss.
The ransom is set at £65,000: low enough to pay rather than fight, high enough to be worth the effort, and comfortably within the business's visible liquid assets. The payload deploys at 2:47pm on a Friday, timed for when the bookkeeper has already left and the owner is on a job site and unreachable. By the time anyone understands what's happened, every file on the shared drive is encrypted and a ransom note sits on every screen in the office.
Five ordinary things weren't in place. None of them were expensive, and most were already bundled into security tools the business was already paying for.
Each of these corresponds to a control that comes bundled with security tools most businesses this size already pay for.

























