← Case Studies

The ransomware was the noise. Something quieter had been there a year

A UK operator called us about ransomware on a Friday night. By the Tuesday we had found a second intruder who had been inside for fourteen months and had taken nothing we could see.

A UK regional telecommunications operator, roughly 400 staff, carrying voice and data for business customers including several public sector bodies

  • 14 monthsDwell time of the second intruder, found during ransomware recovery
  • 19 daysFrom first call to full return to service
  • £0Ransom paid
  • 2Separate threat actors evicted in one operation

The situation

Telecommunications carriers sit in an awkward position. They are ordinary businesses with ordinary IT, and they are also critical national infrastructure carrying other people's traffic, which makes them interesting to people who are not interested in money.

That second category is well documented. The China-linked cluster tracked as Salt Typhoon has focused on telecommunications since at least 2019, and public reporting has placed it across more than 600 organisations in some 80 countries, including nine US carriers and the lawful-intercept systems they operate. CISA and allied agencies issued a joint advisory on that activity in 2025. The objective in these campaigns is not disruption. It is access to who is talking to whom.

Those two threats behave completely differently, and the difference matters operationally. Mandiant's M-Trends 2026, drawn from over 500,000 hours of incident response, puts the median time from intrusion to ransomware execution at around five days. The same report puts overall median dwell time at 14 days, with cases found by external notification running to 25, pulled upward by long-dwell espionage. One kind of intruder is in and shouting within a week. The other stays for a year and never raises its voice.

The problem

The operator called on a Friday evening. Ransomware had encrypted a file cluster and two application servers, an extortion note had landed, and the overnight team had already begun shutting things down.

The immediate problems were the usual ones. Nobody knew how the attackers had got in, nobody knew what had been taken before encryption, and the backups had not been restore-tested since a platform change eight months earlier. A 72-hour regulatory clock was running, and the operator carried traffic for public sector customers who would have to be told something before anyone knew what.

The harder problem arrived on day four, and it came from a detail that did not fit.

The forensic timeline showed the ransomware crew buying access from somewhere else, moving fast, and detonating within six days of first entry. Ordinary, and consistent with the published medians. But one of our analysts kept returning to a scheduled task on a domain controller that predated all of it. It was signed, it was named to look like a monitoring agent, and it had been created fourteen months earlier.

It was not theirs. It belonged to somebody who had been quietly reading traffic metadata and mail flow for over a year, had touched nothing, encrypted nothing and demanded nothing.

What we did

The obvious move on day four was to rebuild. The business wanted to trade, the ransomware was understood, and a clean rebuild would have evicted both intruders at once.

We argued against it, and it was not a popular position in a room that had been awake for most of a week.

The reasoning was that a rebuild is a loud act. Rebuilding immediately would have told a patient, well-resourced actor that it had been seen, before we knew how many footholds it held. We had found one scheduled task. We had no idea whether that was the whole of it, and on a fourteen-month dwell, it very rarely is. Evicting the noisy intruder while leaving the quiet one a way back in is the worst of both outcomes, and the operator would have believed itself clean.

So the response split. The ransomware track ran at emergency speed: containment, evidence preservation, sanctions screening on the extortion group, and a restore order the business agreed on commercial grounds rather than technical convenience. The espionage track ran slowly and silently in parallel for eleven days, mapping persistence across the estate without touching any of it, while the attacker continued to believe it was unobserved.

That track eventually found six persistence mechanisms across four hosts, including credentials for a service account nobody could account for and which had been renewed twice by automation.

Eviction happened once, in a single coordinated window, for both actors together.

The outcome

Nineteen days from the first call to full return to service, on evidence the environment was clean rather than on a judgement that enough time had passed.

No ransom was paid. The restore worked because the restore order was decided commercially, so the systems that mattered to trading came back first and the rest followed.

The fourteen-month intrusion is the finding that matters, and it would not have been found at all without the ransomware. That is an uncomfortable thing to write down. A criminal group looking for a quick payment is the reason this operator discovered a state-aligned actor inside its core, and had the ransomware never happened, the quiet one would presumably still be there.

Monitoring now covers the estate rather than the perimeter, and the operator runs continuous exposure management instead of an annual test, because the second intruder did not exploit anything a penetration test would have flagged. It used valid credentials and scheduled tasks, and behaved like an administrator.

A burglar kicked in the front door and set off every alarm in the building. That is how the family discovered the surveyor who had been living in the loft since the previous summer, taking notes, and who had never once touched the silverware.

We called them about ransomware. On day four they sat us down and said the ransomware was the least of our problems. I have never had a worse meeting or a more useful one.

Chief Information Officer, UK telecommunications operator

We would talk you through this properly

Including what we got wrong and would do differently. The people who delivered it are the people you would meet.

Start a conversation