Picture this: it’s Friday afternoon at your Bradenton office. Your bookkeeper just left for the weekend. You’re out on a job site. And every file on your shared drive just got locked by someone who spent $14 and about six hours to take your entire business hostage. Think that’s an exaggeration? It’s not. Here’s exactly how it happens.
What follows is a step-by-step walkthrough of how a small business gets hit with ransomware — written from the attacker’s perspective. The company in this story is fictional, but the methods come straight from current threat intelligence. And after the walkthrough, I’ll show you five specific moments where the attack would have been stopped cold by tools most small businesses already pay for.
Monday: How the Attacker Picked You
The attacker works regular hours, just like you. They keep a spreadsheet of about 40 targets per month, and they prefer businesses between 10 and 50 employees. Why that range? Simple economics.
Big companies have security teams, incident response contracts, and lawyers. Too expensive to mess with. Sole proprietors don’t have enough at stake. But a 22-person company — say, a CPA firm, a wealth management office, or a commercial services business — sits right in the sweet spot. Payroll, client database, project files, supplier relationships, and an owner who will pay to get it all back.
They didn’t find you through some secret breach. They found you on a public business records portal. Florida’s state business registries, federal contract awards, and Manatee County licensing databases publish enough detail to identify your company, look up your name, estimate your revenue, and pick the most useful person inside the business.
Here’s the kicker: the fact that nothing bad has happened to your company yet is actually the strongest signal they look for. It means your credentials are probably still valid, your staff hasn’t been trained to spot anything, and nobody has had a reason to change a password. A clean record is the first thing they check.
Tuesday: Building Your Org Chart for Free
Total research time: about 40 minutes with nothing but a web browser.
LinkedIn gives them eight of your current employees with job titles listed. Your office manager has been there for six years and her profile summary says “accounts payable, payroll, and supplier invoicing.” Your second admin joined 14 months ago. Your own profile is sparse with a low connection count — which tells them you’re unlikely to notice when someone unusual starts poking around.
Public business filings confirm your registered business name and full legal name. A “meet the team” post from two years ago on your Facebook page lists first names and photos. One of the commenters shares your last name.
Now the attacker knows who handles your money, what their name is, how long they’ve been there, and what software they probably use. (They’ll check your Indeed job ads for phrases like “experience with QuickBooks or Sage.”) They also know who can approve a payment without a second signature.
That person — not you — is the primary target. You’re harder to reach and probably more cautious. Your office manager has system access, handles supplier payments, and is busy enough that one more email in her inbox doesn’t get a second look.
Total cost so far: zero dollars.
Wednesday: Your Credentials Cost $14
Ever heard of “stealer logs”? They’re credential packages harvested by malware that infected someone’s personal device — sometimes months or years ago. The malware records every username and password typed into the machine, then bundles the data for sale. Buyers can search these logs by company email domain on underground marketplaces.
The attacker searches for your company’s email domain. Two results come back. One is your office manager’s work email with a password saved in her browser. The other is a personal Gmail that appears to belong to a family member — probably from a device on your home network.
Price: $14. Time: four minutes.
Your office manager’s password follows a pattern we see constantly with Tampa Bay businesses: a pet or child’s name, a year, and an exclamation mark. A quick check on HaveIBeenPwned (the same free tool security pros use) shows it appeared in a retail loyalty program breach three years ago. The password hasn’t been changed since.
The family member’s credentials are even more useful than they look. The same password, with minor variations, works across a streaming service, a gaming account, and your company’s Microsoft 365 login. The only thing standing between the attacker and your inbox is the second factor.
Thursday: Getting Past Your MFA
Multi-factor authentication stops a lot of attacks. But how it’s set up matters way more than just having the checkbox ticked.
Simple push-notification fatigue (where the attacker keeps sending “approve” prompts until someone taps yes) won’t work here. Microsoft enabled number matching by default for all Authenticator push notifications in 2023, which means the user has to type a specific code rather than just tap approve.
What still works is something called adversary-in-the-middle (AiTM) phishing. The attacker sends your office manager an email that looks like a routine Microsoft 365 password reset notification — even citing the real breach her password appeared in. The link goes to a page that mirrors the real Microsoft sign-in screen. But it’s actually a proxy the attacker controls.
When she enters her password and approves her MFA prompt, the proxy forwards everything to the real Microsoft login server. Microsoft validates the credentials, completes the MFA challenge, and issues a session token — but it goes back to the attacker’s proxy. She sees a normal login experience. The attacker now has her live session token.
They also had a backup plan. Earlier that day, they called your office pretending to be your IT support company (they found the company name in a Google review you left 18 months ago). They told the receptionist they were seeing unusual login activity on the office manager’s account. The call cost nothing.
By Thursday night, the attacker is inside your office manager’s Microsoft 365 account. They set up an inbox forwarding rule to silently copy her emails to an address they control. Then they wait.
Friday at 2:47 PM: Why They Waited 36 Hours Before Encrypting
The attacker spends 36 hours reading email before encrypting a single file. That dwell time is how they size the ransom.
In those 36 hours, they find your cyber insurance policy attached to an email from your broker — with a cyber liability sub-limit of $250,000. A bank reconciliation shows your business account at around $180,000. Your customer list sits in a quote template. A message thread with a project manager mentions a job starting in three weeks with a hard deadline.
