Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

The ransom note is the part everyone pictures, but by the time it appears the attack is mostly over. Someone got in days earlier, found the admin accounts, and went looking for the backups before touching a single file. Here's how a ransomware attack moves through a network, what to do in the first hour, and why backups decide how it ends.

What Is a Ransomware Attack?

A ransomware attack is a break-in where criminals encrypt an organization's files or systems and demand payment for the key. Modern crews usually steal a copy of the data first, then threaten to publish it too. That second threat is called double extortion. It means a clean backup restores your files but doesn't make the leak go away.

The encryption is the last step, not the first. Everything that decides the outcome happens before it: how the attacker got in, how far they spread, and whether they reached the backups.

The people behind it are often not the people who wrote the malware. Ransomware as a service (RaaS) works like a franchise. A core group builds the encryptor and the leak site, and affiliates rent it, break in, and split the ransom.

How Attackers Get In

Ransomware rarely arrives as a mystery file. It comes through a door someone left open. The usual doors are a phishing email with a malicious link or attachment, an exposed remote desktop (RDP) port, an unpatched firewall or VPN appliance, or a password reused from an earlier breach.

Edge devices deserve special attention. A firewall or VPN box sits on the internet by design, gets patched less often than laptops, and usually has no endpoint agent watching it. One incident responder in this r/msp thread lists the entry points he sees weekly, and firewalls and SSL VPNs sit right next to phishing and open RDP.

The same responder makes the useful point: in many cases the attackers got in, but good endpoint detection stopped them from deploying tools or moving around. Getting in is only step one.

How One Laptop Becomes the Whole Network

Once inside, the attacker works through a fairly predictable sequence. First they escalate, turning a normal user's access into admin rights by dumping stored credentials or abusing a misconfigured service. Then they move laterally, using legitimate admin tools like remote desktop, PowerShell and remote management software, so the traffic looks like IT doing its job.

Next they map the network and find what matters: file servers, databases, the domain controllers, and the backup system. Many crews steal data at this stage. Only after all of that do they push the encryptor, often everywhere at once, often overnight or on a weekend.

On timing, Mandiant's M-Trends 2026 report puts the global median dwell time, the gap between break-in and discovery, at 14 days. When the attacker announces themselves, which is what ransomware does, the median drops to 5 days. Five days is enough time to find every admin account on a small network.

This walkthrough from Huntress's SOC shows the same chain in a real case, from first access to encryption.

The reason one laptop turns into three hundred is shared credentials. If the same domain admin account can reach every workstation, every server and the backup console, the attacker only needs to steal it once. Separate admin accounts for workstations, servers and backups turn one stolen password into a contained incident. Our guide to RMM security covers the same logic for remote management tools, which attackers love for the same reason IT does.

Why Attackers Go After Backups First

A victim with working backups doesn't need to pay. So ransomware crews go after backups before they encrypt anything. Mandiant's 2026 report notes attackers "actively deleting backup objects from cloud storage", and groups like Akira and Qilin going after backup infrastructure and hypervisor management directly.

The easy target is a backup system that trusts the same domain as everything else. If a domain admin can log into the backup console or reach the backup share, a stolen domain admin account can delete the backups. Practitioners in this r/sysadmin thread describe exactly that, plus backups that skipped "non-critical" servers that turned out to be critical.

The same thread has the opposite story. A former school IT admin describes about 830 schools, two schools hit a week at the worst point, and recovery down to roughly 45 minutes. Two things made that possible: full backups three times a day, and admin accounts kept in their own domain, so a compromised school never exposed everything else.

The First Hour After the Ransom Note

The first hour decides how much you lose and how much evidence survives. The instinct is to wipe and rebuild immediately. Resist it.

  1. Isolate, don't power off. Pull network cables, disable Wi-Fi, or block the machines at the switch or firewall. Keep them running, because memory holds evidence a reboot destroys.
  2. Find the scope. Check which systems show encrypted files or ransom notes, and whether servers and the domain controllers are affected.
  3. Protect the backups. Take the backup system offline from the production network and check that the backup copies are intact before restoring anything.
  4. Call for help early. Contact your incident response provider and your cyber insurer before you talk to the attacker. Many policies require it, and our cyber insurance requirements guide covers what insurers expect.
  5. Report it. In the US, file with the FBI's IC3 and check CISA's #StopRansomware guide. Outside the US, use your national cyber agency.
  6. Don't negotiate or pay on your own. Payment decisions involve legal, insurance and sanctions questions, and paying doesn't guarantee a working key.

Write down every action with a timestamp. The incident responders, the insurer and possibly a regulator will all ask for that log, and memory gets unreliable fast when the phones are ringing. Our incident management guide covers how to run that process on a normal day, which is the best way to be ready for a bad one.

Backups Decide How It Ends

The numbers show how often backups fail when they're needed. Sophos's State of Ransomware 2025 survey of 3,400 IT leaders found that 54% of victims restored their data from backups, the lowest rate in six years. Veeam's 2026 resilience report found that only 28% of affected victims recovered all of their data. Different surveys, different questions, same direction.

A backup that survives a ransomware attack has four properties. It has at least one copy that attackers can't change or delete, either offline or immutable. It uses credentials that live outside the main domain. It keeps restore points older than the attacker's dwell time, since last Tuesday's backup may already contain them. And someone has restored from it recently, with a stopwatch. Our guide to disaster recovery testing covers how to run that restore and what counts as a pass.

Two numbers turn that into a plan: how long each system can be down, and how much data you can afford to lose. Those are your RTO and RPO, and our RTO vs RPO guide shows how to set them by system.

Visibility matters too. You can't protect a server nobody knows exists. OpenFrame pulls a live device inventory from every managed endpoint, which makes it easier to check the backup scope against what's running.

The Short Version

A ransomware attack is days of quiet work followed by one very loud night. Close the doors attackers use, keep admin accounts separated so one stolen password stays contained, and keep at least one backup copy the attackers can't reach.

For the tools side of that last point, our roundup of MSP backup solutions is the next read.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Ransomware

It depends on how far the attack spread and whether clean backups survived. With tested, separate backups, a single site can be back in hours; without them, recovery can take weeks. Sophos's 2025 survey found 53% of victims fully recovered within a week.
Law enforcement agencies advise against paying, and paying doesn't guarantee a working decryption key or that stolen data gets deleted. Payment also raises legal and sanctions questions, so involve your incident response provider, insurer and legal counsel before any decision.
Traditional antivirus catches known ransomware files but often misses attackers who use legitimate admin tools to move around first. Endpoint detection and response (EDR), patched edge devices, multi-factor authentication and separate admin accounts stop far more attacks before encryption starts.
Ransomware as a service (RaaS) is a criminal business model where a core group builds the ransomware and leak site, and affiliates rent it to break into victims. The affiliates carry out the attacks and split the ransom with the developers.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.