Small Business Ransomware: How Attacks Happen and How to Prevent Them

Getting your Trinity Audio player ready...

Many small business owners assume cybercriminals focus on large corporations. In reality, small businesses are among the most common ransomware targets because they often have valuable data, limited IT resources, and fewer security controls in place.

Microsoft provides an overview of how ransomware works and why layered security is essential for protecting organizations from modern attacks.

A business with 20 or 30 employees can be just as attractive to an attacker as a larger organization. Customer records, financial information, payroll systems, and Microsoft 365 accounts all have value, and criminals know it.

The walkthrough below explains how a modern ransomware attack can unfold from the attacker’s point of view. While the company described is fictional, the techniques are based on real-world attack methods observed by today’s cybersecurity professionals.

Afterward, we’ll highlight five points where the attack could have been stopped using security features many businesses already own but may not be fully utilizing.

Day One: Choosing the Right Target

I don’t waste time chasing giant corporations. They have dedicated security teams, incident response plans, and specialists ready to respond.

Instead, I look for businesses with roughly 10 to 50 employees.

They typically have enough revenue to justify paying a ransom but often lack full-time cybersecurity staff. That makes them ideal targets.

Finding potential victims is surprisingly easy.

Public business registries, government contract databases, licensing records, and company websites provide plenty of information. Within minutes I can learn:

  • Company name
  • Estimated size
  • Business owner
  • Recent projects
  • Revenue indicators
  • Key decision makers

Ironically, companies that have never experienced a cyberattack often appear even more appealing. There’s a good chance passwords haven’t been updated recently, security awareness training is limited, and employees haven’t developed a healthy skepticism toward unexpected emails.

That’s exactly what I’m hoping for.

Day Two: Learning Everything About Your Team

Today I spend less than an hour gathering intelligence using nothing more than publicly available information.

LinkedIn quickly reveals employee names, job titles, and responsibilities.

Your office manager mentions handling payroll, accounts payable, and vendor invoices.

A “Meet Our Team” post on Facebook introduces additional staff members and includes photos.

Business filings confirm ownership information.

Job postings reveal the software you likely use every day, whether it’s QuickBooks, Sage, Microsoft 365, or another business platform.

At this point I already know:

  • Who controls company finances
  • Who processes payments
  • Who has administrative access
  • Who is most likely to approve requests without questioning them

The business owner isn’t always my primary target.

Busy office managers and administrators usually have broad access to systems while juggling dozens of daily tasks. A convincing email is much more likely to blend into their workload.

Best of all, my research hasn’t cost me anything.

Day Three: Purchasing Stolen Credentials

Today’s investment is minimal.

Cybercriminal marketplaces sell credential packages collected by infostealer malware that infected someone’s personal computer months, or even years, ago.

These stolen credentials often include saved usernames and passwords from web browsers.

I search for your company’s email domain.

Two matching accounts appear.

One belongs to your office manager.

The password looks familiar because it follows a common pattern, a family name, a birth year, and a special character.

A quick search confirms it previously appeared in a public data breach.

That tells me the password may have been reused elsewhere.

Another set of credentials belongs to someone connected to the business owner through a personal account.

After trying a few password variations, one successfully authenticates against Microsoft 365.

Now only multi-factor authentication stands between me and your business.

For less than twenty dollars, I’ve positioned myself to compromise your environment.

Day Four: Working Around Multi-Factor Authentication

Multi-factor authentication (MFA) is one of the strongest security controls available, but only when it’s implemented correctly.

Simple MFA fatigue attacks are far less effective today thanks to Microsoft’s number-matching requirement in Microsoft Authenticator.

So I use a more sophisticated approach.

I send an email that appears to be an official Microsoft 365 security notification explaining that the user’s password may have been exposed during a recent breach.

The message includes what appears to be a legitimate Microsoft sign-in link.

It isn’t.

Instead, it leads to a phishing proxy that perfectly mirrors Microsoft’s login page.

The employee signs in normally.

They complete the MFA prompt.

Everything appears legitimate.

Behind the scenes, my phishing server captures the authenticated session token that Microsoft issues after successful login.

I never need their password again.

Microsoft sees a valid authenticated session, so my activity appears trustworthy.

If the phishing email fails, I have another option.

Earlier in the day I call the office pretending to represent the company’s IT provider.

Using publicly available information, I reference a technician’s name and explain that unusual login activity requires a verification prompt.

Social engineering often succeeds simply because employees want to be helpful.

