Cyclone 365

Dependable Service. Consistent Results.

With over 25 years of industry experience, we provide a wide range of IT services for small and medium-sized businesses on the Gulf Coast.

Open weekdays from 9am to 5pm.

In-person office meetings by appointment only.

How a Small Business Gets Ransomed in a Single Week

Most owners assume ransomware crews are chasing hospitals, banks, and national retailers. The incident numbers say otherwise. Small businesses are the most common ransomware target by volume, and the preferred range sits between 10 and 50 staff. A company that size has payroll, a customer database, project files, and an owner who will pay to get all of it back. What it usually does not have is a dedicated security team.

Here is how the week unfolds, written from the attacker's side. The company is composite, but the methods match current threat intelligence.

Monday, target selection. No breach and no inside tip. Public records do the work. State business registries, federal contract awards, and county licensing databases publish company names, registered agents, contract values, and named contacts. For a 22-person commercial services firm with a recent municipal job on file, a single search produces enough to begin. A clean incident history is a selling point to an attacker, because it suggests credentials are still valid and staff have never been trained to question anything.

Tuesday, the free org chart. Forty minutes in a browser is enough. LinkedIn supplies employee names and titles, including an office manager who lists accounts payable, payroll, and supplier invoicing in her profile. An old team photo post fills in the rest. Job listings mentioning QuickBooks or Sage reveal the accounting stack. The person who can approve a payment without a second signature becomes the primary target, not the owner.

Wednesday, fourteen dollars. Stealer logs are credential bundles harvested by malware from personal devices, then sold and searchable by company email domain. Two hits come back for this business. The office manager's password matches a pattern of a name plus a year plus a punctuation mark, and it already appeared in a retail breach three years ago. It was never changed. Password reuse across personal and business accounts is what turns a $14 purchase into full access.

Thursday, around the MFA. Push fatigue attacks largely stopped working once Microsoft enabled number matching by default for Authenticator notifications in May 2023. What still works is adversary-in-the-middle phishing. A convincing password reset email leads to a proxy page mirroring the real Microsoft sign-in screen. The victim enters her password, approves the prompt, and Microsoft issues a valid session token straight into the attacker's browser. The MFA challenge succeeds, and the attacker is signed in anyway. An inbox forwarding rule goes in quietly, and then the waiting starts.

Friday at 2:47pm. Thirty six hours of reading email is how the ransom gets priced. The cyber insurance policy shows a $250,000 sub limit. A bank reconciliation shows roughly $180,000 in the operating account. A message thread reveals a project with a hard deadline three weeks out. The demand lands at $65,000, deliberately low enough to be paid without a fight. The payload deploys on Friday afternoon, after the bookkeeper leaves and while the owner is on a job site. Total attacker spend, $14 and about six hours.

Five ordinary controls would have ended this. Enforcing unique passwords through a password manager and Microsoft Entra password protection makes purchased credentials worthless. Phishing-resistant MFA using FIDO2 keys, passkeys, or Windows Hello for Business defeats the session token capture, as do Conditional Access policies requiring a compliant device. Blocking external email forwarding at the tenant level removes the attacker's window into your inbox. Microsoft Defender for Business generates an alert the moment a forwarding rule is created, which means the detection existed and simply went unread. Finally, a practical conversation with your team about how much job detail belongs in a public profile removes the easy targeting.

Four of those five come bundled with licenses that most businesses in this size range already hold. The gap is rarely a missing product. It is configuration and attention.

If you want a straight answer on where you stand, ask your IT provider three things. Are we using phishing-resistant MFA for finance, admin, and executive logins? Is external email forwarding blocked at the tenant level? Are our security alerts going somewhere, and is somebody actually reviewing them?

Cyclone 365 works with contractors, professional services firms, and family owned businesses across the Gulf Coast to answer those questions properly, tighten Microsoft 365 configurations, and make sure the alerts your tools generate reach a human being. Reach out and we will walk your environment with you. Call or Email us today!

We provide IT support and services in and around these areas:

Mobile, AL Pensacola, FL Pascagoula, MS
Daphne, AL Fort Walton Beach, FL Gautier, MS
Fairhope, AL Destin, FL Ocean Springs, MS
Foley, AL Panama City, FL Biloxi, MS
Gulf Shores, AL Tallahassee, FL Gulfport, MS
Orange Beach, AL Lake City, FL Pass Christian, MS

★ Copyright © MMXXI. All rights reserved. ★