Ransomware Protection
Ransomware Attack Case Studies: Lessons From Major Incidents
Major ransomware case studies — including Colonial Pipeline (a ransom of about $4.4 million (USD), fuel supply disruption), NotPetya (billions of US dollars in global damage via supply chain), WannaCry (200,000+ victims across 150 countries), and MOVEit/Cl0p (2,500+ organisations breached) — reveal consistent patterns: unpatched vulnerabilities, inadequate segmentation, and insufficient backup isolation.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
Why Study Ransomware Incidents?
Every major ransomware attack reveals gaps that many organizations share. Studying these incidents — how the attackers got in, how they moved, why defenses failed — provides actionable intelligence for strengthening your own security posture. The patterns are remarkably consistent.
Case Study 1: Colonial Pipeline (May 2021)
- What happened: The DarkSide ransomware group attacked Colonial Pipeline, the largest refined-products pipeline in the United States. The attack shut down pipeline operations for 6 days, causing fuel shortages across the southeastern US.
- Initial access: A compromised VPN credential — a legacy VPN account without multi-factor authentication. The password was found in a previous dark web data dump.
- Impact: Pipeline operations shut down for 6 days. Fuel shortages and price spikes across multiple states. Colonial paid a ransom of about $4.4 million (USD). The US government recovered approximately $2.3M of the payment.
- Lessons:
- MFA is non-negotiable. A single VPN account without MFA brought critical infrastructure to a halt.
- Disable legacy accounts. Dormant accounts with active credentials are a common entry point.
- Segment IT and OT networks. Colonial shut down OT (pipeline operations) as a precaution because they couldn't confirm the attack hadn't spread. Better segmentation would have allowed continued operations.
- Don't pay (if possible). While Colonial paid, the decryption tool was so slow they ended up restoring from backups anyway.
Case Study 2: NotPetya (June 2017)
- What happened: NotPetya masqueraded as ransomware but was actually a destructive wiper, attributed to Russian military intelligence. It spread via a compromised Ukrainian tax software update (M.E.Doc) and then laterally using EternalBlue and credential harvesting.
- Initial access: Supply chain attack — a compromised software update to M.E.Doc, used by virtually every company doing business in Ukraine.
- Impact: billions of US dollars in global damage, according to the White House. Maersk (shipping): an estimated impact of $200–300 million (USD). Merck (pharma) and FedEx/TNT also reported losses in the hundreds of millions of US dollars. Multiple global companies shut down for weeks.
- Lessons:
- Supply chain attacks are devastating. One compromised supplier can affect thousands of organizations globally.
- Worm capabilities multiply impact. NotPetya spread using EternalBlue (the same exploit as WannaCry) — an unpatched vulnerability. Patching would have contained the spread.
- "Ransomware" may be a cover. Not all encryption attacks are financially motivated. Nation-state actors use ransomware as a cover for destruction.
- Backups must survive the attack. Companies that lost their domain controllers and backup systems took weeks or months to recover. Maersk was saved by a single offline domain controller in Ghana.
Case Study 3: WannaCry (May 2017)
- What happened: WannaCry exploited the EternalBlue vulnerability in Windows SMB to spread across networks and the internet, encrypting systems in over 150 countries. The NHS in the UK was severely affected, with hospitals unable to access patient records.
- Initial access: Self-propagating — WannaCry scanned the internet for vulnerable SMB services and exploited them directly.
- Impact: 200,000+ systems in 150 countries. NHS: at least 81 of 236 trusts in England affected, and an estimated 19,000 appointments cancelled.
- Lessons:
- Patch critical vulnerabilities immediately. The EternalBlue patch was available for two months before WannaCry. Organizations that patched were unaffected.
- Network segmentation limits spread. WannaCry spread via SMB. Organizations that segmented networks and blocked unnecessary SMB traffic contained the damage.
- End-of-life systems are critical risks. Many affected systems ran Windows XP, which was no longer receiving security updates.
Case Study 4: MOVEit / Cl0p (2023)
- What happened: The Cl0p ransomware group exploited a zero-day SQL injection vulnerability in MOVEit Transfer, a widely used file transfer application. They used the vulnerability to steal data from organizations using MOVEit — mass exploitation without deploying traditional ransomware.
- Initial access: Zero-day vulnerability exploitation in MOVEit Transfer (CVE-2023-34362).
- Impact: 2,700+ organisations and more than 95 million individuals affected. Victims included Shell, BBC, British Airways, US Department of Energy, and multiple government agencies. Emsisoft estimated the total cost at more than $15 billion (USD), based on IBM's average cost per record.
- Lessons:
- Third-party software is a risk. Widely deployed software becomes a high-value target. Monitor for vulnerabilities in all third-party applications.
- Zero-days happen. You can't patch what isn't known. Defense in depth — monitoring, segmentation, and data loss prevention — catches attacks that exploit unknown vulnerabilities.
- Data-only attacks are increasing. Cl0p stole data without encrypting systems. Even organizations with excellent backups lost sensitive data.
- Minimize data in transfer tools. Don't store sensitive data longer than necessary in file transfer systems. Reduce the data available for theft.
Common Patterns Across All Cases
Every major ransomware incident shares these patterns:
- Initial access was preventable — unpatched vulnerability, missing MFA, legacy account, or supply chain oversight
- Lateral movement was undetected — insufficient monitoring, missing segmentation, or blind spots
- Backups were insufficient — encrypted, corrupted, untested, or too slow for recovery
- Response was reactive — organizations discovered attacks too late, lacked response plans, or made costly decisions under pressure
The organizations that recovered fastest shared three traits: immutable backups, network segmentation, and practiced incident response.
How SeqOps fits
Ransomware usually starts with a known weakness: an unpatched server, an exposed service or a misconfigured cloud account. SeqOps finds these across your cloud and servers and ranks them so you can close the most dangerous ones first. It doesn't detect or stop an attack in progress.
Sources
- CISA Advisory AA23-158A, CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability (2023)
- National Audit Office, Investigation: WannaCry cyber attack and the NHS (27 October 2017) (2017)
- Kaseya press release, Kaseya Responds Swiftly to Sophisticated Cyberattack (5 July 2021) (2021)
- The White House, Statement from the Press Secretary on NotPetya (15 February 2018, archived) (2018)
- CISA, The Attack on Colonial Pipeline: What We've Learned & What We've Done Over the Past Two Years (7 May 2023) (2023)
- GovInfoSecurity, $2.3 Million of Colonial Pipeline Ransom Payment Recovered (7 June 2021) (2021)
- Computer Weekly, NotPetya attack cost up to $300m, says Maersk (16 August 2017, citing Maersk's Q2 2017 interim report) (2017)
- NCSC, UK supports US charges against North Korean cyber actors (17 February 2021) (2021)
- Emsisoft, Unpacking the MOVEit Breach: Statistics and Analysis (2,773 organisations and 95,788,491 individuals as of 28 June 2024) (2024)