Mon – Fri  9AM – 5PM|Client Portal
ITstuffed
Cybersecurity

How a Ransomware Attack on a Small Business Actually Works

Most small business owners assume ransomware is a problem for hospitals and banks. It is not. The businesses that get hit most often employ between 10 and 50 people, have enough revenue to make a payout worthwhile, and no dedicated security team to stop it. A 22-person professional services business is not too small to target. It is exactly the right size.

What follows is a step-by-step account of how that attack unfolds - written from the attacker's perspective. The scenario is composite, but every method described reflects how these attacks actually work. At the end, there are five specific points where the attack would have stopped. None of them required expensive new tools.

On the first day, the attacker finds you through a public business records portal. Not a data breach. Not a tip-off. A standard business search. Your company name, your name, an estimate of your revenue, and the name of whoever submitted your last contract tender - all public. The fact that nothing has gone wrong at your business yet is the first signal they look for. It suggests your passwords are probably unchanged and your staff have not been through any security training.

By the second day, they have spent 40 minutes on LinkedIn and Facebook building a picture of your team. They know who handles your accounts payable. They know how long she has been there. They know which accounting software she probably uses, because they checked your last job ad on Seek. They know who can approve a payment without a second signature. That person becomes the primary target - not you, because you are harder to reach. Your accounts person is busy, has full system access, and is unlikely to scrutinise one more email in an already full inbox.

On the third day, the attacker buys her credentials for $14. Infostealer malware - the kind that spreads through pirated software and dodgy browser extensions - harvests saved passwords from personal devices and bundles them for sale on Telegram channels and private forums. A search of your company's email domain returns two results. One is her work email with a saved browser password. The password follows a pattern common enough that it appeared in a retail loyalty programme breach three years earlier and was never changed. Total spend so far: $14 and about an hour of work.

The multi-factor authentication - the extra code she has to enter when logging in - does not stop the attack. It slows it down for about a day. The attacker sends her an email designed to look like a Microsoft 365 security alert, linking to a page that mirrors the real Microsoft login screen. That page is a proxy the attacker controls. When she enters her password and approves the login prompt, the proxy captures the resulting session token - the digital key that tells Microsoft "this is a legitimate, already-verified session." Microsoft sees a valid login. The attacker is now inside her account. She sees a normal password-updated confirmation screen and moves on with her day.

The attacker then sets up a silent forwarding rule so every email she receives copies to an address they control. They do not encrypt anything yet. They spend 36 hours reading her inbox.

In those 36 hours, they find her cyber insurance policy with a $250,000 liability sub-limit. They find a bank reconciliation showing roughly $180,000 in the business account at month end. They find a municipal project starting in three weeks with a hard deadline. They set the ransom at $65,000 - low enough that paying is easier than fighting, high enough to be worth the effort, and well within what they can see you have access to.

The encryption payload goes out at 2:47pm on a Friday. The accounts person finishes at 3pm on Fridays. The business owner is on a job site. By the time anyone understands what has happened, it is Friday evening, every file on the shared drive is locked, and a ransom note is on every screen in the office. If you have been through something like this, the steps to take immediately after a breach are worth having close to hand.

Total cost to the attacker: $14 and about six hours of work spread across a week.

Now here are the five points where the attack would have died.

The credential purchase on day three only worked because the password was reused and had never been changed after a known breach. Microsoft 365 includes tools - specifically Microsoft Entra password protection - that can detect and block compromised or commonly reused passwords across your accounts. A password manager enforcing unique passwords per account makes a stolen credential package worthless. HaveIBeenPwned, the same database the attacker used to verify the password, is free and available to anyone who wants to check. If you want to understand what happens after credentials surface somewhere they should not, finding your data on the dark web is a practical place to start.

The MFA bypass worked because standard push-notification approval was in place. Microsoft has actually addressed the simpler version of this attack - since May 2023, Microsoft Authenticator requires number matching by default, meaning a user has to type a code rather than just tap approve. But the proxy-based attack described here bypasses that. Phishing-resistant MFA - using a hardware security key, a passkey, or Windows Hello for Business - stops it, because the authentication is tied to the specific website being visited, not a code that can be relayed through a proxy. Conditional Access policies that only allow login from a known, compliant device add another layer on top of that.

The forwarding rule that gave the attacker 36 hours of email access can be blocked at the tenant level in Microsoft 365. It is a configuration setting, not a new product. With that block in place, the attacker would have been flying blind on the ransom amount.

Microsoft Defender for Business - included in Microsoft 365 Business Premium - generates an alert when a new inbox forwarding rule is created. If someone had been watching those alerts on Thursday night, the attack would have been detected before a single file was encrypted. The most impactful change for a business this size is rarely a new software purchase. It is having someone actually review the alerts that the tools already in place are already generating. That is exactly what a managed IT support arrangement covers.

The public business records will stay public - you cannot unpublish a government contracting registry. What you can influence is what your team chooses to share about their specific responsibilities. A LinkedIn profile listing "accounts payable, payroll, and supplier invoicing" is a target brief. That is worth a conversation with your team - not a policy, just an awareness discussion about what level of detail is worth posting publicly.

If any part of this walkthrough sounded like your business, start with three questions to whoever manages your IT. Are you using phishing-resistant MFA for finance and admin logins? Is external email forwarding blocked at the tenant level? Are your security alerts going somewhere, and is someone reviewing them? A competent IT engineer should be able to confirm the answers within an hour or two. It is also worth knowing that the mistakes businesses make after a breach often compound the original damage significantly. For more on what a proactive security setup looks like in practice, the ITstuffed cyber security page covers the controls Canterbury businesses should have in place.

If you are not sure where your business sits, ITstuffed offers a 15-minute IT Fit Check at itstuffed.co.nz/booking - no preparation needed on your end.