IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling At-Bay InsurSec Watch

At-Bay InsurSec Claims & Cyber Risk Rolling Intelligence Card

A source-cited rolling one-year synthesis of At-Bay claims research, InsurSec reporting, cyber case studies, threat research, underwriting signals, and practical security guidance. The chronology now spans August 2025 through July 2026 and connects initial access and control failure to claim frequency, severity, interruption, fraud recovery, litigation, extortion, and post-incident resilience without presenting At-Bay's insured population as a universal incident census.

Coverage
Jul 29, 2025–Jul 28, 2026
Record Version
v2
Updated
Jul 28, 2026
AI Monitor
Weekly · Fri midday ET
Evidence
16 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 1-Year Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Jul 29, 2025Jul 28, 2026

365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

365-day windowWeekly on Friday at midday ET

6,500+[5]

Claims Evidence Base

Claims analyzed in At-Bay's 2026 InsurSec reporting; not a national incident count.Evidence dated Apr 22, 2026

100K+[4][11]

Policy-Year Evidence

At-Bay cyber policy years underlying the report.Evidence dated Apr 22, 2026

73%[5]

VPN Share of Ransomware

Share of At-Bay 2025 ransomware claims beginning with VPN access.Evidence dated Apr 22, 2026

87%[5]

Remote-Access Share

VPN and RDP combined share of At-Bay ransomware claims.Evidence dated Apr 22, 2026

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

At-Bay's evidence places remotely accessible infrastructure, valid credentials, trusted software acquisition, and weak third-party security operations ahead of exotic malware as the access conditions most likely to translate into insured loss.

1

Publisher-observed access path

VPN exploitation[4][5][11]Evidence dated Apr 22, 2026

Retained At-Bay evidence; local exposure and prevalence require validation

How it starts
Attackers identify and exploit exposed remote-access appliances or use credentials associated with them.
Attacker outcome
Privileged network entry followed by ransomware, data theft, or recovery-system targeting.
What to monitor
Exact appliance inventory, exposure, versions, configuration drift, admin changes, anomalous VPN sessions, and post-patch credential use.
2

Publisher-observed access path

Exposed or weakly governed RDP[5]Evidence dated Apr 22, 2026

Retained At-Bay evidence; local exposure and prevalence require validation

How it starts
Remote desktop is reachable or protected by reusable credentials and insufficient authentication controls.
Attacker outcome
Interactive access, lateral movement, staging, and ransomware deployment.
What to monitor
Internet reachability, failed-to-successful logins, unusual source infrastructure, new sessions, privilege changes, and remote tooling.
3

Publisher-observed access path

Stolen credentials and legacy authentication[7]Evidence dated Jul 14, 2026

Retained At-Bay evidence; local exposure and prevalence require validation

How it starts
An attacker acquires valid credentials and selects an older or unusual authentication path.
Attacker outcome
Account takeover that can bypass user suspicion and conventional malware detection.
What to monitor
Impossible geography, low-cost cloud sources, never-before-used protocols, session changes, and access outside normal behavior.
4

Publisher-observed access path

SEO-poisoned software[10]Evidence dated May 13, 2026

Retained At-Bay evidence; local exposure and prevalence require validation

How it starts
A user or service provider downloads a trojanized tool from a manipulated search result.
Attacker outcome
Execution through a trusted administrative workflow followed by ransomware and backup destruction.
What to monitor
Approved software catalogs, signatures and hashes, download origin, first-run child processes, MFA anomalies, and rapid lateral spread.
5

Publisher-observed access path

MSP and recovery trust gaps[6][8][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026

