How a Hacker Breaks Into a Small Business for $14

TL;DR: Small businesses are the top ransomware target, not the exception. A 20-person company has enough money to be worth attacking and no security team to stop it. This post walks through how a real attack unfolds, step by step, from public records to a Friday afternoon ransom note. Then it shows five ordinary controls, most already bundled in tools you pay for, that would have stopped it cold.

Most small business owners assume hackers chase big companies. The data says the opposite. According to Verizon’s 2025 Data Breach Investigations Report, ransomware showed up in 88% of small business breaches, compared to 39% at large enterprises. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a public footprint an attacker can research in about an hour.

Here is how an attack actually plays out against a business that size. The company below is made up, but every step matches how these attacks really happen. After the walkthrough, you will see five ordinary points where the whole thing would have fallen apart, using controls most small businesses already pay for.

Do hackers really target small businesses like yours?

Yes, and businesses with 10 to 50 staff sit right in the sweet spot. Large companies have security teams and lawyers that make attacks expensive. Sole traders rarely have enough at stake to bother with. A small business in between has real money, real data, and an owner who will pay to get it all back, with almost nothing standing in the way.

The fact that nothing has gone wrong at your company yet is not reassuring to an attacker. It is a green light. It tells them your passwords are probably still valid, your staff has never been trained to spot an attack, and nobody has had a reason to change anything. A clean record is often the first thing they look for. Solid cybersecurity protection is what turns that green light red.

Building your org chart, for free

An attacker can map your whole company in about 40 minutes with nothing but a browser. Public business registries, contract awards, and licensing databases hand over your company name, your legal name, a recent job’s value, and the named contact on the paperwork. None of it costs a cent, and none of it can be taken back down.

From there, LinkedIn fills in the rest. It lists your employees and their job titles. Your office manager’s profile helpfully spells out “accounts payable, payroll, and supplier invoicing,” which marks her as the person who handles money. An old “meet the team” post on Facebook adds first names and faces. Job ads on Indeed reveal which accounting software you run. Within an hour, an attacker knows who moves your money, how long they have been there, and who can approve a payment without a second signature. That person becomes the target, and this is exactly why security awareness training matters as much as any tool.

How does your password end up for sale?

Your password may already be for sale for the price of a sandwich. Attackers buy “stealer logs,” which are bundles of usernames and passwords harvested by malware that infected someone’s personal device, sometimes years earlier. That malware records every password typed into the machine, then the data gets packaged and sold in bulk on hidden marketplaces, searchable by company email domain.

A search for your company’s domain might return your office manager’s work login, with a password saved in her browser. It might also turn up a family member’s personal account that shares a home network with a work device. The cost for the package is often around $14, and the search takes minutes. Many of these passwords follow easy patterns, like a pet’s name plus a year, and a quick check against HaveIBeenPwned, the same free breach database security pros use, often shows the password leaked in an old breach and was never changed. The only thing left between the attacker and the inbox is the second login factor.

How do attackers get past your MFA?

They no longer bombard you with prompts, hoping you tap “approve”. Microsoft closed that door by turning on number matching by default for all Authenticator push notifications in May 2023, which forces you to type a code from your screen instead of tapping yes. So attackers switched to a sneakier method called adversary-in-the-middle phishing.

Here is how it works. The attacker sends an email that appears to be a routine Microsoft 365 password reset, often citing the very breach the password was exposed in. The link opens a page that looks exactly like the Microsoft sign-in screen, but it is actually a relay controlled by the attacker. When the target enters her password and approves the MFA prompt, the relay passes both to the real Microsoft server, which issues a session token, the digital pass that keeps you logged in. The attacker grabs that token and signs in as her, while she just sees a “password updated” message.

If the email fails, there is a backup plan: a phone call to your front desk, posing as your IT company using a name pulled from an old Google review, asking someone to approve a verification prompt. Once inside, the attacker quietly sets up a rule that forwards the office manager’s email to an address they control, then waits. Locking down email and spam protection is one of the places this quietly falls apart, as you will see below.

Why does an attacker wait before striking?

Because reading your email first is how they size the ransom. An attacker often spends 36 hours inside the inbox before encrypting anything. That waiting period, called dwell time, is where they learn exactly how much you can pay and how badly you need your files.

