Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Company

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

A Week Inside a Ransomware Attack

How a 22-person business gets picked, breached, and encrypted in five days

Most ransomware attacks on small and mid-sized businesses don't start with a sophisticated exploit. They start with public records, a cheap credential package, and a gap in how multi-factor authentication is configured. The walkthrough below follows one realistic attack, day by day, against a fictional 22-person commercial services company, to show exactly how little it costs an attacker to get in and how far they get before anyone notices.

Every technique described here is real and current. None of the five points where it could have been stopped required new software, only better use of what most businesses this size already pay for.

Monday: how the target gets picked

Attackers running a small volume operation work from spreadsheets of prospects, often around 40 a month, favouring businesses with 10 to 50 staff. Large enterprises have security teams and lawyers that make recovery expensive for the attacker. Sole traders rarely have enough at stake to bother with. A business in the middle sits in the right zone: payroll, a customer database, project files, supplier relationships, and an owner who will pay to get it all back.

The target isn't found through a breach or a tip. It's found on public business records: state registries, federal contract awards, and county-level licensing databases publish enough detail to identify the company, estimate revenue, and pick the most useful person inside it. A clean track record, no past incidents, is itself a signal. It suggests credentials are still valid and staff haven't been trained to spot anything unusual.

Tuesday: building an org chart for free

About 40 minutes of browser research does most of the work. LinkedIn reveals current employees and job titles; an office manager's profile listing "accounts payable, payroll, and supplier invoicing" identifies the person who can approve a payment without a second signature. Public filings confirm the legal business name and owner. An old "meet the team" post on Facebook fills in first names, photos, and family connections. Job ads on Indeed reveal which accounting software the business runs. None of this costs the attacker a dollar.

Wednesday: credentials for £14

Stealer logs are credential packages harvested by infostealer malware that infected someone's personal device, often months or years earlier. They're sold on Telegram channels and forums, searchable by company email domain. Searching the target's domain turns up two hits: the office manager's work email, with a browser-saved password, and a personal Gmail address belonging to a family member on the same home network.

The package costs £14 and takes four minutes to buy. The office manager's password follows a common pattern and appears in a retail loyalty program breach from three years earlier, unchanged since. The family member's password, reused with minor variations across a streaming service and a gaming account, also works on the company's Microsoft 365 login. The only barrier left is the second factor.

Thursday: getting past MFA

Multi-factor authentication stops a lot of attacks, but the implementation matters more than the checkbox. Simple push-notification fatigue no longer works against Microsoft 365 accounts, since Microsoft enabled number matching by default for all Authenticator push notifications in May 2023. What still works is adversary-in-the-middle (AiTM) phishing.

A phishing email designed to look like a routine password reset notification, citing the same breach the password was found in, links to a proxy page that mirrors the real Microsoft sign-in screen. When the target enters their password and approves the MFA prompt, the proxy forwards both to the real Microsoft server, captures the resulting session token, and the victim sees a normal "password updated successfully" message. Microsoft sees a valid authenticated session and treats the attacker's activity as legitimate.

A backup plan covers the case where the email isn't clicked: a phone call posing as the company's IT provider, using a name pulled from a Google review, asking a receptionist to approve a verification push. If that fails too, it costs nothing to try again later. Once inside, an inbox forwarding rule is set up quietly, and the attacker waits.

Friday, 2:47pm: why the attacker waits before encrypting

Thirty-six hours of reading email is how the ransom gets sized correctly.

A cyber insurance policy attached to an email from the broker reveals a £250,000 sub-limit. A bank reconciliation shows roughly £180,000 in the business account. A quote template reveals the full customer list, and a message thread flags a municipal project with a deadline the business can't afford to miss.

The ransom is set at £65,000: low enough to pay rather than fight, high enough to be worth the effort, and comfortably within the business's visible liquid assets. The payload deploys at 2:47pm on a Friday, timed for when the bookkeeper has already left and the owner is on a job site and unreachable. By the time anyone understands what's happened, every file on the shared drive is encrypted and a ransom note sits on every screen in the office.

Five places this attack would have died

Five ordinary things weren't in place. None of them were expensive, and most were already bundled into security tools the business was already paying for.

  • The credential purchase. HaveIBeenPwned is free, and Microsoft Entra password protection can block reused or commonly compromised passwords. Unique passwords per account, enforced through a password manager and Entra policy, make a stolen credential package useless.
  • The MFA bypass. Phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business), Conditional Access policies requiring a compliant device, and anti-phishing protection in Microsoft Defender for Office 365 would each have prevented the session token capture or made it unusable.
  • The inbox forwarding rule. Microsoft 365 allows admins to block external forwarding rules at the tenant level. With that in place, the attacker never gets to read 36 hours of email.
  • The 36-hour dwell time. Microsoft Defender for Business, included in Microsoft 365 Business Premium, alerts on new inbox forwarding rules. Someone reviewing those alerts catches the intrusion on Thursday night.
  • The public business records. State and federal registries can't be unpublished, but what a team posts about their specific responsibilities can be. A LinkedIn profile detailing financial duties is worth a conversation about practical security awareness.

Three questions to send an IT provider

Each of these corresponds to a control that comes bundled with security tools most businesses this size already pay for.

Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?