A manufacturer with USB-drive backups and RDP open to the internet lost everything to ransomware in one morning, including the backups. What recovery looked like, what the ransom really bought, and what exists now instead.
The situation
In 2016, a manufacturer of about forty people, ten in the office and thirty on the floor, ran its entire business through one server: the ERP that scheduled and costed every job, and every file the office produced. The server was running Small Business Server 2003, a product that had passed the end of its extended support the year before. Remote users reached it over RDP, left open to the internet because that was the easiest way to make remote access work.
The backups were USB drives plugged into that same server.
When the ransomware arrived through the open remote access, it did what ransomware does: it encrypted everything it could reach. And because the backup drives were attached to the machine being encrypted, they were not a backup at all. They were just more disk. The backups were among the first things lost.
- The ERP, encrypted. No job costing, no scheduling, no order history
- Every office file, encrypted
- The USB backup drives, encrypted along with the server they were plugged into
- An operating system so old that modern recovery tooling no longer expected to meet it
The company had an IT person, and this was the day that arrangement reached its limit. This is not a story about a client of ours. They were not a client. They called Tech Dynamix the way you call for help when the person responsible has run out of answers, because thirty people on a production floor were about to have nothing to build from.
What we did
What we did
Triage came first, and triage delivered the worst version of the facts: there was nothing to restore from. No offsite copy, no disconnected drive, no earlier server. The choices were to rebuild the business from paper, or to pay.
That decision belonged to the owner, and with the ERP holding every order and every job, the owner paid. Several thousand dollars, in Bitcoin, to criminals, for the return of the company's own data. We will not dress that up as a strategy. It is the position a business is in when its backups fail with it, and everything else in this case study exists so that no one reading it ends up making that decision.
Paying was not the end of it, and this is the part people do not expect. The decrypter the attackers provided assumed a modern Windows system. Pointed at a 2003-era server, it failed: runtimes it depended on did not exist there, and the tool itself was buggy. Tech Dynamix spent the weekend debugging the criminals' own software, supplying the components it silently required and working around its failures, to make the ransom the owner had already paid actually produce the data it was paid for.
Around that ran the rebuild. By the end of the weekend the core systems were running and the floor could work. Getting to nearly everything back took over a week, file by file, system by system, on hardware that should have been retired years earlier.
Where it landed
The company came out the other side, which in 2016, with encrypted backups and a server two years past the end of its support, was not the likely outcome.
- Core systems running after one weekend
- Nearly everything recovered in just over a week
- The full cost was the ransom plus the downtime plus the rebuild, and the ransom was the smallest of the three
They became a managed services client, and the environment that made the incident possible was dismantled: the server replaced, backups moved to a system that runs automatically, keeps copies away from the machines it protects, and gets tested rather than assumed, and remote access closed off from the open internet.
The lesson is the one the USB drives taught. A backup that sits attached to the server it protects fails at the exact moment it is needed, because whatever takes the server takes the backup with it. And paying the ransom is not the recovery plan people imagine: the money buys you a broken tool written by criminals, and if nobody on your side can make it work, the payment buys nothing at all.
Real backups make the entire question disappear. That is what they are for.
The numbers
| What changed | Before | After |
|---|---|---|
| Backups | USB drives plugged into the server | Automatic, tested, with copies kept apart |
| Remote access | RDP open to the internet | Closed off from the open internet |
| Server | SBS 2003, past end of support | Replaced and supported |
| Time to get core systems running | No plan existed | One weekend |
| Time to nearly everything recovered | No plan existed | Just over a week |
| What ransomware could take | Everything, backups included | What the last backup missed |
What it changed
- The ransom, several thousand dollars in Bitcoin, turned out to be the smallest of the three costs. The downtime and the rebuild were the other two.
- The ransom worked only because somebody debugged the attackers' broken decrypter on a weekend. Nothing about that is a plan. The plan is the backup system that has existed since.