Another day, another cyberattack. This time Patelco — a credit union with over $9 billion in assets and 400,000+ members — has been hit by ransomware. The downstream impact is going to be significant.

Worth using this one as a teaching moment, because the mechanics are increasingly the same across incidents.

How a ransomware attack actually unfolds

Most ransomware operations follow a three-stage pattern. Understanding each stage matters because the defences for each are different.

1. Access

The attackers get in. The how varies — phishing emails, exploitation of unpatched vulnerabilities, stolen credentials bought from initial access brokers, supply chain compromises.

Once inside, they usually don’t strike immediately. They dwell — moving laterally, mapping the network, identifying critical systems (file servers, backup infrastructure, domain controllers), and escalating privileges. This phase can run for days or weeks before anything visibly bad happens.

2. Activation

When the attackers are ready, the encryption payload deploys across as many systems as they’ve reached. Files become inaccessible. Services break. And critically, the attackers usually:

  • Delete or encrypt backups first, so recovery isn’t a quick restore
  • Disable security tooling that might raise alerts
  • Exfiltrate sensitive data before encryption (so they have something to extort with even if you have backups)

Modern ransomware is rarely just encryption anymore. It’s encryption plus a data leak threat.

3. Ransom demand

The ransom note arrives — typically a cryptocurrency demand with a deadline. If you don’t pay, the price increases. If you still don’t pay, the stolen data goes public.

This is why “we have backups” no longer makes you immune. Backups solve the encryption problem. They don’t solve the data leak problem.

The real impact

A ransomware incident isn’t just an IT crisis — it cascades:

  • Financial losses — response costs, possible ransom, recovery work, business interruption
  • Personal data exposure — for a financial institution, that means SSNs, account details, transaction history
  • Brand damage — trust is hard to rebuild after members find out their data sat in a criminal’s bucket
  • Regulatory penalties — failure to meet data protection obligations can compound the bill significantly

The takeaway

The pattern hasn’t really changed in years. What changes is the scale and sophistication of each phase. Initial access is industrialised. Lateral movement tooling is mature. Extortion has become a parallel revenue stream alongside encryption.

The defensive posture has to match: assume the access will happen, make the dwell time visible, segment so lateral movement is expensive, and treat backups and data leak prevention as two separate problems that both need solving.


Incident details: Patelco ransomware report