Article Summary: Most ransomware operations target small businesses at volume, running through dozens of prospects per month. A 22-person company can be researched in 40 minutes using public records, attacked using session-token theft after a single phishing click, and ransomed within a week. What follows is a step-by-step walkthrough of how that attack unfolds, written from the attacker’s perspective, plus the five specific controls that would have stopped it. Each control is included in security tools small businesses already pay for.

Small businesses account for the highest volume of ransomware incidents, even though many owners assume hackers focus on larger organizations. A 22-person company has enough revenue to be a worthwhile target, no dedicated security team to defend it, and a public footprint that takes about an hour to research.

What follows is a step-by-step walkthrough of how a small business gets attacked, written from the attacker’s perspective. The company in this example is fictional, but the tactics reflect current threat intelligence reporting. After the walkthrough, you’ll see five points where the attack could have been stopped using security controls that are often included with tools small businesses already pay for.

Monday: How I Picked You

I work regular hours and run a low-volume operation. My spreadsheet contains about 40 prospects each month, and I prefer businesses with 10 to 50 employees. The reason is simple: economics.

Large enterprises have security teams, incident response retainers, and legal resources that make recovery difficult and expensive for me. At the other end of the spectrum, sole proprietors rarely have enough assets at stake to justify the effort. A 22-person commercial services company is ideal: payroll, customer data, project files, supplier relationships, and an owner likely to pay to recover operations. The return on investment is better than at either extreme.

I did not find you through a breach or a tip. I found you on a public business records portal. State business registries, federal contract awards, and county licensing databases publish enough information for me to identify your company, estimate revenue, and identify useful contacts.

One search revealed your company name, registered agent, the value of a recent municipal contract, and the contact listed on the submission.

The fact that nothing has gone wrong at your company yet is one of my strongest indicators. It suggests your credentials are still valid, staff have not been exposed to recent security incidents, and no one has felt compelled to update passwords. A clean record is often the first signal I look for.

Tuesday: Building Your Org Chart for Free

Today, I spend about 40 minutes researching your company using nothing more than a web browser.

LinkedIn shows eight employees with job titles. Your office manager has been with the company for six years and lists responsibilities including accounts payable, payroll, and supplier invoicing. A second administrator joined 14 months ago. Your profile as director is sparse and has relatively few connections, suggesting you’re less likely to notice unusual engagement with your profile or company social media accounts.

Public business filings confirm your registered business name and full legal name. A “Meet the Team” Facebook post from two years ago includes first names and photos, including someone described as helping in the office a few days a week. One commenter shares your surname.

I now know who handles your finances, how long they have been there, what software they likely use, and who can approve payments without a second signature.

That person becomes my primary target. You are harder to reach and probably more cautious. Your office manager has system access, manages supplier payments, and receives enough email that one more message is unlikely to attract scrutiny.

So far, I haven’t spent a dollar.

Wednesday: I Bought Your Credentials for $14

Stealer logs are collections of credentials harvested by infostealer malware, often from personal devices infected months or years earlier. The malware records usernames and passwords, then packages the data for sale. Buyers can search these databases by company email domain.

I search for your company’s email domain and find two results. One belongs to your office manager and includes what appears to be a browser-saved password. The other is a personal Gmail account that appears to belong to a family member.

I pay $14 for the package. The purchase takes four minutes.

Your office manager’s password follows a common pattern: a pet or child’s name, a year, and an exclamation point. I check it against HaveIBeenPwned and discover it appeared in a credential dump from a retail loyalty program breach three years ago. The password has never been changed.

The family member’s credentials are even more useful. Variations of the same password appear across multiple online accounts, including a Microsoft 365 login. The password works. The only remaining barrier is multifactor authentication.

Total spend so far: $14.

Thursday: Getting Past Your MFA

Multifactor authentication stops many attacks, but how it is implemented matters.

Simple MFA fatigue attacks do not work against your office manager’s account. Microsoft enabled number matching by default for Microsoft Authenticator push notifications in May 2023, so she must enter a code from the login screen rather than tap Approve. That blocks basic push-bombing attempts.

What still works is adversary-in-the-middle (AiTM) phishing.

I send an email that appears to be a routine Microsoft 365 password reset notification, referencing the breach where her password was exposed. The message links to a page that looks identical to Microsoft’s sign-in screen, but it is actually a proxy under my control.

When she enters her password and completes the MFA challenge, my proxy relays the information to Microsoft’s servers. Microsoft validates the login and issues a session token. My proxy captures that token.

She sees what appears to be a normal login process followed by a “password updated successfully” message.

I am now signed in as her. Microsoft sees a valid authenticated session and treats my activity as legitimate.

I also prepared a backup plan. Earlier that day, I called your office pretending to represent your IT provider, using a name I found in a Google review posted 18 months earlier. I told your receptionist we had detected unusual login activity and would need the office manager to approve a verification request. She said the office manager was away from her desk. I said I would call back later.

