Updated: October 2026
The ransom note is the part everyone pictures, but by the time it appears the attack is mostly over. Someone got in days earlier, found the admin accounts, and went looking for the backups before touching a single file. Here's how a ransomware attack moves through a network, what to do in the first hour, and why backups decide how it ends.
What Is a Ransomware Attack?
A ransomware attack is a break-in where criminals encrypt an organization's files or systems and demand payment for the key. Modern crews usually steal a copy of the data first, then threaten to publish it too. That second threat is called double extortion. It means a clean backup restores your files but doesn't make the leak go away.
The encryption is the last step, not the first. Everything that decides the outcome happens before it: how the attacker got in, how far they spread, and whether they reached the backups.
The people behind it are often not the people who wrote the malware. Ransomware as a service (RaaS) works like a franchise. A core group builds the encryptor and the leak site, and affiliates rent it, break in, and split the ransom.
How Attackers Get In
Ransomware rarely arrives as a mystery file. It comes through a door someone left open. The usual doors are a phishing email with a malicious link or attachment, an exposed remote desktop (RDP) port, an unpatched firewall or VPN appliance, or a password reused from an earlier breach.
Edge devices deserve special attention. A firewall or VPN box sits on the internet by design, gets patched less often than laptops, and usually has no endpoint agent watching it. One incident responder in this r/msp thread lists the entry points he sees weekly, and firewalls and SSL VPNs sit right next to phishing and open RDP.
The same responder makes the useful point: in many cases the attackers got in, but good endpoint detection stopped them from deploying tools or moving around. Getting in is only step one.
How One Laptop Becomes the Whole Network
Once inside, the attacker works through a fairly predictable sequence. First they escalate, turning a normal user's access into admin rights by dumping stored credentials or abusing a misconfigured service. Then they move laterally, using legitimate admin tools like remote desktop, PowerShell and remote management software, so the traffic looks like IT doing its job.
Next they map the network and find what matters: file servers, databases, the domain controllers, and the backup system. Many crews steal data at this stage. Only after all of that do they push the encryptor, often everywhere at once, often overnight or on a weekend.
On timing, Mandiant's M-Trends 2026 report puts the global median dwell time, the gap between break-in and discovery, at 14 days. When the attacker announces themselves, which is what ransomware does, the median drops to 5 days. Five days is enough time to find every admin account on a small network.
This walkthrough from Huntress's SOC shows the same chain in a real case, from first access to encryption.
The reason one laptop turns into three hundred is shared credentials. If the same domain admin account can reach every workstation, every server and the backup console, the attacker only needs to steal it once. Separate admin accounts for workstations, servers and backups turn one stolen password into a contained incident. Our guide to RMM security covers the same logic for remote management tools, which attackers love for the same reason IT does.
Why Attackers Go After Backups First
A victim with working backups doesn't need to pay. So ransomware crews go after backups before they encrypt anything. Mandiant's 2026 report notes attackers "actively deleting backup objects from cloud storage", and groups like Akira and Qilin going after backup infrastructure and hypervisor management directly.
The easy target is a backup system that trusts the same domain as everything else. If a domain admin can log into the backup console or reach the backup share, a stolen domain admin account can delete the backups. Practitioners in this r/sysadmin thread describe exactly that, plus backups that skipped "non-critical" servers that turned out to be critical.
The same thread has the opposite story. A former school IT admin describes about 830 schools, two schools hit a week at the worst point, and recovery down to roughly 45 minutes. Two things made that possible: full backups three times a day, and admin accounts kept in their own domain, so a compromised school never exposed everything else.
The First Hour After the Ransom Note
The first hour decides how much you lose and how much evidence survives. The instinct is to wipe and rebuild immediately. Resist it.
- Isolate, don't power off. Pull network cables, disable Wi-Fi, or block the machines at the switch or firewall. Keep them running, because memory holds evidence a reboot destroys.
- Find the scope. Check which systems show encrypted files or ransom notes, and whether servers and the domain controllers are affected.
- Protect the backups. Take the backup system offline from the production network and check that the backup copies are intact before restoring anything.
- Call for help early. Contact your incident response provider and your cyber insurer before you talk to the attacker. Many policies require it, and our cyber insurance requirements guide covers what insurers expect.
- Report it. In the US, file with the FBI's IC3 and check CISA's #StopRansomware guide. Outside the US, use your national cyber agency.
- Don't negotiate or pay on your own. Payment decisions involve legal, insurance and sanctions questions, and paying doesn't guarantee a working key.
Write down every action with a timestamp. The incident responders, the insurer and possibly a regulator will all ask for that log, and memory gets unreliable fast when the phones are ringing. Our incident management guide covers how to run that process on a normal day, which is the best way to be ready for a bad one.
Backups Decide How It Ends
The numbers show how often backups fail when they're needed. Sophos's State of Ransomware 2025 survey of 3,400 IT leaders found that 54% of victims restored their data from backups, the lowest rate in six years. Veeam's 2026 resilience report found that only 28% of affected victims recovered all of their data. Different surveys, different questions, same direction.
A backup that survives a ransomware attack has four properties. It has at least one copy that attackers can't change or delete, either offline or immutable. It uses credentials that live outside the main domain. It keeps restore points older than the attacker's dwell time, since last Tuesday's backup may already contain them. And someone has restored from it recently, with a stopwatch. Our guide to disaster recovery testing covers how to run that restore and what counts as a pass.
Two numbers turn that into a plan: how long each system can be down, and how much data you can afford to lose. Those are your RTO and RPO, and our RTO vs RPO guide shows how to set them by system.
Visibility matters too. You can't protect a server nobody knows exists. OpenFrame pulls a live device inventory from every managed endpoint, which makes it easier to check the backup scope against what's running.
The Short Version
A ransomware attack is days of quiet work followed by one very loud night. Close the doors attackers use, keep admin accounts separated so one stolen password stays contained, and keep at least one backup copy the attackers can't reach.
For the tools side of that last point, our roundup of MSP backup solutions is the next read.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
