What Happens During a Ransomware Attack?
A ransomware attack typically unfolds in stages: initial access (usually through phishing or exploited vulnerability), lateral movement through your network, data exfiltration (stealing your data), and finally encryption of your files with a ransom demand. The entire process can take hours to weeks, and recovery—even with backups—typically takes 2-4 weeks with significant business disruption.
Written by Alex Dayan, Founder of King of IT | Toronto Managed IT Services
1Stage 1: Initial Access (Day 0)
How Attackers Get In
The attack starts when criminals gain access to your network. Common entry points:
Phishing Email (Most Common)
Employee clicks malicious link or opens infected attachment
Credentials stolen through fake login page
Malware downloaded and executed
Exploited Vulnerabilities
Unpatched VPN or firewall
Exposed Remote Desktop (RDP)
Vulnerable web application
Compromised Credentials
Passwords leaked in previous breaches
Weak or reused passwords
No multi-factor authentication
What You Might Notice: Usually nothing. The initial compromise is silent. The attacker now has a foothold but hasn't done anything visible yet.
2Stage 2: Reconnaissance & Lateral Movement (Days 1-14)
What Attackers Do Next
Once inside, attackers don't immediately encrypt. They spend days or weeks:
Mapping Your Network
Identifying servers, workstations, and backups
Finding Active Directory and domain controllers
Locating file shares and databases
Escalating Privileges
Stealing admin credentials
Compromising service accounts
Gaining domain admin access
Disabling Security
Turning off antivirus
Deleting shadow copies (Windows restore points)
Identifying and targeting backup systems
What You Might Notice: Unusual login times, disabled security tools, antivirus alerts being dismissed. Most organizations don't notice anything until encryption begins.
Dwell Time: Attackers typically spend 10-21 days inside networks before deploying ransomware. Some stay for months.
3Stage 3: Data Exfiltration (Days 7-21)
Double Extortion
Modern ransomware gangs don't just encrypt—they steal your data first:
What They Take:
Customer databases and personal information
Financial records and banking details
Employee HR files and payroll data
Contracts and legal documents
Intellectual property and trade secrets
Email archives
Why They Steal Data:
Even if you have backups and refuse to pay for decryption, they threaten to:
Publish your data on leak sites
Sell data to competitors or criminals
Report you to regulators (triggering PIPEDA investigations)
Contact your customers directly
What You Might Notice: Large data transfers to unknown destinations, but most organizations don't monitor outbound traffic closely enough to catch this.
4Stage 4: Encryption & Ransom Demand (D-Day)
The Attack Goes Loud
When attackers are ready, they deploy ransomware simultaneously across your network:
What Happens:
All accessible files are encrypted (documents, databases, images)
Ransom notes appear on every screen
Systems become unusable
Backups are encrypted or deleted if accessible
The Ransom Note:
Typically demands payment in cryptocurrency (Bitcoin, Monero) and includes:
Ransom amount (often $50,000-$500,000+ for SMBs)
Payment deadline (usually 48-72 hours)
Threat to increase price or leak data
Instructions for contact (usually via Tor)
Typical Ransom Amounts:
Small business (under 50 employees): $50,000-$200,000
Mid-sized business (50-500 employees): $200,000-$2,000,000
Enterprise: $2,000,000-$50,000,000+
What You Notice: Everything stops. Employees can't access files. Phones start ringing. Panic sets in.
5The Recovery Process (Weeks to Months)
With or Without Paying
If You Pay (Not Recommended):
Payment doesn't guarantee decryption works
80% of companies that pay are attacked again
Average recovery time: 2-3 weeks even with decryption keys
You've funded criminal operations
If You Don't Pay:
Restore from backups (if they exist and weren't compromised)
Rebuild systems from scratch
Accept some data loss
Potentially deal with leaked data
Typical Recovery Timeline:
Day 1-3: Incident response, contain the attack, assess damage
Day 3-7: Forensic investigation, determine scope
Week 1-2: Begin restoration from backups or rebuild
Week 2-4: Restore critical systems and data
Month 1-3: Full recovery, security improvements
Real Costs (Beyond Ransom):
Business interruption (average 21 days downtime)
Incident response and forensics ($20,000-$100,000+)
System rebuilding and restoration
Legal and regulatory compliance
Customer notification and credit monitoring
Reputation damage
Increased insurance premiums
Average Total Cost for SMB: $200,000-$1,000,000+
6How to Prevent Ransomware
The Basics That Stop Most Attacks:
- Multi-Factor Authentication (MFA)
- Patch Management
- Email Security
- Endpoint Protection
- Backup Strategy
- Network Segmentation
- Incident Response Plan
King of IT Tip: 90% of ransomware attacks we've helped respond to could have been prevented by MFA on email. It's the single highest-impact security control.