In a day and a half of reading, an attacker can find your cyber insurance policy and its coverage limit, a bank reconciliation showing your account balance, your customer list, and a message about a project with a hard deadline you cannot miss. Armed with that, they set a ransom low enough that you will pay rather than fight, but high enough to be worth their time. Then they pick the worst possible moment, like 2:47 pm on a Friday, right after your bookkeeper leaves and while you are out on a job site. By the time anyone notices, every file on the shared drive is locked and a ransom note is on every screen. The total cost to the attacker was about $14 and a few hours of work.

Five places this attack would have died

The attack worked because five ordinary things were missing, and none of them are expensive. Most are already built into tools a business this size already pays for. Each one alone could have ended the whole thing.

First, the credential purchase. Blocking reused and known-breached passwords through a password manager and Microsoft Entra password protection makes a bought password useless.

Second, the MFA bypass. Phishing-resistant MFA, such as a hardware key, passkey, or Windows Hello, cannot be relayed via a fake page, so the stolen token would have been worthless.

Third, the forwarding rule. Microsoft 365 lets admins block external email forwarding at the tenant level, which would have stopped the attacker from reading 36 hours of mail.

Fourth, the dwell time. Microsoft Defender for Business, included in Microsoft 365 Business Premium, raises an alert the moment a new forwarding rule is created. Someone reviewing those alerts would have caught this on night one, which is where day-to-day managed IT services earn their value.

Fifth, the public exposure. You cannot unpublish a state registry, but you can coach your team on how much detail they put in their profiles. An office manager’s LinkedIn listing of every financial duty made her the obvious target, and that is a friendly conversation worth having.

The theme across all five is simple. The most useful change for a small business is rarely a new product. It is having someone actually watch the alerts the tools you already own are already sending.

Three questions to send your IT provider

You do not need to understand every technical detail to close these gaps. You need three clear answers. Send these to whoever manages your technology, and a good IT partner should be able to confirm all three within an hour or two.

First: are we using phishing-resistant MFA, like hardware keys, passkeys, or Windows Hello, for finance, admin, and executive logins? Second: is external email forwarding blocked at the tenant level? Third: are our security alerts going somewhere, and is someone actually reviewing them?

If the answers come back clear and confident, you are in good shape. If they come back vague, you have found your starting point, and it is worth fixing before an attacker finds the same gaps first. Not sure where your business stands? Reach out to our team and we will walk through these three questions with you.

Worried this sounds like your business?

If any part of that walkthrough felt uncomfortably familiar, that is worth acting on now rather than after an incident. Z-JAK Technologies can review your Microsoft 365 setup, confirm whether these five controls are in place, and close the gaps that are not, most of them without buying anything new. Schedule a quick security review and find out where you actually stand.

Frequently Asked Questions

Do hackers target small businesses?

Yes. Most ransomware operations focus on small and mid-sized businesses because the payout is high relative to the defenses in place. According to Verizon’s 2025 report, 88% of small business breaches involved ransomware, versus 39% at large enterprises. The sweet spot is roughly 10 to 50 staff, where there are assets worth encrypting but no dedicated security team.

What is adversary-in-the-middle (AiTM) phishing?

AiTM phishing is a technique where the attacker hosts a fake login page that relays everything to the real service. When the user enters their password and approves the MFA prompt, the relay captures the resulting session token. The real service sees a normal login, but the token ends up in the attacker’s browser, giving them access. It has become the most common way attackers get past standard MFA.

What is a stealer log?

A stealer log is a package of passwords harvested by malware from an infected personal device. It includes browser-saved passwords and login tokens, and the packages sell for roughly $10 to $20 on underground markets. The malware usually gets onto personal computers through pirated software or malicious browser extensions, which is why personal-device hygiene affects your business.

How much does it cost an attacker to compromise a small business?

In the walkthrough above, the total was about $14 for stolen credentials and a few hours of work. Costs vary, but the bar to attempt this kind of attack sits well under $100. That low cost is exactly why small businesses get targeted so often.

Are there free tools that would have stopped this attack?

Several of these controls come bundled with the Microsoft 365 Business Premium licenses many small businesses already hold. Blocking external forwarding and turning on Defender for Business alerts are configuration changes, not new purchases. HaveIBeenPwned is a free breach check anyone can use. Phishing-resistant MFA keys are a small per-user cost next to the price of a ransomware incident.