Retained At-Bay evidence; local exposure and prevalence require validation

How it starts
Operational providers restore or administer systems without sufficient threat detection, forensic scope, or validation.
Attacker outcome
Long dwell, persistent access, reinfection, incomplete closure, or downstream impact.
What to monitor
Shared accounts, provider tooling, log retention, backup cleanliness, post-incident persistence checks, and security-monitoring ownership.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentExecutives, CISOs, CIOs, incident-response leaders, threat-intelligence teams, SOC leaders, risk owners, and business-continuity leaders who need a decision-ready view of one publisher's strongest public research.
Audience fieldDecision useAssessmentUse the card to identify recurring access paths, actor and campaign changes, affected technologies, likely business impact, and control priorities that deserve validation inside the reader's own environment.
Audience fieldSource postureAssessmentAt-Bay is the controlling source for publisher-specific observations. External facts repeated in a publication retain the original attribution and are not upgraded into independently verified IntelliOS findings.
Audience fieldUpdate modelAssessmentA dedicated publisher agent checks the complete monitored corpus weekly on friday at midday et, keeps a cumulative rolling one-year window, and sends Page Alerts only for material source-backed changes.

Chronology and Decision Milestones

Timeline of Notable Activity

Entries are ordered from oldest to newest across the full rolling year. Portfolio findings use the end of At-Bay's named claims or observation period; case studies, threat research, and advisories use the stated incident or publication date as labeled. Citations preserve the later public date.

  1. SonicWall response activity

    Multiple response cases with similar SonicWall SSL VPN indicators triggered a disable-or-restrict decision

    At-Bay advised organizations to disable the affected SSL VPN function or restrict access to known IP addresses while investigations continued. The response standard is exact appliance inventory, exposure reduction, credential review and retrospective hunting—not waiting for perfect attribution.[13]

  2. Backup risk assessment

    A six-year-old backup design created recovery risk even before a ransomware event

    At-Bay's university assessment found aging infrastructure and no dedicated ransomware protections in the backup environment. The useful lesson is to treat immutability, isolation, credentials, retention and recovery testing as one designed control, not a storage purchase.[14]

  3. Rhysida intrusion chain

    A trojanized PuTTY installer turned a trusted admin workflow into six stages of access, theft and evasion

    At-Bay traces SEO poisoning to remote access, RDP movement, network scanning, AzCopy exfiltration of more than 100,000 files and log clearing. A failed cleanup script preserved evidence; ordinary administration tools must be correlated as a sequence.[15]

  4. 2025 observation · ransomware initial access

    Remote access has become the dominant loss path in At-Bay's ransomware claims

    At-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.[4][5][11]

  5. 2025 observation · SMB loss severity

    Small businesses are absorbing a higher financial floor for cyber incidents

    For companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.[5][11]

  6. 2025 observation · ransomware concentration

    Akira industrialized one appliance-focused campaign into portfolio-level loss

    At-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.[5][11]

  7. 2025 observation · detection and response

    EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome

    At-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.[5]

  8. 2025 observation · secondary loss

    Interruption and liability can dominate the cost after initial compromise

    At-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.[4][5][11]

  9. 2025 observation · financial fraud recovery

    The first three days materially change stolen-funds recovery odds

    At-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.[5][11]

  10. Q4 observation · extortion shift

    Non-encryption extortion rose 450% from Q3 to Q4 in At-Bay's response data

    At-Bay's Pure Extraction research describes operators prioritizing fast data theft and pressure over encryption. Recovery readiness remains necessary, but identity, exfiltration detection, legal preparation and executive communications now determine outcome even when systems stay online.[16]

  11. PEAR operating model

    PEAR paired long dwell with a 24-hour exfiltration burst and direct executive pressure

    In At-Bay's casework, the actor spent months inside, then used WinSCP to remove roughly 732 GB within 24 hours before extortion. Detection alerts without full containment allowed the operation to continue; executive contact can be the first visible sign of a long-running compromise.[16]

  12. Low-cost control uplift

    Existing Google Workspace controls can raise the baseline before new tooling is purchased

    At-Bay highlights malware scanning, security checkup, DLP, behavioral phishing detection, and heuristic analysis already available in common productivity workflows. Organizations should verify configuration, licensing, logging, alert ownership, and response rather than assuming default availability equals effective protection.[12]

  13. Long dwell and extortion

    Seven months of quiet access erased the evidence needed to identify initial entry

