/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FireEye: 76% of all enterprise ransomware attacks occur outside business hours, when IT staff support is reduced, overall ransomware attacks up 860% since 2017

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

FireEye's timing data lands mid-arc in a ransomware escalation that has been compounding for years: attacks had already quadrupled year over year back in 2016 and were shifting from individual PCs to whole networks, and by early 2020 Trustwave found ransomware had overtaken credit card theft as the most common form of cybercrime. The 860% growth figure since 2017 confirms that trajectory accelerating rather than plateauing.

What makes this report distinct is the operational insight buried in the headline number: attackers are deliberately scheduling strikes for nights and weekends, when enterprise IT staffing thins out. Later survey data bears this out — by late 2022, [[a:984961|more than one-third of cybersecurity professionals said their firm lost more money from holiday or weekend ransomware attacks]], up sharply from the prior year.

First-order effects

  • Enterprises can no longer treat business-hours monitoring as adequate coverage — the majority of attack volume now arrives precisely when in-house IT and security teams are least staffed, forcing immediate rethinking of on-call rotations and alert triage.
  • FireEye's Mandiant-side incident response business gains a concrete selling point: the finding converts an abstract threat statistic into a direct argument for outsourced 24/7 detection and response.

Second-order effects

Third-order effects

  • If the pattern holds, enterprise security structurally migrates toward always-on managed detection and response, because few organizations can staff equivalent expertise around the clock internally — shifting spend from headcount to service contracts.
  • Ransomware consolidating as the dominant cybercrime category, timed against organizational weak points, points regulators toward mandatory incident reporting and minimum-response standards of the kind FireEye itself urged at the SolarWinds hearing.

The trend: Ransomware is industrializing into a scheduled campaign discipline that targets enterprise staffing gaps, pushing security economics from in-house coverage toward continuous outsourced defense.

Discussion

  • @kaseyacorp @kaseyacorp on x
    According to a new survey, 27% of all #ransomware attacks take place during the weekend, 49% after working hours during weekdays, reports @ZDNet https://www.zdnet.com/...
  • @acronis @acronis on x
    💬What matters is ensuring your systems, workloads and data are safe at all times. Night or day, it's time to get #CyberFit with Acronis and keep #Ransomware at bay. via @ZDNet https://www.zdnet.com/...
  • @mandiant @mandiant on x
    We examined dozens of #ransomware incident response investigations from 2017 to 2019 & identified a number of common characteristics in initial intrusion vectors, dwell time, and time of day of ransomware deployment. Discover our findings here: http://r.socialstudio.radian6.com/ …