Ransomware Incidents That Actually Broke Organizations

I spent about seven years doing incident response work before moving into consulting, and the ransomware landscape shifted in ways most people don't realize. You see headlines about the biggest attacks, but what actually matters is understanding the mechanics and knowing what to do when it lands on your desk at 2 AM. Let me walk through some of the most destructive ransomware campaigns on record, then get into what happens after the encryption starts. NotPetya in 2017 is still the largest cyberattack by damages, estimated at around $10 billion globally. It wasn't even really ransomware in the traditional sense. The encryption was a cover. The real weapon was a wiper disguised as ransomware, designed to destroy data permanently while giving the appearance of a decryptable attack. Maersk, Merck, and FedEx were all hit. Maersk lost 43,000 containers and had to rebuild their entire global IT infrastructure from scratch. They went back to paper maps and manual processes for days because their TEMA system was completely fried. The infection vector was a compromised update to M.E.Doc, a Ukrainian accounting software. The attackers had been sitting in the update chain for months before deploying the payload. Ryuk hit in 2018 and targeted American organizations specifically. It demanded ransoms in the millions, often $25,000 minimum and sometimes up to $20 million. The distinguishing feature was that Ryuk operators would scan your network for weeks before triggering the encryption. They moved laterally, found your backups, encrypted or deleted those too, and then hit production systems. I worked a case where a mid-sized hospital system paid $600,000 because they couldn't restore from offline backups. The attackers had found the backup server on the same subnet and hit it first.

Mariadb in 2019 was interesting because it used a living-off-the-land approach. The attackers leveraged legitimate database administration tools to move through networks undetected for extended periods. Several manufacturing companies were affected, and the attackers specifically targeted OT/ICS systems, which made traditional recovery much harder since you can't just reimage a PLC. CWunab/Ragnar Locker appeared around 2020 and pioneered double-extortion at scale. They wouldn't just encrypt your files. They would exfiltrate everything first, then send you the data along with the encryption. Even if you restored from backups, they still had copies of your confidential information. This fundamentally changed the calculus because restoring data no longer solved the problem. You could pay the ransom and still face regulatory notification requirements if customer data was in that exfiltrated pile. Conti in 2021 became one of the most aggressive operators. Colonial Pipeline is the big one here. They shut down the largest fuel pipeline in the United States, causing gas shortages across the Southeast. The FBI traced the ransom payment back to a wallet that was later seized. Colonial paid roughly $4.4 million, mostly in Bitcoin, though they later claimed only $150,000 was actually paid. The real cost was far higher due to operational disruption and recovery expenses, estimated in the hundreds of millions.

Kaseya VPS attack in July 2021 was a supply-chain ransomware event. The attackers compromised Kaseya's virtualization platform and pushed malicious code to 1,500 of their customers simultaneously. Most of those customers were smaller managed service providers who had no visibility into what was running on their clients' systems. This was unprecedented because the blast radius came from a single vulnerability in a management tool, not from individual organization failures. LockBit 3.0 has been the dominant ransomware gang since late 2021. They operate as a ransomware-as-a-service model, meaning they recruit affiliates who handle the actual attacks while LockBit provides the tooling and support. They claim over 1,600 victims and have extorted more than $350 million. Their public leak site publishes victim data as proof of payment, which creates enormous pressure on organizations to pay quickly. The group is believed to be based in Eastern Europe, though exact attribution is difficult. Black Basta emerged around 2022 and differentiates itself with a cleaner operation. They don't leak victim data publicly. Instead, they negotiate directly and claim to have a code of conduct. Whether that's genuine or just smarter extortion strategy is debated. JBS Foods, one of the world's largest meat processors, paid $11 million to Black Basta after a 2022 attack. The damage was less about the ransom payment and more about the operational chaos that followed.

How These Attacks Actually Work

The initial access is almost never a direct intrusion. Attackers use phishing emails with malicious attachments, credential theft from legitimate services, or exploitation of unpatched vulnerabilities in internet-facing systems. The most common entry point remains phishing. A single employee clicks a link, and the attacker now has a foothold. From there, the typical path involves privilege escalation, lateral movement, and reconnaissance. Attackers map the network, identify critical systems, locate backup infrastructure, and determine where sensitive data lives. This phase can take days or weeks depending on how well the target organization segments its network. The encryption phase is surprisingly fast. Modern ransomware can encrypt terabytes of data in under an hour if the network infrastructure supports it. The real bottleneck isn't encryption speed. It's the initial access and lateral movement. Attackers who spend three weeks moving through a network are the ones who cause the most damage because they find everything before they touch anything.

