
Small Businesses Are the Preferred Target — Here’s Why
Many small business owners assume ransomware gangs are chasing the big fish — banks, hospitals, multinationals. They’re not, at least not exclusively. A 22-person business has enough revenue to be worth attacking, no dedicated security team to push back, and a publicly traceable footprint that takes under an hour to map. By volume of incidents, small businesses are the most common ransomware target.
What follows is a step-by-step account of how a typical attack unfolds — written from the attacker’s perspective. The company is a composite, but the methods reflect current threat intelligence. At the end, we’ll show you the five points where this attack would have stopped dead, using controls already bundled into tools most small businesses are already paying for.
Monday: You Were Chosen From a Public Registry
Attackers running small-volume operations — around 40 targets per month — actively prefer businesses in the 10”“50 staff range. Larger enterprises have security teams and incident response contracts. Sole traders don’t have enough at stake. A 22-person commercial services company sits right in the sweet spot.
Your business was found through a public registry — state business records, federal contract awards, licensing databases. In a single search, an attacker can find your company name, your name, a recent contract value, and the named contact on the submission. No breach required.
Tuesday: Your Org Chart, Built for Free in 40 Minutes
LinkedIn alone surfaces eight employees with job titles. The office manager’s profile lists “accounts payable, payroll, and supplier invoicing.” A Facebook team post from two years ago adds first names and faces. Job ads on seek.com.au confirm which accounting software your team uses.
The office manager becomes the primary target — she has system access, handles supplier payments, and is busy enough that one more email doesn’t get scrutinised the way it might otherwise.
Wednesday: Credentials Purchased for $14
Stealer logs are credential packages harvested from infected personal devices — browser-saved passwords, session cookies, stored tokens — sold on Telegram channels and underground forums. A search by your company’s email domain returns two results. The office manager’s work password follows a common pattern: a name, a year, an exclamation mark. It appeared in a retail loyalty program breach three years earlier and was never changed.
A family member’s credentials are even more useful. The same password, with minor variations, works across a streaming service, a gaming account, and your Microsoft 365 login. Total spend: $14.
Thursday: Getting Past MFA
Microsoft’s default number-matching for Authenticator push notifications stopped push-bombing attacks in 2023 — so the attacker doesn’t bother trying. Instead, they use adversary-in-the-middle (AiTM) phishing: an email that mimics a Microsoft 365 password reset notice, linking to a proxy page that mirrors the real sign-in screen. When the office manager enters her credentials and approves the MFA prompt, the proxy captures the resulting session token. Microsoft sees a valid authenticated session. The attacker is now inside her account.
A silent inbox forwarding rule is created. Emails begin copying to an external address. Nobody is notified.
Friday 2:47pm: Encryption
The attacker spends 36 hours reading email before deploying a single payload. In that time they find the cyber insurance policy (sub-limit: $250,000), a bank reconciliation showing $180,000 in the business account, a complete customer list, and a municipal project deadline three weeks out that can’t be missed. The ransom is set at $65,000 — well within reach, well below the threshold where businesses tend to fight back.
Encryption deploys at 2:47pm on a Friday. The bookkeeper finishes at 3pm. The director is on-site. By Friday evening, every file on the shared drive is locked and a ransom note sits on every screen.
Total attacker cost: $14 and roughly six hours of work.
Five Places This Attack Could Have Been Stopped
1. Block Compromised Passwords at the Source
Microsoft Entra ID’s password protection policies detect and block commonly compromised passwords across your tenant. Paired with a password manager enforcing unique credentials per account, a $14 credential purchase becomes worthless.
2. Use Phishing-Resistant MFA
AiTM phishing defeats standard push-notification MFA. What stops it: FIDO2 hardware keys, passkeys, or Windows Hello for Business. Conditional Access policies requiring a compliant or Intune-enrolled device also make a captured session token unusable from an attacker’s IP. Microsoft Defender for Office 365 adds anti-phishing protection at the email layer.
3. Block External Email Forwarding at the Tenant Level
Microsoft 365 lets admins disable external forwarding rules tenant-wide. With that setting enabled, the forwarding rule that fed 36 hours of business intelligence to the attacker simply doesn’t work. This is a configuration change, not a new product.
4. Act on the Alerts You’re Already Receiving
Microsoft Defender for Business — included in Microsoft 365 Business Premium — generates an alert when a new inbox forwarding rule is created. That alert existed. Nobody was watching it. Reviewing the alerts your existing tools are already generating is often the highest-impact improvement available to a business at this size.
5. Limit What Staff Publish About Their Roles
You can’t unpublish a state contracting registry. You can have a practical conversation with your team about what they list publicly. The office manager’s LinkedIn profile detailed her financial responsibilities clearly enough to make her the obvious target. Framed as security awareness rather than a restriction, that’s a 15-minute discussion worth having.
Three Questions to Ask Your IT Provider This Week
These map directly to the five controls above and should take your provider no more than an hour to answer:
- Are finance, admin, and executive logins using phishing-resistant MFA — FIDO2 keys, passkeys, or Windows Hello for Business?
- Is external email forwarding blocked at the Microsoft 365 tenant level?
- Are our Defender security alerts going somewhere, and is someone reviewing them regularly?
If any part of this walkthrough felt uncomfortably familiar, the ACSC’s Essential Eight recommends multi-factor authentication and restricting administrative privileges as two of its top mitigations — both relevant here. Under the Privacy Act and the Notifiable Data Breaches scheme, a successful ransomware attack that exposes customer data also carries reporting obligations that add cost and complexity well beyond the ransom itself.
If you’d like us to check what’s actually in place across your Microsoft 365 environment, get in touch with the team at IT TechNinjas — we’ll give you a straight answer.
