THREAT / RANSOMWARE2026-09-029 min

Ransomware attack examples: 6 scenarios and where to break them

Six realistic attack paths, from a stolen VPN account to a compromised supplier, with chain-breaking controls.

Direct answer

A useful ransomware example describes the full path: initial access, privilege, propagation, exfiltration and impact. That view shows exactly where defenders can detect or interrupt the operation.

48%

of breaches involved ransomware

Verizon’s 2026 DBIR found ransomware in 48% of breaches in its dataset. The benchmark supports prioritizing backups, identity, segmentation and response readiness.

Verizon — 2026 Data Breach Investigations Report

Scenarios 1 and 2: remote identity and email

A reused VPN password opens the network where MFA is absent. Breakpoints include phishing-resistant MFA, access policy and new-session detection.

In the second path, an attachment launches a loader followed by legitimate administration tools. Attachment controls, endpoint telemetry and least privilege expose the sequence.

Scenarios 3 and 4: vulnerability and administration

An unpatched edge device becomes the entry point. Continuous inventory, exposure-based patching and device telemetry reduce the window.

A domain administrator is then used from a normal workstation. Dedicated admin stations, PAM and tier separation limit the stolen identity.

Families change; defensive decisions should be built around the attack path.
Key takeaway:Families change; defensive decisions should be built around the attack path.

Scenarios 5 and 6: cloud and suppliers

A malicious OAuth app reads mail and files without stealing a password. Restricting consent and monitoring grants breaks the path.

A compromised supplier uses legitimate maintenance access. Time-bound access, segmentation and session recording reduce implicit trust.

Build an exercise from one path

Choose the most plausible scenario for a critical service, list the expected telemetry and insert three decisions: contain an identity, isolate a segment and stop a service. Add ambiguity to test judgment.

The outcome is an owned gap list with dates and closure tests, not a theatrical scenario.

Operational decision matrix

StageQuestion to resolveExpected outcome
EntryIdentify the verified initial vector.Fix the exposure
ExpansionReconstruct privileges and movement.Find interruption points
ImpactSeparate theft, disruption and encryption.Prioritize critical operations

Using examples well

A historical case is useful when it exposes defensive invariants, not when it freezes a checklist around an old brand.

The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.

Frequently asked questions

Which ransomware path is most common?

It varies by exposure. Compromised identity, edge vulnerabilities and suppliers all require modeling.

Why do attackers use legitimate tools?

Approved tools blend into operations, making context and sequence critical to detection.

How should we choose the first exercise?

Start from a critical business asset and map the most plausible access path through controls actually deployed.

Official sources

Achraf Hachimi

CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.