A Ransomware Attack at 2am

A Ransomware Attack at 2am

A Ransomware Attack at 2am


It starts with one click. A user opens a phishing email minutes before leaving for the day. The payload waits. At 2am, with nobody watching, files begin encrypting and data starts leaving the network. By morning, screens are blank. This is the most common attack pattern MSPs describe to us, and the gap it exploits is not a tooling gap. It is the hours when nobody is awake. 


enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. This is what the same night looks like with a 24/7 SOC on watch. 

The situation


A mid-size client, a busy Thursday, an email built to look like a supplier document. The user clicks, enters credentials on a convincing page, and moves on with their day. Nothing visible happens. The attacker now has a foothold and a plan: stay quiet through business hours, map the network, and go loud when the response window is widest. 


At 2am the loud phase starts. A process begins encrypting file shares at machine speed while a second channel stages data toward an external host. 

What we detect


The signals arrive as a sequence, across more than one surface. The email connector flags the message source against known phishing infrastructure. Identity telemetry shows a login from an unfamiliar location on the compromised account. The endpoint agent reports an unusual process touching files at abnormal volume. The network sensor sees outbound traffic climbing toward a destination the environment has never spoken to. 


Correlation ties those signals into a single Critical case with a timeline attached: the click, the login, the process, the traffic. One attack, not four alerts. 

What gets automated


The response actions were agreed at onboarding, so nothing waits for a phone call. The affected host is contained through the endpoint integration. The compromised account is disabled. The outbound destination is blocked at the firewall. Encryption stops where it stands, and the staging channel dies with the connection. 

Where humans step in


A SOC analyst picks up the Critical case, confirms the automated actions held, and checks for lateral movement the timeline might have missed. Escalation to the MSP follows the agreed out-of-hours path with the case detail attached. In the morning, the Fractional Security Director walks the MSP through what happened, what stopped it, and what the client conversation should cover. 

The outcome


Encryption reached a small number of files on one machine before containment. No data left the network. The client's morning starts with a briefing from their MSP, not a blank screen. The monthly report shows the case timeline end to end, which is the version of this story an MSP wants to be telling. 

Check your own stack


  • Who is watching your clients between midnight and 6am? 

  • Which response actions run tonight without waiting for approval? 

  • Would an endpoint alert, an identity alert, and a traffic spike arrive as one case or three? 

  • Does anything watch network traffic, or only devices with agents? 

  • What is your out-of-hours escalation path, written down? 

Want to know what your current setup does in this scenario?

Want to know what your current setup does in this scenario?

Want to know what your current setup does in this scenario?

Book a 30-minute call with Hannah Lloyd, our co-founder