A multi-site healthcare organization running its own on-premises identity, email, file, and phone infrastructure across all of its locations. Their name and identifying details are withheld in this case study.
The first call came the morning after. Overnight, a professional extortion crew, working with stolen administrator credentials, had:
The organization woke up to the questions every ransomware victim faces at once: what did they touch, what can still be trusted, how fast can we be back, and do we have to deal with the attackers at all?
Containment and evidence. We cut the attacker's paths into the network, isolated the affected systems, and preserved forensic evidence from every touched machine before anything was changed. Recovery has to start from facts, not hope, and evidence only exists if you protect it first.
Forensic reconstruction. We rebuilt the attack minute by minute, from the first quiet probing days before the strike through the overnight attack itself. Just as important, we established what the attacker had not touched, and verified it system by system instead of assuming it.
Recovery from backups. The backup platform's snapshots had survived the attempt to destroy them. Domain controllers, email, file shares, and the phone system came back from clean, pre-attack recovery points or were verified untouched, and every one was checked before it returned to service.
Identity rebuilt, not disinfected. The attacker had held the organization's most privileged credentials. Rather than try to certify a compromised directory as trustworthy again, we rebuilt identity from scratch: every account re-created deliberately, and years of quietly accumulated privilege stripped out along the way.
The move to Microsoft 365. Instead of restoring an aging on-premises email system so it could be attacked again, the organization moved to Microsoft 365: 140 users onto cloud-hosted email, modern identity, and multi-factor authentication as the default rather than an afterthought. The recovery became an upgrade, and one whole class of on-premises risk left the building with it.
Closing the doors. The openings the attacker had used were closed before systems came back online, not after. Compromised and unneeded accounts were disabled as part of containment, and the rebuilt environment came up under our monitoring.
Backups only count if they restore, and if an attacker cannot quietly destroy them first. Evidence comes before action: knowing exactly what was and was not compromised is what makes a recovery both fast and trustworthy. And a compromised identity system is not something to clean, it is something to replace, on newer and better-defended ground than it stood on before.
Those principles turned an attack designed to stop the whole organization into a recovery, and the recovery into a modernization, with nothing paid to the attackers.
Been hit, or want the plan in place before anyone tries? Talk to us.