Cybersecurity
How Ransomware Attackers Target Small Businesses
This composite walkthrough follows a week-long ransomware attack from public-records research to session-token theft, then shows where layered identity, email, and monitoring controls could interrupt or limit the attack.
Small businesses face meaningful ransomware risk even though many owners assume attackers focus only on larger organizations. Smaller teams can still hold valuable payroll, customer, project, and supplier data while operating with limited security resources.
What follows is a step-by-step walkthrough of how a small business can be attacked, written from the attacker's side. The company, timeline, headcount, prices, ransom figures, and other numerical details are illustrative elements of a composite scenario. The attack methods and defensive controls reflect documented techniques and current vendor guidance. After the walkthrough, you'll see five points where layered controls could have interrupted or limited the attack.
Monday: How I Picked You
In this composite scenario, I run a volume operation and add a 22-person commercial services company to my prospect list. The company has payroll, customer records, project files, and supplier relationships, but no dedicated security team. Those characteristics can make a smaller organization attractive to an attacker without implying that any particular employee-count range is uniquely targeted.
I did not find you through a breach or a tip. I found you on a public business records portal. State business registries, federal contract awards, and county-level licensing databases publish enough detail for me to identify your company, look up your name, estimate your revenue, and pick the most useful person inside the business. One search told me your company name, your registered agent, the contract value of a recent municipal job, and the named contact on the submission.
I find no public report of a prior incident. That does not prove anything about the company's internal controls, but an attacker may interpret the absence of visible security messaging as a reason to keep researching.
Tuesday: Building Your Org Chart for Free
I spend about 40 minutes researching your company today using only a browser.
LinkedIn gives me eight of your current employees with their job titles listed. Your office manager has been there for six years and lists "accounts payable, payroll, and supplier invoicing" in her profile summary. Your second admin joined 14 months ago. You list yourself as director, with a sparse profile and a low connection count, which tells me you are unlikely to notice when someone unusual starts engaging with your profile or your company's social media.
Public business filings confirm your registered business name and your full legal name. A "meet the team" post from two years ago on your Facebook page lists first names and photos, including someone described as helping out in the office a couple of days a week. One of the commenters shares your surname.
I now know who handles your money, what their name is, how long they have been there, what software they probably use (I will check your job ads on Indeed for the phrase "experience with QuickBooks or Sage"), and who in your business has the authority to approve a payment without a second signature.
That last person is my primary target. You are harder to reach and probably more cautious. Your office manager has system access, handles supplier payments, and is busy enough that one more email in her inbox does not get scrutinized the way it might if she had nothing else to do.
I have not spent a dollar yet.
Wednesday: I Bought Your Credentials for $14
Stealer logs are data packages harvested by infostealer malware on an infected device, sometimes months or years earlier. Depending on the malware and device, a log can contain browser-saved credentials, cookies, tokens, and other captured data. Criminal marketplaces may let buyers search available logs by company email domain.
I search for your company's email domain. One matching stealer package contains your office manager's work email, with a password that looks like it was saved in her browser. The same browser profile also contains a personal Gmail address that appears to belong to her, based on the matching name and account-recovery details included in this composite scenario.
For this illustrative scenario, I pay $14 for the package. The actual price and availability of stolen data vary widely.
Your office manager's password follows a common pattern: a pet or child's name combined with a year and an exclamation mark. A check against the free Have I Been Pwned Pwned Passwords service shows that the password value has appeared in known breach data. That check does not identify which person or breach used it, but it confirms the password should not be trusted.
Your office manager's personal credentials are more interesting than they look at first. The same password, with minor variations, appears across a streaming service, a gaming account, and her company Microsoft 365 login. The work password succeeds. The only thing standing between me and her inbox is the second factor.
Illustrative spend so far: $14.
Thursday: Getting Past Your MFA
Multi-factor authentication stops a lot of attacks, but the implementation matters more than the checkbox.
Simple push-notification fatigue does not work against your office manager's account. Microsoft enabled number matching by default for all Microsoft Authenticator push notifications in May 2023, which means she would have to type a code from her login screen rather than just tap approve. Push bombing fails against that configuration.
