The gang didn’t lock a single file. They didn’t need to — they showed us a folder listing from our own file server and gave us ninety-six hours before it went up on a leak site. No ransomware. Just the threat of one, aimed precisely.
The email arrived at 6:14 a.m. on a Tuesday, addressed to three people whose names weren’t public anywhere convenient, with a zip file attached. Inside were four documents pulled from our finance share, a screenshot of a folder tree with roughly nine thousand files, and a countdown: ninety-six hours before “a sample” went to a journalist and the rest went up for anyone to download. No ransom note demanding we pay to get files back, because nothing had been taken away from us. Everything still worked. That was the problem.
We spent five years building backup and recovery discipline around the assumption that the attack we needed to survive was encryption. Restore from backup, eat the downtime, move on. This wasn’t that attack, and our runbook — genuinely good at handling the scenario it was written for — had almost nothing to say about a threat that never touched availability at all.
The economics that got us here
Encryption was never really the point of ransomware; it was the leverage mechanism available when data theft alone wasn’t reliably profitable. That’s changed. Ransomware-as-a-service has pushed the technical bar for running an extortion operation close to zero, and the group that hit us wasn’t the operator who built the tooling — they were an affiliate who rented access to it, following a fairly standard playbook. Encrypting a network draws attention fast: backups get isolated, IT gets paged, incident response engages within the hour. Quietly exfiltrating a few gigabytes of the right documents and threatening disclosure draws none of that — until the ninety-six-hour clock is already running.
What we did in the first 96 hours
Hour 0-4: confirm before you panic
The first job wasn’t containment, it was verification — was this real, and was the sample they showed us actually current and actually ours? Two engineers worked backward from the screenshot’s file paths and modification timestamps while legal and comms were looped in simultaneously, not sequentially. Fear of a leak is not a reason to skip confirming the leak is real; several extortion attempts are pure bluff, and treating a bluff as a confirmed breach wastes the exact hours you need most.
Hour 4-24: scope the exposure, not the network
Because nothing was encrypted, there was no “restore and move on” step. The only question that mattered was what, specifically, had left the building. We rebuilt the access logs for the share in question and found the actual entry point: a contractor account with broader read access than their role required, active for eleven months past their engagement’s end date. That account should have been deprovisioned automatically and wasn’t, because our offboarding process depended on a manual ticket that nobody had filed.
Hour 24-96: decide, communicate, don’t pay
We didn’t pay, and we’d make the same call again — payment doesn’t reliably prevent disclosure, and it directly funds the next attempt against someone else. We disclosed proactively to the affected parties inside the deadline rather than waiting to see if the threat was real, which cost us an uncomfortable few days and saved us a much worse story a month later, when it turned out the group posted stolen data from non-paying targets regardless.
We had a backup strategy that would have survived encryption perfectly. We didn’t have a strategy for the version of this attack that skips encryption entirely, because we’d spent five years preparing for the wrong ending.
What changed in our playbook
The uncomfortable part
Nine thousand files sounds enormous until you actually walk through them and realize most were routine, and the handful that mattered were the reason the deadline felt so sharp. Ransomware without encryption is a smaller technical event and a much bigger judgment call, decided under a clock someone else set. The backups were never going to save us this time. The access review that didn’t happen eleven months earlier is the thing that would have.