    At-Bay's PEAR case found a seven-month intrusion only after executives received extortion threats. Log rolling prevented recovery of the exact initial-access method. Security telemetry retention must reflect realistic dwell and litigation periods rather than short operational defaults.[8]

  14. Incomplete remediation

    Restoring operations left one organization compromised for roughly two years

    At-Bay found that an earlier incident had never been fully investigated or remediated; persistence and encrypted domain resources survived the operational recovery. Incident closure requires forensic scope, access revocation, persistence removal, clean identity recovery, and post-restoration monitoring.[9]

  15. SEO-poisoned software

    A trusted IT workflow delivered Akira and destroyed backups across 60 servers

    An MSP installed a trojanized AI tool from a poisoned search result, leading to an Akira incident, destroyed backups, and a $10M demand. At-Bay reports isolation in about two hours and a $1.5M settlement; those are case-specific outcomes, while software provenance and backup separation are the repeatable lessons.[10]

  16. Recovery integrity

    A clean restore is not guaranteed when the backup repository still contains malware

    In an At-Bay case, a routine restore began reintroducing a malicious macro document from the original breach. Behavioral detection stopped execution and the response removed the file from both the restored system and source repository. Recovery testing must include malware validation and backup sanitization, not only successful restoration.[6]

  17. Identity detection

    One anomalous legacy-authentication event can reveal stolen-credential access

    At-Bay describes a U.S. finance user authenticating from a low-cost cloud server in Ukraine through legacy systems the user had never used. Geographic, behavioral, and authentication-path anomalies enabled session revocation before exfiltration.[7]

Bottom Line Up Front

BLUF

Coverage periodJul 29, 2025Jul 28, 2026365 calendar days, inclusiveUpdated Jul 28, 2026
  • Remote access has become the dominant loss path in At-Bay's ransomware claims: At-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.[4][5][11]Evidence dated Apr 22, 2026

  • Small businesses are absorbing a higher financial floor for cyber incidents: For companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.[5][11]Evidence dated Apr 22, 2026

  • Akira industrialized one appliance-focused campaign into portfolio-level loss: At-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.[5][11]Evidence dated Apr 22, 2026

  • EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome: At-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.[5]Evidence dated Apr 22, 2026

  • Interruption and liability can dominate the cost after initial compromise: At-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.[4][5][11]Evidence dated Apr 22, 2026

  • The first three days materially change stolen-funds recovery odds: At-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.[5][11]Evidence dated Apr 22, 2026

Decision Context

Executive Summary

Coverage periodJul 29, 2025Jul 28, 2026365 calendar days, inclusiveUpdated Jul 28, 2026

At-Bay's most important contribution is connecting technical exposure to financial outcome. Its 2026 InsurSec reporting draws on more than 100,000 policy years and over 6,500 claims, giving executives a portfolio view of which access paths, controls, and response conditions correlated with frequency and severity inside At-Bay's book. Those results are decision evidence, not a national incident census.[4][5][11]Evidence dated Apr 22, 2026

Remote access dominates the ransomware story. VPNs initiated 73% of reported ransomware claims and VPN plus RDP initiated 87%. Akira's concentration around SonicWall shows why generic control questions are too weak: leadership needs an owned inventory of exact appliances, versions, configurations, exposure history, identities, logs, and compensating monitoring.[4][5][11]Evidence dated Apr 22, 2026

The case studies show that technical recovery and security closure are different outcomes. Malware can remain in backups, attacker persistence can survive restoration, identity access can remain active, and old evidence can disappear before extortion is discovered. A restore test that measures only whether systems boot is not proof that the environment is clean or the incident is closed.[6][8][9]First cited source May 13, 2026 · Latest cited source Jul 14, 2026

At-Bay's loss data makes time an executive control. Rapid fraud notification materially improved recovery rates, monitored detection changed ransomware outcomes in its Akira data, and business interruption multiplied severity. Escalation thresholds, insurer and bank contacts, containment authority, evidence retention, and recovery priorities must exist before the event.[5][7][10][11]First cited source Apr 22, 2026 · Latest cited source Jul 14, 2026