The call cost nothing.

By Thursday evening, I am inside the Microsoft 365 account. I create an inbox forwarding rule that silently copies emails to an address I control and then wait.

Friday, 2:47 p.m.: Why I Waited 36 Hours Before Encrypting

I spend 36 hours reading email before encrypting anything. That dwell time helps me determine the right ransom amount.

During those 36 hours, I find a cyber insurance policy showing a cyber liability sub-limit of $250,000. A recent bank reconciliation indicates approximately $180,000 in the business account at month end. A customer list appears in an emailed quote template, and a project email references a municipal contract with a deadline three weeks away.

I set the ransom at $65,000 in cryptocurrency. The amount is low enough to encourage payment, high enough to justify the effort, and comfortably within available resources. Demands exceeding 10 percent of visible liquid assets are more likely to be challenged.

I deploy the ransomware at 2:47 p.m. on Friday.

The timing is deliberate. Your bookkeeper finishes at 3 p.m., which I learned from an out-of-office message. You are on a job site, according to your shared calendar. The people most likely to identify the issue and respond quickly are unavailable.

By the time anyone understands what has happened, it is Friday evening, shared drives are encrypted, and a ransom note appears on every screen.

Total cost to me: $14 and roughly six hours of work spread across the week.

Five Places This Attack Would Have Failed

The attack succeeded because five ordinary security controls were missing. None are particularly expensive, and most are already included in tools many businesses use.

1. The Credential Purchase

HaveIBeenPwned is free. Microsoft Entra Password Protection can detect and block commonly compromised or reused passwords. Enforcing unique passwords through password managers and Entra policies makes stolen credentials far less valuable.

2. The MFA Bypass

Microsoft already blocks basic MFA-fatigue attacks through number matching. The more common bypass today is AiTM phishing.

Effective defenses include phishing-resistant MFA such as FIDO2 security keys, passkeys, or Windows Hello for Business; Conditional Access policies requiring compliant devices; and Microsoft Defender for Office 365 anti-phishing protections. Any of these measures could have prevented token theft or rendered the stolen token useless.

3. The Inbox Forwarding Rule

Microsoft 365 allows administrators to block external email forwarding. With that setting enabled, the forwarding rule used to monitor emails would have failed.

I might still have launched ransomware, but I would have been estimating the ransom amount without critical intelligence.

4. The 36-Hour Dwell Time

Microsoft Defender for Business, included with Microsoft 365 Business Premium, generates alerts when inbox forwarding rules are created.

If those alerts had been monitored or routed to the right people, I likely would have been detected on Thursday evening.

For a business of this size, the greatest improvement often comes not from buying new products but from reviewing the alerts already being generated.

5. Public Business Information

You cannot remove information from state registries or public contract databases. That data will remain available.

What you can control is how much detail employees share about their responsibilities online. In this example, the office manager’s LinkedIn profile provided enough information to make her the obvious target.

That is worth discussing as part of practical security awareness training, not as a restriction on social media use.

Three Questions to Send Your IT Provider

These questions address most of the weaknesses exploited in this example:

  1. Are we using phishing-resistant MFA (FIDO2 keys, passkeys, or Windows Hello for Business) for finance, administrative, and executive accounts?
  2. Is external email forwarding blocked at the tenant level?
  3. Are security alerts being monitored, and is someone responsible for reviewing them?

Article FAQs

Do Hackers Target Small Businesses?

Yes. Many ransomware groups target small and midsized businesses because they offer a favorable balance between potential payout and defensive capability. Organizations with 10 to 50 employees often have valuable data and limited security resources.

What Is Adversary-in-the-Middle (AiTM) Phishing?

AiTM phishing uses a proxy page that imitates a legitimate login portal such as Microsoft 365 or Google Workspace. When a user enters credentials and completes MFA, the proxy captures the resulting session token. The legitimate service sees a valid login, but the attacker gains access to the authenticated session.

What Is a Stealer Log?

A stealer log is a collection of credentials and authentication data harvested by infostealer malware from an infected device. These logs often contain saved passwords, session cookies, and authentication tokens and are commonly sold on underground marketplaces.

How Much Does It Cost an Attacker to Compromise a Small Business?

In the example above, the attack required $14 in stolen credentials and roughly six hours of effort. Actual costs vary, but the barrier to entry for this type of attack can be surprisingly low.

Are There Free Tools That Would Have Stopped This Attack?

Several of the controls described above are included with Microsoft 365 Business Premium. Others, such as external forwarding restrictions and alert management, require configuration rather than additional purchases. HaveIBeenPwned is free, and phishing-resistant MFA solutions are inexpensive compared with the cost of a successful ransomware attack.

Get Your Free Cybersecurity Risk Review