Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Hits Unprepared Small Business, Leads to Shutdown

Dimly lit office with cluttered desk, old computer displaying ransomware warning, and gloomy sky outside.

“We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys,” Dave Hatter quotes the owner as saying. “Thanks for shopping. You’re too expensive.”

The veto that preceded a collapse

Dave Hatter, a cybersecurity and compliance consultant with Intrust IT, recounts how a new chief financial officer at a small construction company reached out to hire his firm, only to have the proposal vetoed by the owner. Three weeks later Hatter received an urgent call from a local accountant friend about a ransomware attack. When Hatter dialed the number he recognised the victim: the same construction company that had rejected outside help.

The company relied on an old, unpatched Windows server that held its most important data, and its sole backup was an external drive connected to that same server. The ransomware encrypted both the server and the backup drive. “Their entire backup is this external drive, which, of course, is now encrypted,” Hatter said. As a result the business could not pay employees and “they don't know who owes them money.” Hatter said he could not help the company, and he never found out whether the organisation paid the ransom. The business, which had operated for years, went out of business within months.

Single-point failures: backups and patching

The episode illustrates two concrete technical failures documented by Hatter: an unpatched Windows server and a backup strategy that left the backup device directly attached to the primary host. The downstream effects were immediate and operational — payroll and receivables were inaccessible — and ultimately terminal for the firm.

Hatter’s account underscores standard defensive priorities: backups must be isolated from the systems they protect (off-site or cloud copies rather than a single external drive) and servers need timely patching. As Hatter puts it in the retelling, you “can never assume that your company is too small to be attacked.”

From executive email compromise to a near-disastrous RFP phishing campaign

Hatter describes a separate incident affecting two firms in the landscaping and construction sector. An attacker gained access to an executive’s email at company one, added mail-filtering rules so outgoing phishing messages were hidden from the real account owner, and used that account to send highly credible RFP (request for proposal) messages to company two.

Those phishing messages were crafted without grammar mistakes or obvious tells and appeared to come from the compromised sender. Instead of attaching a document, the messages contained a download button that directed recipients to a Microsoft 365 login screen that looked identical to the real thing — except the page was not on the microsoft.com domain. The fake page requested the recipient’s email and password and then also asked for a short‑lived 2FA code.

Behind the scenes the attackers relayed the credentials to Microsoft in real time, prompting Microsoft to send an SMS one‑time passcode to the victim. The victim then entered that SMS code into the fake site — a classic man‑in‑the‑middle — and the attackers gained access to the Microsoft 365 account and email at company two. Hatter noted the possible impacts: attackers with access could perform password resets, conduct fraudulent money transfers, steal personal information, or use the account to phish additional contacts.

TarBot, Entra ID P2, and the limits of SMS-based 2FA

In this case Hatter's client had installed TarBot, an Intrust IT product that runs in the Microsoft 365 environment and uses Entra ID P2 to detect anomalous logins. “It throws off a bunch of telemetry, statistics, metrics, whatever you want to call it, that allows our software to say, this is an anomalous login, revoke the token, and make the user log in again,” Hatter said. Because of that tooling the intruders were kicked out after just a few minutes.

Hatter emphasised that tools like TarBot are not unique and that other apps perform similar detection. Still, he argued the stronger defence is phishing‑resistant MFA such as hardware security keys (for example, the YubiKey line) or passkeys, rather than SMS one‑time codes. “If I can get in your email and send out emails as you, the recipients, especially if they've interacted with me before, aren't going to have any guard up,” Hatter said. He added a caution about the evolving threat environment: “With today’s AI-assisted phishing, telltale signs such as bad grammar or obviously fake login pages are becoming few and far between.”

What this means for small businesses, Microsoft 365 users, and security vendors

  • Small businesses: The construction firm’s collapse shows that declining professionally managed security on the basis of size or cost can carry existential risk. Isolated, directly attached backups and unpatched servers create single points of catastrophic failure.
  • Microsoft 365 users: Account takeover via credential‑relay phishing remains effective against SMS-based 2FA; organisations should consider phishing‑resistant MFA options and tools that surface anomalous logins (for example, Entra ID P2–based detectors).
  • Security vendors and consultants: Hatter’s account illustrates demand for apps that leverage platform telemetry to detect anomalous sessions and for services that help small customers deploy practical protections such as isolated backups and phishing‑resistant authentication.

The two vignettes reported by Hatter contrast a worst case — a life‑long business undone after a single ransomware strike — with a near‑miss enabled by layered detection and modern identity controls. Which small firms will revise backup and authentication practices remains a question the toll of one shuttered company suggests they must answer.

https://www.theregister.com/security/2026/10/08/cheapskates-wouldnt-pay-for-security-help-got-hit-by-ransomware-and-went-bust-months-later/5301757