A threat that can still bypass many MFA implementations is adversary-in-the-middle (AiTM) phishing. I send your office manager an email designed to look like a routine Microsoft 365 security-verification notice, using the company name and public details gathered earlier in the week to make the pretext credible. The link in the email takes her to a page that mirrors the real Microsoft sign-in screen. That page is a proxy I control.
When she enters her password and approves her MFA prompt, my proxy forwards both to the real Microsoft login server. Microsoft validates the credentials, completes the MFA challenge, and issues a session token back to my proxy. I capture the token. She sees a normal login experience on what she thinks is the real Microsoft site, then a "password updated successfully" message.
I am now signed in as her. The MFA prompt succeeded, and the session token sits in my browser instead of hers. Microsoft sees a valid authenticated session and treats my activity as legitimate.
I had a backup plan in case the email did not get clicked. Earlier in the day, I called your office posing as your IT support company, using a name I found in a Google review you had left 18 months earlier. I told your receptionist that we were seeing unusual login activity on the office manager's account and that I would need her to approve a verification push in the next few minutes. She said the office manager was not at her desk. I said no problem, I would try again later. The call cost me nothing.
By Thursday morning, I am inside your office manager's Microsoft 365 account. I set up an inbox forwarding rule so her emails copy to an address I control without notifying her, then I wait.
The mailbox session alone cannot encrypt office computers or a shared drive. In this composite scenario, I find account messages for the company's remote-support portal, reset that portal password through the compromised inbox, and sign in because the portal has no additional authentication factor. The portal reaches the office manager's workstation. From that endpoint, an overly broad account and an unsegmented file share provide the execution and write access needed to spread beyond the mailbox. Those additional weaknesses—not Microsoft 365 access by itself—create the path to encryption.
Friday 3:17pm: Why I Waited Before Encrypting
I spend the rest of Thursday and much of Friday reading email before I encrypt anything. That dwell time is how I size the ransom correctly.
During that dwell time, I find your cyber insurance policy attached to an email from your broker, with a cyber liability sub-limit of $250,000. A bank reconciliation your office manager sent you two weeks ago shows your business account at around $180,000 at month end. Your customer list sits in a quote template she emailed to herself, and a message thread with a municipal project manager mentions a job starting in three weeks with a hard deadline you cannot afford to miss.
In this composite scenario, I set the ransom at $65,000 in cryptocurrency after reviewing the company's finances, insurance, and operational pressure. That amount is an illustrative narrative detail, not a universal ransom-pricing formula or prediction of whether a victim would pay.
Using the remote-support foothold established above, I deploy the encryption payload at 3:17pm on Friday. The timing is deliberate. Your bookkeeper finishes at 3pm on Fridays, which I know from an out-of-office reply I saw in the forwarded emails. You are on a job site, with your calendar synced to the shared inbox. The person most likely to notice something wrong and call for help has already left, and the person with the authority to make decisions is unreachable.
By the time anyone understands what has happened, it is a Friday evening, the files reachable through the shared drive are encrypted, and a ransom note appears on the compromised office manager's workstation and in the affected shared folders.
Illustrative cost in this scenario: $14 for credentials and about six hours of work spread across the week. Real attack costs, timelines, and criminal-market prices vary.
Five Places Layered Controls Could Interrupt or Limit This Attack
The attack in this composite scenario progressed because several defensive layers were missing, misconfigured, or unmonitored. Some controls may be configuration changes in an existing subscription; others can require additional licensing, hardware, or operational effort.
1The credential purchase on Wednesday
Endpoint protection, prompt patching, least privilege, application control, and user training can reduce the chance that infostealer malware succeeds. Avoiding browser-stored credentials can reduce what malware harvests, although it does not make an infected device safe. When exposed credentials are detected, reset them, revoke active sessions, and investigate and remediate the source device. Have I Been Pwned's Pwned Passwords check is free and can show that a password value appears in known breach data, but it does not identify the person or breach. Microsoft Entra Password Protection can block terms from Microsoft's global or custom banned-password lists; it does not detect reuse or recover a stolen current password.
