Skip to content

Incident response · 9 min read · 4 August 2026

Ransomware in 2026: What Happens During the First 24 Hours?

Encryption is the end of a ransomware attack, not the beginning. Understanding what happens beforehand is what makes prevention possible.

Most people picture ransomware as a single moment: screens change, a demand appears and work stops. That moment is the conclusion of a process. By then the attacker has usually obtained access, mapped the environment, raised privileges, weakened some defences and copied the data intended for leverage.

Every one of those earlier steps is an opportunity. Encryption is difficult to undo; almost everything before it can still be interrupted. The fictional timeline below follows Halden Precision, a mid-sized manufacturer with about 400 employees, three sites and a small IT team.

Why the first day is the whole argument

Mandiant's M-Trends 2026 reported that global median dwell time, the interval between intrusion and discovery, rose to 14 days in 2025. Yet the median hand-off from an initial-access operator to a secondary group collapsed from more than eight hours in 2022 to just 22 seconds in 2025. Access is now a product, and damaging operations can begin almost immediately after it changes hands.

48%

Share of analysed breaches involving ransomware in Verizon's 2026 DBIR, up from 44% in the prior edition.

14 days

Global median dwell time reported by Mandiant for 2025 investigations, up from 11 days.

Verizon also reported that 69% of ransomware victims in its 2026 dataset did not pay. Recovery capability is improving even though ransomware remains frequent.

Fictional 24-hour attack timeline
  1. 00:00Initial accessPatch exposed systems
  2. 00:20Credential compromiseLeast privilege + MFA
  3. 01:10ReconnaissanceBehavioural detection
  4. 03:45Privilege escalationTiered administration
  5. 05:30Lateral movementSegmentation + monitoring
  6. 11:00Data exfiltrationEgress baselines + DLP
  7. 17:40Backup interferenceImmutable offline copy
  8. 21:15EncryptionContinuity limits impact
  9. 23:30DetectionResponse and recovery

The first 24 hours at Halden Precision

00:00 Initial access

An internet-facing remote access appliance at a secondary site is running a version with a publicly known vulnerability. The patch was released weeks earlier but never completed. Automated scanning finds the exposure and access follows. The interrupting control is straightforward: an accurate inventory and patching priorities driven by known exploitation, not severity scores alone.

00:20 Credentials turn access into identity

A service account used by the appliance has an old password and more permissions than its function requires. The intruder can now authenticate internally as a legitimate identity. Separate service accounts, least privilege, phishing-resistant MFA on remote access and alerts for unusual service-account activity could stop the chain here.

01:10 to 05:30 Reconnaissance, escalation and movement

The environment is mapped using utilities already present. One identity queries far more servers, file shares and directory objects than its role requires. Later, an administrator session left open on a management server provides elevated rights. Movement between systems then uses tools the IT team itself relies on.

This stage rewards behavioural monitoring. Enumeration, privileged-group changes, unusual administrative connections and remote-management software operating outside an approved list are more useful signals than looking only for malicious files. Tiered administration and network segmentation reduce what a single compromised identity can reach.

08:15 Security controls go quiet

Monitoring agents are disabled on selected systems and log retention is shortened. The dashboard shows fewer alerts, which looks like a calm morning. A mature programme treats missing telemetry as an alert of its own. Endpoint tamper protection and logs stored outside the administrator's control preserve visibility.

11:00 to 17:40 Data leaves and backups are targeted

Finance, HR, legal and engineering files are collected and transferred over an encrypted connection to a commercial cloud service. Egress baselines, data-loss prevention on high-value repositories and alerts for unusually broad file access could still interrupt the operation.

Later, online backup jobs are altered and reachable copies are made unusable. An offline copy survives because it was never network-accessible. Immutable or air-gapped backups, separate administrative identities and routine restore tests determine whether recovery is a plan or a hope.

21:15 to 23:30 Encryption, extortion and detection

Encryption begins outside working hours through legitimate management channels. File services, scheduling and the ERP platform become unavailable. A demand follows, supported by a sample of stolen data. At this point prevention has failed; segmentation and continuity planning can only limit operational impact.

A night-shift supervisor finally reports that a production schedule will not open. Detection comes twenty-three and a half hours after the first connection. Any one of the earlier controls could have produced a materially different day.

What the timeline says about investment

The entry point was ordinary. Verizon's 2026 DBIR says vulnerability exploitation became the leading initial-access vector at 31% of breaches, while Mandiant found exploits accounted for 32% of intrusions in 2025. The tooling looked legitimate and data left before encryption. Investment therefore belongs in rapid remediation, behavioural detection, segmented administration, egress visibility and backups outside the production identity plane.

Containment and recovery priorities

Containment starts by isolating affected systems without automatically powering everything off, because volatile evidence may explain what happened. Disable compromised accounts, revoke sessions and verify that backup infrastructure remains separated.

Preserve logs and disk evidence, establish the entry point and determine what data left the environment. Move communication to an independent channel and involve counsel and insurers early. Recovery should rebuild trust, reset service identities and application secrets, restore in business-dependency order and monitor for re-entry.

Ransomware readiness checklist

  • Every internet-facing system has an owner, inventory record and patch service level.
  • Remote access requires phishing-resistant MFA with no informal exceptions.
  • At least one backup copy is immutable or offline and has been restored successfully.
  • Privileged identities are separated from ordinary daily-use accounts and workstations.
  • Endpoint agents resist tampering and missing telemetry generates an alert.
  • Outbound data volumes are baselined, especially for critical repositories.
  • An out-of-band communication channel and printed crisis contacts are available.
  • Leadership has rehearsed an incident and documented decision authority in advance.

The window is longer than it feels

The uncomfortable part of this timeline is how ordinary each stage is: an unpatched appliance, an over-privileged account, a privileged session left open and backups reachable from production. None is exotic, and each can be fixed. Organisations do not need perfection at hour zero. They need something watching at hour three and someone empowered to act on what it sees.

Sources and further reading

  1. 1.Verizon - Data Breach Investigations Report
  2. 2.Google Cloud / Mandiant - M-Trends
  3. 3.NIST SP 800-61r3 - Incident Response Recommendations
  4. 4.CISA - StopRansomware Guide