Cybersecurity

How Small Business Ransomware Attacks Actually Work

Most small business owners picture a ransomware attack as a dramatic, high-tech intrusion. The reality is quieter, cheaper, and more methodical than that. Here is exactly how it unfolds, written from the attacker’s side.
Ransomware attack small business

Monday: How Attackers Find You

The attacker does not choose you randomly. They search public business records (state registries, federal contract awards, county licensing databases) looking for companies in the 10 to 50 employee range. That size is deliberate: large enough to have revenue worth encrypting, small enough to have no dedicated security team.

In less than an hour, they have your company name, your registered agent, and an estimate of your revenue, and the name of the person whose email appears on public filings.

A clean business record is the first signal an attacker looks for. It means nothing has gone wrong yet, so nothing has been changed.

Tuesday: Building Your Org Chart for Free

The attacker spends about 40 minutes on research using only a browser. LinkedIn surfaces eight current employees with job titles. One person’s profile lists “accounts payable, payroll, and supplier invoicing” – they are now the primary target.

Your public business presence (contract awards, chamber listings, LinkedIn page) is also an attacker’s research tool. You cannot remove that data, but your team can limit how much operational detail they publish about their specific responsibilities. 

Wednesday: Purchasing Your Credentials for $14

Stealer logs are credential packages harvested by infostealer malware that infected someone’s device, often months or years earlier. The malware records every username and password typed into the machine and bundles the data for sale on Telegram channels and underground forums.

The office manager’s work email and password appear in the package, harvested from a retail loyalty program breach three years ago. The password has not been changed. Total cost: $14 and 4 minutes.

A three-year-old loyalty program breach. $14. That is all it took to obtain valid credentials for a 22-person business.

Thursday: Getting Past MFA

Multi-factor authentication stops many attacks, but the method matters. The attacker uses adversary-in-the-middle phishing. A fake Microsoft reset page that acts as a proxy, capturing the session token when the employee completes the MFA prompt. The MFA succeeded. The session now lives in the attacker’s browser.

Phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business) produces credentials that are cryptographically bound to the legitimate site. A proxy cannot capture them.

Friday at 2:47 PM: Why the Attacker Waited

The attacker spends a few hours reading the targets emails before encrypting anything. In that time, they find the cyber insurance policy (sub-limit: $250,000). the bank reconciliation, and a hard project deadline three weeks out. Then ransom is set at $65,000 – calculated, not random. Low enough that paying is faster than fighting. High enough to be worth the time.

The encryption payload deploys at 2:47pm on a Friday. The bookkeeper leaves at 3pm on Fridays. By the time anyone understands what happened, it is Friday evening and every file on the shared drive is encrypted.

The timing, the ransom amount, the target – all calculated using information sitting in the inbox before a single file was encrypted.

Ransomware attack small business

Five Controls That Would Have Stopped This Attack

None of the following are expensive. Most come bundled with tools many small businesses already pay for.
Block Compromised Passwords
Microsoft Entra ID Password Protection detects and blocks passwords that appear in known breach databases. The $14 credential purchase becomes worthless.
Phishing-resistant MFA
FIDO2 hardware keys, passkeys, or Windows Hello for Business produce credentials cryptographically bound to the legitimate site. A proxy cannot capture them.
Block External Email Forwarding

One setting in the Microsoft 365 admin center. The email reading dwell time never happens.

Review Security Alerts
Microsoft Defender for Business generates an alert when a new forwarding rule is created. Someone reviewing alerts Thursday night stops this before Friday.
Limit Operational Detail in Public Profiles
A conversation with your team about what financial responsibilities to include in public bios costs nothing and removes the primary targeting signal.
The most impactful change is rarely a new product purchase. It is someone reviewing the alerts the tools already in place are generating.
invoice

Three Questions to Ask Your IT Provider

  1. Are we using phishing-resistant MFA for finance, admin, and executive accounts?
  2. Is external email forwarding blocked at the tenant level in our Microsoft 365 environment?
  3. Are our security alerts going somewhere, and is someone reviewing them on a regular schedule?

If your IT provider cannot answer all three with specifics, that conversation is worth having before the next breach in your industry makes the news.

Cleartech Group provides managed IT and cybersecurity services to businesses across Central Massachusetts and Greater Boston. If you’d like us to run through your current setup against these five controls, that’s a 15-minute conversation.

(978) 466-1938 | cleartechgroup.com

Article adapted from The Technology Press.

Have questions about your setup?

We start every partnership the same way: a conversation about where you are, where you’re headed, and what you actually need.