Time to Ransom is Money

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress analyzed ransomware incidents to measure 'time-to-ransom' — the average time from initial access to ransomware deployment. Across incidents, the average was nearly 17 hours, with attackers taking an average of 18 actions beforehand. Some groups like Play and Akira moved in as little as four hours, while others like Phobos and Maze performed 30+ pre-deployment actions. Two real incidents are detailed: a slow INC ransomware attack on a healthcare entity spanning six days, and a fast Akira attack on a tech company completed in roughly one day. Key pre-deployment tactics included LSASS credential dumping, disabling security tools, lateral movement via WMI/RDP, and data exfiltration. The post contrasts the hours-long attack window with the average 24-day business disruption that follows, and recommends offline backups, incident response playbooks, and SIEM deployment as defensive measures.

8m read timeFrom huntress.com
Post cover image
Table of contents
What time-to-ransom tells us about ransomware groupsTime-to-ransom: How we collected the dataA tale of two incidentsWhy should we care about time-to-ransom?