Small business owners often assume cybercriminals spend all their time trying to break into large corporations. The truth is quite the opposite.
Most ransomware attacks aren’t aimed at Fortune 500 companies—they’re aimed at businesses just like yours. Companies with 10 to 50 employees are often the perfect target because they have valuable customer data, financial information, and day-to-day operations that depend on technology, but they typically don’t have a dedicated cybersecurity team watching for threats.
The good news? Understanding how attackers operate is one of the best ways to protect your business.
The story below is fictional, but every tactic described is based on real-world attack methods that cybersecurity professionals encounter every day. As you read, you’ll also see where simple security measures could have stopped the attack before it ever became a crisis.
Day 1: Why Your Business Became the Target
“I’m not looking for the biggest company. I’m looking for the easiest one.”
That’s how many ransomware operators think.
A business with 20 to 30 employees is often the ideal size. It has payroll, customer information, vendor relationships, project files, and enough revenue to justify paying a ransom if operations come to a halt.
Finding a target doesn’t require hacking.
Public business records, company websites, social media pages, LinkedIn profiles, and online licensing databases provide more information than most business owners realize. Within an hour, an attacker can often identify:
- Company leadership
- Financial decision-makers
- Employee names and job titles
- Vendors and software being used
- Recent contracts or projects
- Contact information
In many cases, your online presence becomes the attacker’s research department.
Day 2: Building Your Company’s Org Chart
Next comes identifying the right person to target.
Business owners aren’t always the easiest target. They’re often busy, cautious, and receive fewer routine emails than administrative staff.
Instead, attackers frequently focus on office managers, bookkeepers, payroll administrators, or accounts payable employees. These individuals often have access to financial systems, email accounts, and vendor relationships—and they’re juggling dozens of legitimate requests every day.
Public LinkedIn profiles can reveal years of experience, job responsibilities, and even the accounting software someone uses. A company Facebook page might introduce team members by name. Job postings may reveal technology platforms already in use.
To a cybercriminal, these details aren’t interesting trivia—they’re reconnaissance.
Day 3: Buying Stolen Credentials
Many business owners imagine hackers spending hours cracking passwords.
Often, they simply buy them.
Stolen username and password combinations—known as stealer logs—are sold on underground marketplaces for surprisingly little money. These credentials are frequently harvested from personal devices infected with malware or from old data breaches where passwords were reused across multiple accounts.
If an employee reused the same password for an online shopping account and their Microsoft 365 account, that password may already be available to criminals.
This is one reason cybersecurity professionals strongly recommend:
- Using unique passwords for every account
- Enabling a password manager
- Regularly checking for compromised credentials
One reused password can become the front door to your business.
Day 4: Getting Past Multi-Factor Authentication
Multi-factor authentication (MFA) remains one of the most effective cybersecurity tools available—but not every implementation offers the same level of protection.
Today’s attackers increasingly rely on a technique known as Adversary-in-the-Middle (AiTM) phishing.
Instead of stealing only a username and password, attackers create convincing copies of legitimate Microsoft 365 login pages. When a user signs in and approves their MFA request, the fake website quietly captures the authenticated session token while passing the login through to Microsoft.
From the employee’s perspective, everything looks perfectly normal.
Behind the scenes, the attacker now has an authenticated session that allows them to access the account without ever knowing the second authentication factor.
This is why phishing-resistant authentication methods—such as passkeys, FIDO2 security keys, or Windows Hello for Business—are becoming increasingly important for businesses.
Day 5: Waiting Before the Attack
One of the biggest misconceptions about ransomware is that criminals immediately encrypt files after gaining access.
Often, they wait.
Over the next day or two, they quietly monitor email conversations, learn how the business operates, identify financial information, determine whether cyber insurance exists, and estimate how much ransom the business is likely to pay.
Only after they’ve gathered enough information do they launch the ransomware attack.
By that point, they know:
- Who approves payments
- When employees leave for the weekend
- Which projects have tight deadlines
- Which files are most valuable
- How disruptive an outage will be
The better they understand your business, the more likely they are to demand a ransom they believe you’ll pay.
Five Security Controls That Could Have Stopped This Attack
The encouraging part of this story is that none of these steps required cutting-edge technology to prevent.
Many businesses already own the tools—they simply haven’t configured them correctly.
1. Use Strong, Unique Passwords
Password reuse remains one of the most common causes of account compromise.
Password managers make it practical to create long, unique passwords for every account without expecting employees to memorize them all.
Checking employee credentials against known breach databases, such as Have I Been Pwned, also helps identify compromised passwords before criminals can use them.
2. Strengthen Multi-Factor Authentication
Traditional MFA is significantly better than no MFA.
However, phishing-resistant authentication methods provide much stronger protection against modern attacks that attempt to steal authenticated sessions rather than passwords.
For employees with access to financial systems, Microsoft 365 administration, or sensitive company information, this additional protection is well worth implementing.
3. Block External Email Forwarding
Many attackers quietly create email forwarding rules after compromising an account.
These rules allow every incoming message to be copied outside the organization without the employee ever noticing.
Fortunately, Microsoft 365 administrators can disable external forwarding across the organization, eliminating one of the easiest ways attackers gather intelligence after gaining access.
4. Review Security Alerts
Modern security platforms generate valuable alerts every day.
The challenge isn’t whether alerts exist—it’s whether anyone is reviewing them.
Many small businesses already have access to Microsoft Defender features through Microsoft 365 Business Premium but aren’t actively monitoring suspicious login attempts, unusual forwarding rules, or risky sign-in behavior.
Technology is only effective if someone is paying attention.
5. Train Employees to Think Like Attackers
You can’t remove your company from public records or ask employees to disappear from LinkedIn.
What you can do is help your team understand how seemingly harmless information can be pieced together into an attack.
Regular security awareness training helps employees recognize phishing attempts, question unexpected requests, and think twice before sharing unnecessary details online.
People remain your first line of defense.
Three Questions to Ask Your IT Provider
If you’re not sure where your business stands, start with these three questions:
- Are we using phishing-resistant authentication for employees with access to financial or administrative systems?
- Is external email forwarding blocked across our Microsoft 365 environment?
- Who reviews our security alerts, and how often?
If your IT provider can’t answer those questions clearly, it’s worth having a deeper conversation about your cybersecurity strategy.
Small Businesses Are Not Too Small to Be Targeted
Cybercriminals aren’t necessarily looking for the biggest payout.
They’re looking for the easiest opportunity.
The businesses that avoid becoming victims aren’t always the ones spending the most money on cybersecurity—they’re the ones that have layered security protections, properly configured systems, and employees who know what to look for.
Cybersecurity isn’t about eliminating every possible risk. It’s about making your business a difficult target so attackers move on to someone else.
If you’d like to evaluate how well your business is protected against today’s ransomware tactics, contact the team at Cornerstone IT Professionals. We’ll help you identify vulnerabilities, strengthen your defenses, and ensure you’re making the most of the security tools you already have.
Helpful Resources
Looking for additional ways to strengthen your cybersecurity posture?
- Download our Phishing Prevention Checklist to reduce one of the most common attack methods businesses face.
- Learn more about Microsoft’s recommended security best practices for Microsoft 365.
- Review the Stop Ransomware Guide published by the Cybersecurity and Infrastructure Security Agency (CISA).
No business can eliminate every cyber threat, but every business can dramatically reduce its risk with the right strategy, tools, and ongoing support.