The practical operating standard is continuous and specific: secure every remote-access path, retire legacy authentication, monitor identity and endpoint behavior, verify software provenance, sanitize backups, retain useful logs, scope MSP trust, and require forensic closure after restoration. Brokers and underwriters can then evaluate evidence of operation rather than control names alone.[5][6][7][8][9][10][12]First cited source Mar 9, 2026 · Latest cited source Jul 14, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    Remote access has become the dominant loss path in At-Bay's ransomware claimsAt-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.[4][5][11]Evidence dated Apr 22, 2026

  2. 2

    Small businesses are absorbing a higher financial floor for cyber incidentsFor companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.[5][11]Evidence dated Apr 22, 2026

  3. 3

    Akira industrialized one appliance-focused campaign into portfolio-level lossAt-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.[5][11]Evidence dated Apr 22, 2026

  4. 4

    EDR presence did not prevent many Akira losses; continuously monitored response changed the outcomeAt-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.[5]Evidence dated Apr 22, 2026

  5. 5

    Interruption and liability can dominate the cost after initial compromiseAt-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.[4][5][11]Evidence dated Apr 22, 2026

  6. 6

    The first three days materially change stolen-funds recovery oddsAt-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.[5][11]Evidence dated Apr 22, 2026

  7. 7

    A clean restore is not guaranteed when the backup repository still contains malwareIn an At-Bay case, a routine restore began reintroducing a malicious macro document from the original breach. Behavioral detection stopped execution and the response removed the file from both the restored system and source repository. Recovery testing must include malware validation and backup sanitization, not only successful restoration.[6]Evidence dated Jul 14, 2026

  8. 8

    One anomalous legacy-authentication event can reveal stolen-credential accessAt-Bay describes a U.S. finance user authenticating from a low-cost cloud server in Ukraine through legacy systems the user had never used. Geographic, behavioral, and authentication-path anomalies enabled session revocation before exfiltration.[7]Evidence dated Jul 14, 2026

  9. 9

    Seven months of quiet access erased the evidence needed to identify initial entryAt-Bay's PEAR case found a seven-month intrusion only after executives received extortion threats. Log rolling prevented recovery of the exact initial-access method. Security telemetry retention must reflect realistic dwell and litigation periods rather than short operational defaults.[8]Evidence dated May 13, 2026

  10. 10

    Restoring operations left one organization compromised for roughly two yearsAt-Bay found that an earlier incident had never been fully investigated or remediated; persistence and encrypted domain resources survived the operational recovery. Incident closure requires forensic scope, access revocation, persistence removal, clean identity recovery, and post-restoration monitoring.[9]Evidence dated May 13, 2026

  11. 11

    A trusted IT workflow delivered Akira and destroyed backups across 60 serversAn MSP installed a trojanized AI tool from a poisoned search result, leading to an Akira incident, destroyed backups, and a $10M demand. At-Bay reports isolation in about two hours and a $1.5M settlement; those are case-specific outcomes, while software provenance and backup separation are the repeatable lessons.[10]Evidence dated May 13, 2026

  12. 12

    Existing Google Workspace controls can raise the baseline before new tooling is purchasedAt-Bay highlights malware scanning, security checkup, DLP, behavioral phishing detection, and heuristic analysis already available in common productivity workflows. Organizations should verify configuration, licensing, logging, alert ownership, and response rather than assuming default availability equals effective protection.[12]Evidence dated Mar 9, 2026

  13. 13

    Multiple response cases with similar SonicWall SSL VPN indicators triggered a disable-or-restrict decisionAt-Bay advised organizations to disable the affected SSL VPN function or restrict access to known IP addresses while investigations continued. The response standard is exact appliance inventory, exposure reduction, credential review and retrospective hunting—not waiting for perfect attribution.[13]Evidence dated Aug 5, 2025

  14. 14

    A six-year-old backup design created recovery risk even before a ransomware eventAt-Bay's university assessment found aging infrastructure and no dedicated ransomware protections in the backup environment. The useful lesson is to treat immutability, isolation, credentials, retention and recovery testing as one designed control, not a storage purchase.[14]Evidence dated Aug 12, 2025

