Cybersecurity
How Small Business Ransomware Attacks Actually Work
Monday: How Attackers Find You
In less than an hour, they have your company name, your registered agent, and an estimate of your revenue, and the name of the person whose email appears on public filings.
A clean business record is the first signal an attacker looks for. It means nothing has gone wrong yet, so nothing has been changed.
Tuesday: Building Your Org Chart for Free
Your public business presence (contract awards, chamber listings, LinkedIn page) is also an attacker’s research tool. You cannot remove that data, but your team can limit how much operational detail they publish about their specific responsibilities.
Wednesday: Purchasing Your Credentials for $14
The office manager’s work email and password appear in the package, harvested from a retail loyalty program breach three years ago. The password has not been changed. Total cost: $14 and 4 minutes.
A three-year-old loyalty program breach. $14. That is all it took to obtain valid credentials for a 22-person business.
Thursday: Getting Past MFA
Phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business) produces credentials that are cryptographically bound to the legitimate site. A proxy cannot capture them.
Friday at 2:47 PM: Why the Attacker Waited
The attacker spends a few hours reading the targets emails before encrypting anything. In that time, they find the cyber insurance policy (sub-limit: $250,000). the bank reconciliation, and a hard project deadline three weeks out. Then ransom is set at $65,000 – calculated, not random. Low enough that paying is faster than fighting. High enough to be worth the time.
The encryption payload deploys at 2:47pm on a Friday. The bookkeeper leaves at 3pm on Fridays. By the time anyone understands what happened, it is Friday evening and every file on the shared drive is encrypted.
The timing, the ransom amount, the target – all calculated using information sitting in the inbox before a single file was encrypted.
Five Controls That Would Have Stopped This Attack
One setting in the Microsoft 365 admin center. The email reading dwell time never happens.
Three Questions to Ask Your IT Provider
- Are we using phishing-resistant MFA for finance, admin, and executive accounts?
- Is external email forwarding blocked at the tenant level in our Microsoft 365 environment?
- Are our security alerts going somewhere, and is someone reviewing them on a regular schedule?
If your IT provider cannot answer all three with specifics, that conversation is worth having before the next breach in your industry makes the news.
(978) 466-1938 | cleartechgroup.com