2The MFA bypass
Microsoft reduced simpler push-bombing attacks by enabling number matching by default for Microsoft Authenticator push notifications in May 2023, but AiTM phishing can still steal an authenticated session. Layered defenses include phishing-resistant credentials such as FIDO2 security keys, passkeys, or Windows Hello for Business; Conditional Access policies that require an approved device; token protection where supported; and anti-phishing protection in Microsoft Defender for Office 365. Phishing-resistant credentials can prevent proxy-based credential capture, while device-bound token protections can reduce replay. No single control guarantees that every session-theft attempt will fail.
3The inbox forwarding rule
Microsoft 365 allows administrators to restrict or block automatic external forwarding at the tenant level. With the appropriate outbound policy in place, external delivery from the rule in this scenario would be blocked, although an attacker with an active session could still read the mailbox interactively.
4The mailbox dwell time
Microsoft 365 alert policies can generate a "Creation of forwarding/redirect rule" alert. That alert capability is available in Microsoft 365 Business Premium through Microsoft Defender for Office 365 Plan 1; Microsoft Defender for Business is the endpoint-security component of the suite. The alert only helps when notifications are routed to someone who reviews and investigates them.
5The public business records
You cannot unpublish a state contracting registry or a federal contract award. That data will stay public. What you can control is what your team chooses to post about their specific responsibilities. Your office manager's LinkedIn profile listed her financial responsibilities in enough detail to make her the obvious target. That detail is worth a conversation with your team, framed as practical security awareness rather than a rule about what people can post.
Three Questions to Send Your IT Provider
These three questions cover central control areas in the example attack. Availability and cost depend on the organization's subscriptions, device platforms, identity design, and monitoring process.
1. Are we using phishing-resistant MFA (FIDO2 keys, passkeys, or Windows Hello for Business) for finance, admin, and executive logins?
2. Is external email forwarding blocked at the tenant level?
3. Are our security alerts going somewhere, and is someone reviewing them?
Reviewing Your Current Controls
Cyber One Solutions works with businesses on the controls in this walkthrough: phishing-resistant MFA and conditional access, Microsoft 365 tenant hardening, endpoint detection and response, and someone reviewing the alerts available in your configured environment. If you want to know which of these are configured in your environment today, contact us for a review.
Article FAQs
Do hackers target small businesses?
Yes. Attackers target organizations of many sizes, and a small business can still hold valuable data, money, and operational leverage. Risk depends on exposed identities, systems, controls, and attacker opportunity—not a universal employee-count "sweet spot."
What is adversary-in-the-middle (AiTM) phishing?
AiTM phishing is a technique where the attacker hosts a proxy page that mirrors a real login screen, such as Microsoft 365 or Google Workspace. When the user enters credentials and completes an MFA prompt, the proxy can capture the resulting session token. The legitimate service treats the login as successful, but the attacker may be able to replay the stolen session. Number matching reduces simpler push-bombing attacks, but it does not by itself prevent AiTM phishing.
What is a stealer log?
A stealer log is a package of data harvested by infostealer malware from an infected device. Depending on the malware and device, a log can include browser-saved passwords, session cookies, and stored authentication tokens. Criminal-market prices vary, and common infection paths include malicious downloads, pirated software, and harmful browser extensions.
How much does it cost an attacker to compromise a small business?
The $14 and six-hour figures in the walkthrough are illustrative, not an estimate for every attack. Costs vary by access method, tooling, target, and criminal market, but stolen data and commodity phishing infrastructure can make attempted compromise inexpensive.
Are there free tools that would have stopped this attack?
Some controls in the walkthrough may already be available in Microsoft 365 Business Premium, depending on the exact feature and configuration. External-forwarding restrictions and Microsoft 365 alert policies are configuration changes where licensed. Have I Been Pwned's password check is free. Phishing-resistant MFA may use built-in platform credentials or separately purchased hardware keys.
