Most ransomware operators target small businesses by volume. A firm of 10 to 50 people sits in their preferred range – enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research.
What follows is a composite walkthrough of how that kind of attack works, written from the attacker’s point of view. The figures are euro equivalents drawn from current threat intelligence. After the walkthrough are five specific places the attack would have died – each one a control already bundled into security tools your firm probably already pays for.
Monday: picking the target
I work regular hours and run about 40 prospects a month, all in the 10-to-50-staff range. The economics are better than chasing either large enterprises or sole traders.
I didn’t find you through a breach. I found you on the Companies Registration Office and cross-checked your principals’ names on LinkedIn. One sitting produced your firm’s name, the partners, and a sense of what kind of clients you act for.
The fact that nothing has ever gone publicly wrong at your firm is, for me, a positive signal. It means your passwords probably haven’t been rotated and nobody is suspicious of anything.
Tuesday: building your org chart for free
About 40 minutes on this.
LinkedIn gave me eight of your current people with job titles. Your office manager has been with you six years and lists “supplier invoicing and payroll” in her profile summary. Your bookkeeper joined fourteen months ago. You list yourself as managing partner with a sparse profile, which tells me you’re unlikely to notice someone unusual liking your firm’s posts.
A “meet the team” piece from two years ago on your firm’s news page gave me first names and faces. Job ads on Indeed mentioned “experience with Sage or Xero,” which tells me what to imitate in a phishing email.
Your office manager is my primary target. You’re harder to reach and more likely to be cautious. She has the access, handles supplier payments, and is busy enough that one more email in her inbox doesn’t get scrutinised.
Spend so far: nothing.
Wednesday: I bought your credentials for €13
Stealer logs are bundles of credentials harvested by infostealer malware that infected someone’s personal device, often months or years earlier. Marketplaces let buyers search by company email domain.
Two results came back. One is your office manager’s work email, with a password that looks like it was saved in her browser. The other is a personal Gmail address that appears to belong to a family member, probably from a device that shared a home network.
I paid €13. Took four minutes.
Her password follows a common pattern: a pet’s name, a year, an exclamation mark. The same password, with small variations, shows up on a streaming service and your firm’s Microsoft 365 login. It still works. All that stands between me and the inbox is the second factor.
Thursday: getting past your MFA
Simple push-notification spam doesn’t work any more – Microsoft turned on number matching by default in May 2023, so your office manager would have to type a code from her login screen rather than tap approve.
What still works is adversary-in-the-middle phishing. I send her an email designed to look like a routine Microsoft 365 password reset, referencing the breach her password actually appeared in. The link goes to a page that mirrors the real Microsoft sign-in. That page is a proxy I control.
When she enters her password and approves the MFA prompt, my proxy forwards both to the real Microsoft login server. Microsoft validates everything and issues a session token back. I capture it. She sees a normal login experience on what she thinks is the real Microsoft site, then a “password updated successfully” message.
I’m now signed in as her. Microsoft sees a valid authenticated session and treats my activity as legitimate.
Friday, 2:47pm: why I waited 36 hours
I spend 36 hours reading email before encrypting anything. Dwell time is how I size the ransom correctly.
In that time I find your cyber insurance policy with a €250,000 sub-limit, a bank reconciliation showing your operating account near €170,000 at month end, and a thread with a client about a deal completing in three weeks. I also set up an inbox forwarding rule that copies her emails to me, so I can keep reading.
I set the ransom at €60,000 – low enough that you’ll pay rather than fight it, high enough to be worth my time, and below the threshold where ransoms tend to get contested.
I deploy at 2:47 pm on Friday. Your bookkeeper finishes at 3. Your office is winding down and you’re with a client. By the time anyone understands what’s happening, every file on the shared drive is encrypted and a ransom note is on every screen.
Total cost to me: €13 for credentials and about six hours of work over the week.
Five places the attack would have died
The attack worked because five ordinary things were not in place. None of them are expensive. Most are already bundled into security tools your firm probably already pays for.
- The credential purchase.
Microsoft Entra password protection can detect and block reused or commonly-compromised passwords. Combined with a password manager and unique passwords per account, the €13 stealer log buys nothing. - The MFA bypass.
Phishing-resistant MFA – FIDO2 keys, passkeys or Windows Hello for Business – defeats the proxy. So does a Conditional Access policy that requires a compliant or hybrid-joined device. Either one would have stopped the session token from being captured or used. - The inbox forwarding rule.
Microsoft 365 lets administrators block external forwarding rules at the tenant level. With that block in place, the rule I used to read 36 hours of email simply wouldn’t have worked. I might have encrypted anyway, but I’d have been guessing on the ransom size. - The 36-hour dwell time.
Microsoft Defender for Business, included in M365 Business Premium, raises an alert the moment a new inbox forwarding rule is created. The single most useful change for a firm of this size is rarely a new product purchase – it’s someone reviewing the alerts the tools you already pay for are already generating. - The public records.
You can’t unpublish the CRO or eTenders. What you can control is what your team chooses to post about their specific responsibilities. Your office manager’s LinkedIn profile listed her financial responsibilities in enough detail to make her the obvious target. That’s a five-minute conversation with the team, framed as practical awareness rather than a rule.
Three questions to send your IT provider
These three cover most of where the example attack failed.
- Are we using phishing-resistant MFA for finance, admin and partner-level logins?
- Is external email forwarding blocked at the tenant level?
- Are our security alerts going somewhere, and is someone reviewing them?
If you’d like us to check those three things in your environment, get in touch and we’ll take a look.

