Home About Services Support Contact Projects Blog
216.785.2700 support@microadv.com Login

Case Study: Ransomware Recovery and a Clean Move to Microsoft 365

A multi-site healthcare organization running its own on-premises identity, email, file, and phone infrastructure across all of its locations. Their name and identifying details are withheld in this case study.

The situation

The first call came the morning after. Overnight, a professional extortion crew, working with stolen administrator credentials, had:

  • Encrypted the file servers and the virtual machines that ran core services.
  • Started destroying the backups, an attempt that was caught and interrupted before it finished.
  • Shut down the endpoint protection that was supposed to stop exactly this, then left ransom notes across the environment.

The organization woke up to the questions every ransomware victim faces at once: what did they touch, what can still be trusted, how fast can we be back, and do we have to deal with the attackers at all?

What we did

Containment and evidence. We cut the attacker's paths into the network, isolated the affected systems, and preserved forensic evidence from every touched machine before anything was changed. Recovery has to start from facts, not hope, and evidence only exists if you protect it first.

Forensic reconstruction. We rebuilt the attack minute by minute, from the first quiet probing days before the strike through the overnight attack itself. Just as important, we established what the attacker had not touched, and verified it system by system instead of assuming it.

Recovery from backups. The backup platform's snapshots had survived the attempt to destroy them. Domain controllers, email, file shares, and the phone system came back from clean, pre-attack recovery points or were verified untouched, and every one was checked before it returned to service.

Identity rebuilt, not disinfected. The attacker had held the organization's most privileged credentials. Rather than try to certify a compromised directory as trustworthy again, we rebuilt identity from scratch: every account re-created deliberately, and years of quietly accumulated privilege stripped out along the way.

The move to Microsoft 365. Instead of restoring an aging on-premises email system so it could be attacked again, the organization moved to Microsoft 365: 140 users onto cloud-hosted email, modern identity, and multi-factor authentication as the default rather than an afterthought. The recovery became an upgrade, and one whole class of on-premises risk left the building with it.

Closing the doors. The openings the attacker had used were closed before systems came back online, not after. Compromised and unneeded accounts were disabled as part of containment, and the rebuilt environment came up under our monitoring.

The results

  • No ransom paid
  • Core systems recovered: identity, email, file shares, and phones
  • Backups did their job: the attacker's attempt to destroy them was interrupted, and the surviving snapshots restored cleanly
  • A complete forensic timeline of the attack, from the first probe to the final action
  • A rebuilt identity system with a clean privilege model, instead of a patched and hopefully clean one
  • 140 users now in Microsoft 365, protected by multi-factor authentication
  • The environment is monitored and maintained by our team today

Why it worked

Backups only count if they restore, and if an attacker cannot quietly destroy them first. Evidence comes before action: knowing exactly what was and was not compromised is what makes a recovery both fast and trustworthy. And a compromised identity system is not something to clean, it is something to replace, on newer and better-defended ground than it stood on before.

Those principles turned an attack designed to stop the whole organization into a recovery, and the recovery into a modernization, with nothing paid to the attackers.

Been hit, or want the plan in place before anyone tries? Talk to us.

Talk to Us Call (216) 785-2700