By the end of the day, I have access to the Microsoft 365 account.

I quietly create an email forwarding rule that sends copies of messages to my own mailbox without alerting the user.

Then I wait.

Day Five: Why the Attack Happens Late on Friday

Once I have access, I don’t immediately launch the ransomware.

Instead, I spend the next day and a half quietly observing your business.

I read emails, learn how your company operates, identify key customers, and estimate how much downtime you can afford before it becomes a serious financial problem.

During that time, I discover:

  • Your cyber insurance policy and coverage limits
  • Recent bank reconciliations
  • Customer and vendor relationships
  • Upcoming project deadlines
  • Internal approval processes
  • Financial documents stored in email

With this information, I can calculate a ransom amount that’s painful, but still affordable enough that paying seems like the quickest option.

Timing is equally important.

Late Friday afternoon is ideal.

Employees are heading home, decision-makers are unavailable, and many IT providers have reduced staffing after business hours.

When the ransomware is deployed, shared drives become encrypted, employees lose access to critical files, and ransom notes appear across the network.

By the time anyone notices, valuable hours have already been lost.

The entire operation required very little money and only a handful of hours spread across the week.

Five Small Business Ransomware Defenses That Could Have Stopped This Attack

The good news is that this attack wasn’t inevitable.

Several security controls could have interrupted the attack long before ransomware was ever deployed. Many of these protections are already included with Microsoft 365 Business Premium and other business security solutions.

1. Prevent the Use of Stolen Passwords

The attack gained momentum because compromised credentials were still valid.

Organizations should require unique passwords for every account, enforce strong password policies, and use password managers whenever possible.

Microsoft Entra Password Protection can also help prevent employees from using passwords that have already been exposed in known data breaches.

2. Strengthen Multi-Factor Authentication

Modern attackers don’t just steal passwords, they try to bypass MFA.

Phishing-resistant authentication methods such as passkeys, FIDO2 security keys, and Windows Hello for Business dramatically reduce this risk.

Pairing these methods with Conditional Access policies and Microsoft Defender for Office 365 adds additional layers of protection that make stolen session tokens far less useful.

3. Block Automatic Email Forwarding

One of the attacker’s biggest advantages came from silently forwarding email outside the organization.

Microsoft 365 administrators can disable external email forwarding across the tenant, preventing attackers from secretly monitoring conversations and gathering intelligence after compromising an account.

4. Monitor Security Alerts Consistently

Security tools are only effective when someone is paying attention.

Microsoft Defender for Business can generate alerts when suspicious activities occur, including the creation of unexpected inbox forwarding rules or unusual login behavior.

Regularly reviewing these alerts allows organizations to detect attackers before ransomware is deployed.

5. Reduce Publicly Available Information

Businesses can’t remove public records or government filings.

However, employees can be more mindful about the information they share online.

Detailed job descriptions, software names, financial responsibilities, and internal processes posted on LinkedIn or social media make it much easier for attackers to identify the best person to target.

A little awareness can significantly reduce your organization’s exposure.

Three Questions to Ask Your IT Provider

If you’re unsure whether your business is protected against today’s ransomware threats, start by asking your IT provider these three questions:

  1. Are phishing-resistant authentication methods, such as passkeys, FIDO2 security keys, or Windows Hello for Business, enabled for employees with access to financial, administrative, or executive accounts?
  2. Is external email forwarding blocked across our Microsoft 365 environment?
  3. Who reviews our security alerts, and how quickly are suspicious activities investigated?

If the answers aren’t clear, it’s worth having a conversation about strengthening your cybersecurity posture before attackers find the gaps first.

Cybercriminals don’t always rely on sophisticated hacking techniques. More often, they succeed by taking advantage of small security oversights, publicly available information, and stolen passwords that were never changed.

Taking a proactive approach today can help prevent costly downtime, financial losses, and disruption tomorrow.

To learn how Twintel can help protect your business from ransomware and other evolving cyber threats, contact our team today for a cybersecurity assessment.

Twintel Logo
+ posts

Twintel has grown into an expansive, full team of IT services professionals, acting as the outsourced IT department of non-profits, small to mid-size businesses, and enterprise-level corporations in Orange County, across California, and nationally.

Today, it’s the strength and deep expertise of the Twintel team that drives positive outcomes for clients. Each of the support staff, technicians, and engineers works diligently each day to make sure that the companies served have the seamless, secure, and stable IT environments needed to allow them to pursue their organizational objectives.

Learn more...