A detailed forensic analysis of a multi-stage ransomware intrusion that began with SEO poisoning on Bing, luring users to a trojanized ManageEngine OpManager installer. The BumbleBee loader was deployed via DLL side-loading, followed by an AdaptixC2 beacon for persistent C2. Over five days, threat actors performed extensive credential harvesting (NTDS.dit, Veeam, LSASS), lateral movement via RDP and reverse SSH tunnels, and exfiltrated over 75GB of data via FileZilla/SFTP to a server in Ukraine. The intrusion concluded with Akira ransomware deployment across root and child domains, with Volume Shadow Copies deleted via WMI. A parallel Swisscom intrusion tied to the same campaign is also documented, including BYOVD attacks and Cloudflare tunnel persistence.