Cybersecurity

What Happens During a Ransomware Attack?

A ransomware attack typically unfolds in stages: initial access (usually through phishing or exploited vulnerability), lateral movement through your network, data exfiltration (stealing your data), and finally encryption of your files with a ransom demand. The entire process can take hours to weeks, and recovery—even with backups—typically takes 2-4 weeks with significant business disruption.

Written by Alex Dayan, Founder of King of IT | Toronto Managed IT Services

1Stage 1: Initial Access (Day 0)

How Attackers Get In

The attack starts when criminals gain access to your network. Common entry points:

Phishing Email (Most Common)

Employee clicks malicious link or opens infected attachment

Credentials stolen through fake login page

Malware downloaded and executed

Exploited Vulnerabilities

Unpatched VPN or firewall

Exposed Remote Desktop (RDP)

Vulnerable web application

Compromised Credentials

Passwords leaked in previous breaches

Weak or reused passwords

No multi-factor authentication

What You Might Notice: Usually nothing. The initial compromise is silent. The attacker now has a foothold but hasn't done anything visible yet.

2Stage 2: Reconnaissance & Lateral Movement (Days 1-14)

What Attackers Do Next

Once inside, attackers don't immediately encrypt. They spend days or weeks:

Mapping Your Network

Identifying servers, workstations, and backups

Finding Active Directory and domain controllers

Locating file shares and databases

Escalating Privileges

Stealing admin credentials

Compromising service accounts

Gaining domain admin access

Disabling Security

Turning off antivirus

Deleting shadow copies (Windows restore points)

Identifying and targeting backup systems

What You Might Notice: Unusual login times, disabled security tools, antivirus alerts being dismissed. Most organizations don't notice anything until encryption begins.

Dwell Time: Attackers typically spend 10-21 days inside networks before deploying ransomware. Some stay for months.

3Stage 3: Data Exfiltration (Days 7-21)

Double Extortion

Modern ransomware gangs don't just encrypt—they steal your data first:

What They Take:

Customer databases and personal information

Financial records and banking details

Employee HR files and payroll data

Contracts and legal documents

Intellectual property and trade secrets

Email archives

Why They Steal Data:

Even if you have backups and refuse to pay for decryption, they threaten to:

Publish your data on leak sites

Sell data to competitors or criminals

Report you to regulators (triggering PIPEDA investigations)

Contact your customers directly

What You Might Notice: Large data transfers to unknown destinations, but most organizations don't monitor outbound traffic closely enough to catch this.

4Stage 4: Encryption & Ransom Demand (D-Day)

The Attack Goes Loud

When attackers are ready, they deploy ransomware simultaneously across your network:

What Happens:

All accessible files are encrypted (documents, databases, images)

Ransom notes appear on every screen

Systems become unusable

Backups are encrypted or deleted if accessible

The Ransom Note:

Typically demands payment in cryptocurrency (Bitcoin, Monero) and includes:

Ransom amount (often $50,000-$500,000+ for SMBs)

Payment deadline (usually 48-72 hours)

Threat to increase price or leak data

Instructions for contact (usually via Tor)

Typical Ransom Amounts:

Small business (under 50 employees): $50,000-$200,000

Mid-sized business (50-500 employees): $200,000-$2,000,000

Enterprise: $2,000,000-$50,000,000+

What You Notice: Everything stops. Employees can't access files. Phones start ringing. Panic sets in.

5The Recovery Process (Weeks to Months)

With or Without Paying

If You Pay (Not Recommended):

Payment doesn't guarantee decryption works

80% of companies that pay are attacked again

Average recovery time: 2-3 weeks even with decryption keys

You've funded criminal operations

If You Don't Pay:

Restore from backups (if they exist and weren't compromised)

Rebuild systems from scratch

Accept some data loss

Potentially deal with leaked data

Typical Recovery Timeline:

Day 1-3: Incident response, contain the attack, assess damage

Day 3-7: Forensic investigation, determine scope

Week 1-2: Begin restoration from backups or rebuild

Week 2-4: Restore critical systems and data

Month 1-3: Full recovery, security improvements

Real Costs (Beyond Ransom):

Business interruption (average 21 days downtime)

Incident response and forensics ($20,000-$100,000+)

System rebuilding and restoration

Legal and regulatory compliance

Customer notification and credit monitoring

Reputation damage

Increased insurance premiums

Average Total Cost for SMB: $200,000-$1,000,000+

6How to Prevent Ransomware

The Basics That Stop Most Attacks:

  1. Multi-Factor Authentication (MFA)
  1. Patch Management
  1. Email Security
  1. Endpoint Protection
  1. Backup Strategy
  1. Network Segmentation
  1. Incident Response Plan

King of IT Tip: 90% of ransomware attacks we've helped respond to could have been prevented by MFA on email. It's the single highest-impact security control.

Have More Questions?

King of IT provides free consultations for Toronto businesses. Get personalized answers about your IT needs from our experienced team.