  15. 15

    A trojanized PuTTY installer turned a trusted admin workflow into six stages of access, theft and evasionAt-Bay traces SEO poisoning to remote access, RDP movement, network scanning, AzCopy exfiltration of more than 100,000 files and log clearing. A failed cleanup script preserved evidence; ordinary administration tools must be correlated as a sequence.[15]Evidence dated Sep 2, 2025

  16. 16

    Non-encryption extortion rose 450% from Q3 to Q4 in At-Bay's response dataAt-Bay's Pure Extraction research describes operators prioritizing fast data theft and pressure over encryption. Recovery readiness remains necessary, but identity, exfiltration detection, legal preparation and executive communications now determine outcome even when systems stay online.[16]Evidence dated Feb 11, 2026

  17. 17

    PEAR paired long dwell with a 24-hour exfiltration burst and direct executive pressureIn At-Bay's casework, the actor spent months inside, then used WinSCP to remove roughly 732 GB within 24 hours before extortion. Detection alerts without full containment allowed the operation to continue; executive contact can be the first visible sign of a long-running compromise.[16]Evidence dated Feb 11, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationBusinesses with exposed VPN or RDP services[4][5][11]Evidence dated Apr 22, 2026SectorsCross-industryGeographyAt-Bay's U.S.-focused insured populationConfirmation statusPortfolio claims analysis; not an internet-wide exposure censusHow companies should use itInventory exact products, restrict exposure, require phishing-resistant access, review historical authentication, and test rapid isolation.
Victim / exposure populationBusinesses under $25M in revenue[5][11]Evidence dated Apr 22, 2026SectorsSMB and lower-middle-marketGeographyAt-Bay portfolioConfirmation statusAt-Bay segment-level frequency and severity analysisHow companies should use itPlan for a higher minimum loss, validate cash-flow and downtime tolerance, and prove recovery rather than relying on organization size as protection.
Victim / exposure populationOrganizations dependent on MSPs[6][8][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026SectorsFinance, media, real estate, and cross-industryGeographyCase-specific U.S. examplesConfirmation statusSeveral individual At-Bay case studiesHow companies should use itSeparate IT operations from security monitoring; govern software sourcing, identity visibility, logging, backup hygiene, and incident closure.
Victim / exposure populationFinance teams and payment workflows[5][11]Evidence dated Apr 22, 2026SectorsCross-industryGeographyAt-Bay claims populationConfirmation statusPortfolio fraud and recovery observationsHow companies should use itImplement dual approval, out-of-band verification, same-day escalation, bank recall, insurer notice, and evidence preservation.
Victim / exposure populationOrganizations restoring from backup after an incident[6][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026SectorsCross-industryGeographyCase-specificConfirmation statusAt-Bay response casesHow companies should use itScan repositories and restored content, rebuild identity safely, remove persistence, validate known-clean state, and monitor after cutover.

Distinct Operational Records

At-Bay Research Themes & Operations

Akira and SonicWall-focused ransomware activity

At-Bay links portfolio-level Akira concentration to systematic exploitation of a specific remote-access technology and documents one SEO-poisoning case with destructive backup impact.[5][10][11]First cited source Apr 22, 2026 · Latest cited source May 13, 2026

PEAR long-dwell extortion

A quiet seven-month intrusion progressed to data theft and direct executive pressure after old evidence had rolled off.[8]Evidence dated May 13, 2026

Stolen-credential account takeover

Behavioral differences in location, cloud hosting, and legacy-authentication use enabled containment before exfiltration.[7]Evidence dated Jul 14, 2026

Backup-mediated malware reinfection

Unclean backup content attempted to reintroduce malware during ordinary restoration.[6]Evidence dated Jul 14, 2026

Persistent access after incomplete remediation

Operational recovery without forensic closure allowed compromise evidence and access to survive for roughly two years.[9]Evidence dated May 13, 2026