I learned this the hard way during a 2019 engagement. We responded to a ransomware event at a manufacturing client. The attackers had been in the network for about ten days before triggering encryption. In that time, they had enumerated every domain controller, located three separate backup systems, disabled the backup software services, and exfiltrated approximately 200GB of engineering drawings. When we arrived on scene, the encryption was already complete. The backup systems were corrupted, not just encrypted. The attackers had specifically targeted the VSS (Volume Shadow Copy Service) on Windows systems, which meant even local restore points were gone. We ended up recovering from a tape backup that was stored offsite and hadn't been updated in three months. The business lost a week of operational data because the backup retention policy was insufficient for ransomware recovery scenarios.

What to Do When It Hits

Isolation is the first priority. Disconnect the affected systems from the network immediately. Don't shut them down unless necessary, because RAM forensics can provide valuable information about the attack. If you shut down a system, you lose volatile evidence. But if the ransomware is actively spreading, isolation takes precedence over forensics. Assess the scope. Determine which systems are affected, which backups are intact, and whether data was exfiltrated. You need this information before you make any decisions about restoration or payment. The existence of exfiltrated data changes everything because even a successful restoration doesn't eliminate the breach if customer or employee information left the network. Do not pay the ransom as a first resort. Law enforcement generally recommends against payment because it funds further criminal activity and doesn't guarantee data recovery. That said, the reality is more complicated. Some organizations pay because the alternative is permanent operational closure. I've seen small healthcare providers pay because they couldn't afford the downtime, and I've seen them suffer anyway because the decryption keys didn't work properly.

If you decide to restore, start with isolated, verified clean backups. Test the restoration before applying it to production systems. A corrupted restoration is worse than the original encryption. During the Kaseya incident, several MSPs attempted to restore their systems only to find that the malicious code had infected their backup files too. The attackers had compromised the Kaseya backend before pushing the ransomware payload, which means backup integrity depends on the backup source being clean. Notification requirements vary by jurisdiction. HIPAA mandates notification within 60 days of discovering a breach. GDPR requires notification to the supervisory authority within 72 hours. Many states have specific ransomware notification laws. Document everything. The forensic timeline matters for regulatory compliance and potential legal proceedings.

Prevention That Actually Works

Backup strategy is the single most effective defense. The 3-2-1 rule applies here: three copies of your data, two different media types, one offsite. But the important detail most organizations miss is that backups need to be immutable. Write-once-read-many storage prevents ransomware from encrypting or deleting backup files. I worked with a company that had excellent backups but stored them on a network-attached storage device. The ransomware hit, found the NAS, and encrypted everything. They had backups. They just couldn't access them. Network segmentation limits lateral movement. If the accounting department's systems are on the same VLAN as the manufacturing control systems, a compromise in one area affects everything. Segmentation doesn't need to be elaborate. Simple VLAN separation with firewall rules between segments can dramatically reduce the attack surface. Email filtering and endpoint detection are standard recommendations, but the effectiveness depends on configuration. Many organizations have EDR solutions that are enabled but not actively managed. Alerts go unread, policies aren't tuned, and the software becomes a checkbox rather than a defense. I've seen EDR blocks that were silently failing because the management console was configured to only log threats rather than block them.

Patch management is painful because it requires coordination across departments and systems. Legacy equipment often can't be patched, which creates permanent vulnerabilities. The Colonial Pipeline attack exploited a VPN vulnerability that had a known patch. The organization had the patch available but hadn't deployed it due to change management processes. Employee training helps but has limited impact. Phishing simulations show that even well-trained employees fall for sophisticated lures. The question isn't whether training works. It's whether you have technical controls that catch what training misses. Multi-factor authentication on remote access and privileged accounts is one of the most effective single controls available. It prevents attackers from using stolen credentials to move laterally, which is the phase where most ransomware deployments succeed or fail.

When Prevention Fails

The hard truth is that ransomware will breach organizations regardless of their security posture. The question is how quickly you detect it, contain it, and recover. Dwell time matters enormously. The average dwell time for ransomware attacks is around 25 days according to various industry reports. During those 25 days, attackers are mapping your network, stealing your data, and planning their encryption strategy. Detection capabilities that identify suspicious lateral movement or unusual data access patterns can catch an attack before encryption begins. The insurance angle is worth considering. Cyber insurance premiums have risen sharply, and many policies now require specific security controls before providing coverage. Some insurers won't cover ransom payments at all. Understand your policy before you need it. Recovery planning should include a decision tree for the ransom payment question. Your board needs to understand the criteria: what ransom amount triggers legal review, when does operational necessity override the non-payment stance, what's the process for engaging with law enforcement regarding payment tracing. Having these decisions pre-approved saves time during a crisis when everyone is operating under extreme stress.

The ransomware landscape continues to evolve. As encryption becomes less effective at forcing payment, operators are leaning harder into data extortion and public shaming through leak sites. The financial motive hasn't changed, but the tactics have shifted toward psychological pressure rather than technical obstruction alone. Understanding where the industry is heading matters as much as understanding what happened in the past.