The ransom gets set at $65,000 in cryptocurrency. Low enough that you’ll pay rather than fight, high enough to be worth their time, and well within what they know you can access. They’ve learned that demands above roughly 10 percent of visible liquid assets tend to get contested. This number sits safely below that line.
The encryption payload drops at 2:47 PM on Friday. Timing is deliberate. Your bookkeeper leaves at 3 PM (the attacker knows this from an out-of-office reply in the forwarded emails). You’re on a job site with your calendar synced to the shared inbox. The person most likely to notice something wrong is already gone, and the person with authority to make decisions is unreachable.
By Friday evening, every file on your shared drive is encrypted and a ransom note sits on every screen in your office. Total cost to the attacker: $14 and about six hours of work spread across the week.
Five Places This Attack Would Have Been Stopped
Here’s the thing that should make you feel better (or frustrated, depending on your perspective): this attack worked because five ordinary controls weren’t in place. None of them were expensive. Most were already bundled into tools the business was already paying for.
1. The credential purchase on Wednesday.
HaveIBeenPwned is free. Microsoft Entra password protection can detect and block reused or commonly-compromised passwords across your accounts. Enforcing unique passwords per account — through a password manager and Entra’s policies — makes a stolen credential purchase useless. This is something every law firm, accounting practice, and financial advisory firm in Bradenton should have locked down already.
2. The MFA bypass on Thursday.
Microsoft already blocks push-bombing attacks with number matching enabled by default since 2023. But the bigger threat now is AiTM phishing. The defenses: phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business), Conditional Access policies requiring a compliant device, and anti-phishing protection in Microsoft Defender for Office 365. Any one of these would have prevented the session token capture or made it useless.
3. The inbox forwarding rule.
Microsoft 365 lets admins block external email forwarding rules at the tenant level. With that block in place, the attacker couldn’t have read 36 hours of email. They might have encrypted anyway, but they’d be guessing on the ransom amount.
4. The 36-hour dwell time.
Microsoft Defender for Business (included in Microsoft 365 Business Premium) generates an alert when a new inbox forwarding rule gets created. If anyone had been watching those alerts, the attacker would have been caught on Thursday night. For most businesses this size — whether you’re a Tampa Bay law firm or a Manatee County financial advisor — the biggest improvement isn’t buying new software. It’s having someone actually review the security alerts your existing tools are already generating.
5. The public business records.
You can’t unpublish a state contracting registry or a federal contract award. That data stays public. But you can control what your team posts about their specific responsibilities. Your office manager’s LinkedIn profile listing her financial duties in detail made her the obvious target. That’s worth a quick conversation with your team — framed as practical security awareness, not a social media crackdown.
Three Questions to Send Your IT Provider Today
These three questions cover most of where this attack succeeded. Each one maps to a control that’s probably already bundled with tools you’re paying for.
- Are we using phishing-resistant MFA (FIDO2 keys, passkeys, or Windows Hello for Business) for finance, admin, and executive logins?
- Is external email forwarding blocked at the tenant level?
- Are our security alerts going somewhere — and is someone actually reviewing them?
Frequently Asked Questions
Do hackers really target small businesses?
Absolutely. According to the Verizon Data Breach Investigations Report, ransomware is involved in the vast majority of breaches at small and mid-sized businesses. The sweet spot for attackers is roughly 10 to 50 employees — big enough to have assets worth encrypting, too small to have a dedicated security team.
What is adversary-in-the-middle (AiTM) phishing?
It’s a technique where the attacker sets up a proxy page that mirrors a real login screen (like Microsoft 365). When you enter your credentials and approve the MFA prompt, the proxy captures your session token. The real service thinks the login succeeded, but the token ends up in the attacker’s browser. It’s now the dominant credential-based attack method against Microsoft 365 after number matching shut down simpler push-bombing attacks.
What is a stealer log?
A bundle of credentials harvested by malware from an infected personal device. The logs include browser-saved passwords, session cookies, and stored authentication tokens. They typically sell for $10 to $20 per package on underground markets. The malware usually spreads through pirated software or malicious browser extensions.
How much does it actually cost an attacker to hit a small business?
In the walkthrough above, the total was $14 for stolen credentials and about six hours of labor. Costs vary, but the threshold to attempt this kind of attack sits well below $100.
Are there free tools that could stop this?
Several of the controls mentioned above come bundled with Microsoft 365 Business Premium licenses that businesses this size typically already have. External forwarding restrictions and Defender for Business alerts are configuration changes, not new purchases. HaveIBeenPwned is free. Phishing-resistant MFA hardware keys are a small per-user cost compared with the cost of a ransomware incident.
Sources and Further Reading
- CISA: Stop Ransomware Guide — federal guidance on the controls referenced throughout this walkthrough.
- Microsoft Learn: How number matching works in MFA push notifications — documentation on the default-enabled feature that blocks push-bombing attacks.
- HaveIBeenPwned — the free database for checking whether an email address has appeared in known breaches.
- Microsoft Learn: Configure external email forwarding in Microsoft 365 — how to block tenant-level external forwarding rules.
If any of this sounded uncomfortably familiar, you’re not alone — we hear it from businesses across Bradenton and Tampa Bay every week. The three questions above are a great starting point. Your IT provider should be able to confirm what’s in place and what’s not within an hour or two. And if you don’t have one, or you just want a second opinion, book a free 15-minute call and we’ll walk through it with you. No pitch, just answers.


