About Services Portfolio Blog Contact Contact Us
Security

Ransomware stopped encrypting. That’s what makes it scarier.

July 21, 2026

The email arrived at 6:14 a.m. on a Tuesday, addressed to three people whose names weren’t public anywhere convenient, with a zip file attached. Inside were four documents pulled from our finance share, a screenshot of a folder tree with roughly nine thousand files, and a countdown: ninety-six hours before “a sample” went to a journalist and the rest went up for anyone to download. No ransom note demanding we pay to get files back, because nothing had been taken away from us. Everything still worked. That was the problem.

We spent five years building backup and recovery discipline around the assumption that the attack we needed to survive was encryption. Restore from backup, eat the downtime, move on. This wasn’t that attack, and our runbook — genuinely good at handling the scenario it was written for — had almost nothing to say about a threat that never touched availability at all.

The economics that got us here

Encryption was never really the point of ransomware; it was the leverage mechanism available when data theft alone wasn’t reliably profitable. That’s changed. Ransomware-as-a-service has pushed the technical bar for running an extortion operation close to zero, and the group that hit us wasn’t the operator who built the tooling — they were an affiliate who rented access to it, following a fairly standard playbook. Encrypting a network draws attention fast: backups get isolated, IT gets paged, incident response engages within the hour. Quietly exfiltrating a few gigabytes of the right documents and threatening disclosure draws none of that — until the ninety-six-hour clock is already running.

What we did in the first 96 hours

Hour 0-4: confirm before you panic

The first job wasn’t containment, it was verification — was this real, and was the sample they showed us actually current and actually ours? Two engineers worked backward from the screenshot’s file paths and modification timestamps while legal and comms were looped in simultaneously, not sequentially. Fear of a leak is not a reason to skip confirming the leak is real; several extortion attempts are pure bluff, and treating a bluff as a confirmed breach wastes the exact hours you need most.

Hour 4-24: scope the exposure, not the network

Because nothing was encrypted, there was no “restore and move on” step. The only question that mattered was what, specifically, had left the building. We rebuilt the access logs for the share in question and found the actual entry point: a contractor account with broader read access than their role required, active for eleven months past their engagement’s end date. That account should have been deprovisioned automatically and wasn’t, because our offboarding process depended on a manual ticket that nobody had filed.

Hour 24-96: decide, communicate, don’t pay

We didn’t pay, and we’d make the same call again — payment doesn’t reliably prevent disclosure, and it directly funds the next attempt against someone else. We disclosed proactively to the affected parties inside the deadline rather than waiting to see if the threat was real, which cost us an uncomfortable few days and saved us a much worse story a month later, when it turned out the group posted stolen data from non-paying targets regardless.

What changed in our playbook

The uncomfortable part

Nine thousand files sounds enormous until you actually walk through them and realize most were routine, and the handful that mattered were the reason the deadline felt so sharp. Ransomware without encryption is a smaller technical event and a much bigger judgment call, decided under a clock someone else set. The backups were never going to save us this time. The access review that didn’t happen eleven months earlier is the thing that would have.

Back to all posts
Ready when you are

Ready to elevate your business?

Start with a free, no-obligation IT audit.

Contact Us