Skip to main content
28 August, 2024
# Topics
Follow Us

Managed IT Services for Small Businesses: Inside a Texas Ransomware Attack — And What Would Have Stopped It

24 July, 2026

Texas small businesses are among the most targeted ransomware victims in the country. The economics are straightforward: enough revenue to justify the ransom demand, no dedicated security team to respond, and a traceable public footprint that makes reconnaissance easy.

What follows is a step-by-step account of how a ransomware attack unfolds against a typical Texas small business — written from the attack sequence backward, so you can see exactly where managed IT services for small businesses changes the outcome. The company in this scenario is 22 people, in professional services, operating in Texas.

Total cost to the attacker: $14 and approximately six hours. Total cost to the business: significantly more.

Monday: How the Attacker Found the Target

Ransomware operations run prospect lists. This one pulled business listings from Texas state contractor registries, LinkedIn company pages, and federal contract award databases. The small professional services firm appeared on all three. The fact that nothing had gone wrong yet was the strongest signal — it suggested the security posture had never been meaningfully updated in response to a prior breach.

Tuesday: Building the Org Chart for Free

Forty minutes of open-source research produced: eight employees with job titles from LinkedIn, the office manager's name from a Texas business filing, the legal entity structure from state records, and software tools in use from a job posting listing required experience. From that, the attacker knew who handled finances, what platforms were in use, and who the primary target would be — the office manager, who typically has access to financial systems, email, and vendor relationships.

Wednesday: Credentials for $14

Stealer logs — packages of credentials harvested by infostealer malware from infected personal devices — are available for purchase on dark web markets by domain. The office manager's work email and password appeared in a package that cost $14. The password followed a common pattern: a family member's name combined with a birth year, reused across multiple accounts.

This is one of the most preventable entry points in managed IT services security assessments. Password reuse across work and personal accounts means a personal device compromise produces usable work credentials. No firewall stops a credential purchase.

Thursday: Getting Past Multi-Factor Authentication

The office manager's Microsoft 365 account had number-matching MFA enabled. The attacker moved to adversary-in-the-middle (AiTM) phishing — hosting a proxy page that mirrors a legitimate Microsoft login screen. When the target entered credentials and approved the MFA prompt, the proxy forwarded both in real time and captured the resulting session token. The attacker now had an authenticated session without ever seeing the MFA code.

Standard push notification MFA, including number matching, does not stop AiTM. Phishing-resistant MFA — FIDO2 hardware security keys, passkeys, or Windows Hello for Business — stops it because the authentication credential is cryptographically bound to the legitimate domain.

The first thing configured after gaining access: an inbox forwarding rule routing all incoming email to the attacker in real time. Every financial communication, vendor message, and internal email was now being read by a third party.

Friday 2:47 PM: Why the Attacker Waited 36 Hours

In those 36 hours, three things were found: the company's cyber insurance policy (attached to a broker email, including the coverage limit), the company's banking relationships and recent transaction history, and the schedule for Friday afternoon — when the bookkeeper would finish weekly batch payments. The ransom was set at $65,000 — low enough relative to the coverage limit to make payment more likely than negotiation. Encryption deployed at 2:47 PM on Friday.

Five Places This Attack Would Have Stopped

1. Compromised Credential Detection

The office manager's password was in a publicly known breach dataset. A managed IT services provider running quarterly credential exposure checks would have flagged it before it was purchased for $14. HaveIBeenPwned is free. Microsoft Entra Password Protection can detect and block reused compromised passwords. Nobody had checked.

2. Phishing-Resistant MFA

For high-value accounts — finance, admin, executives — phishing-resistant MFA (FIDO2 keys, passkeys, Windows Hello) stops AiTM attacks that defeat standard push notification MFA. Any managed service provider for Texas small businesses should have this deployed on accounts that handle financial transactions or vendor relationships.

3. External Email Forwarding Block

The inbox forwarding rule the attacker created Thursday night, which powered the 36-hour intelligence-gathering window, would have failed to create if Microsoft 365 external forwarding was blocked at the tenant level. This is a single policy setting, available on every Microsoft 365 tenant, that closes one of the primary post-compromise reconnaissance techniques.

4. 24/7 Security Monitoring

Microsoft Defender for Business generates an alert when a new inbox forwarding rule is created. A managed detection and response service receiving those alerts would have detected the attacker's Thursday night activity during the 36-hour dwell time window — before encryption deployed. An alert going to an inbox nobody monitors is not a detection capability.

5. Immutable Backup

The attacker deleted the backup repositories before deploying encryption — using the compromised admin account to reach network-connected backup storage. An immutable backup stored in object-locked cloud storage, with credentials outside the primary admin account structure, cannot be deleted by a compromised admin. Recovery becomes painful but achievable. Without it, the ransom is the only path to business continuity.

What This Means for Texas Small Businesses

If your Texas business is operating without a managed service provider who delivers all five controls — phishing-resistant MFA, Conditional Access, EDR, immutable backup, and 24/7 monitoring — the sequence above describes your actual risk exposure. Managed IT services for small businesses cost a fraction of the average ransomware demand, and significantly less than full recovery when backup fails.

Frequently Asked Questions

Do ransomware attackers target Texas small businesses specifically?

Yes. Most ransomware operations target businesses in the 10 to 50 person range because the ratio of potential payout to defensive resources is more favorable. Texas small businesses in professional services, energy, healthcare, and legal represent the common profile: enough revenue for a meaningful ransom, limited security infrastructure to detect or interrupt the attack.

What managed IT services controls actually stop ransomware?

The controls with the most measurable impact are: phishing-resistant MFA for high-privilege accounts, external email forwarding blocked at the tenant level, 24/7 managed detection and response with alert review and response, endpoint detection and response on all endpoints and servers, and immutable backup stored outside the network with credentials separate from primary admin accounts. Elevate Technology's managed IT services for Texas small businesses include all five.