Source-Bound Actor Context

Threat Actors, Operators & Decision Owners

Akira

At-Bay's leading ransomware strain in the report population, tied to appliance-focused activity and a separate case involving SEO-poisoned software, 60 encrypted servers, and destroyed backups.[5][10][11]First cited source Apr 22, 2026 · Latest cited source May 13, 2026

PEAR

Named in At-Bay's seven-month finance-sector intrusion and data-extortion case; the original access method remained unknown because logs had rolled off.[8]Evidence dated May 13, 2026

Credential-access operators

Use stolen credentials, cloud infrastructure, unusual geography, and legacy authentication paths to establish access that can resemble legitimate user activity.[7]Evidence dated Jul 14, 2026

SEO-poisoning distributors

Trojanize or impersonate wanted software so administrators and service providers execute the initial payload through a trusted workflow.[10]Evidence dated May 13, 2026

Financial-fraud operators

Exploit payment authority and delay; At-Bay's recovery statistics show why detection and notification speed materially affect loss.[5][11]Evidence dated Apr 22, 2026

Enterprise Exposure

Affected Technologies & Trust Boundaries

SonicWall and other VPN appliances

At-Bay's claims data elevates exact appliance exposure, configuration, credential, and historical-access review above generic 'VPN present' questionnaires.[4][5][11]Evidence dated Apr 22, 2026

RDP and remote administration

RDP completes the 87% remote-access share and should be removed from direct exposure or strongly brokered, monitored, and identity-protected.[5]Evidence dated Apr 22, 2026

EDR and MDR operations

Product presence alone did not prevent many reported Akira compromises; monitored detection, authority, and containment are the meaningful capability.[5][6][7]First cited source Apr 22, 2026 · Latest cited source Jul 14, 2026

Backup repositories and Active Directory

Backups can carry malware and restored environments can retain persistence or damaged identity resources.[6][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026

Google Workspace

Built-in malware, phishing, DLP, heuristic, and security-review features can strengthen the baseline when configured, logged, and owned.[12]Evidence dated Mar 9, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

2025 observation · ransomware initial access

Remote access has become the dominant loss path in At-Bay's ransomware claims[4][5][11]Evidence dated Apr 22, 2026

Why it mattersAt-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
2Threat / Category

2025 observation · SMB loss severity

Small businesses are absorbing a higher financial floor for cyber incidents[5][11]Evidence dated Apr 22, 2026

Why it mattersFor companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
3Threat / Category

2025 observation · ransomware concentration

Akira industrialized one appliance-focused campaign into portfolio-level loss[5][11]Evidence dated Apr 22, 2026

Why it mattersAt-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
4Threat / Category

2025 observation · detection and response

EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome[5]Evidence dated Apr 22, 2026

Why it mattersAt-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
5Threat / Category

2025 observation · secondary loss

Interruption and liability can dominate the cost after initial compromise[4][5][11]Evidence dated Apr 22, 2026

Why it mattersAt-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
6Threat / Category

2025 observation · financial fraud recovery

The first three days materially change stolen-funds recovery odds[5][11]Evidence dated Apr 22, 2026

Why it mattersAt-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
7Threat / Category

Recovery integrity

A clean restore is not guaranteed when the backup repository still contains malware[6]Evidence dated Jul 14, 2026

Why it mattersIn an At-Bay case, a routine restore began reintroducing a malicious macro document from the original breach. Behavioral detection stopped execution and the response removed the file from both the restored system and source repository. Recovery testing must include malware validation and backup sanitization, not only successful restoration.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
8Threat / Category

Identity detection

One anomalous legacy-authentication event can reveal stolen-credential access[7]Evidence dated Jul 14, 2026

Why it mattersAt-Bay describes a U.S. finance user authenticating from a low-cost cloud server in Ukraine through legacy systems the user had never used. Geographic, behavioral, and authentication-path anomalies enabled session revocation before exfiltration.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
9Threat / Category

Long dwell and extortion

Seven months of quiet access erased the evidence needed to identify initial entry[8]Evidence dated May 13, 2026

Why it mattersAt-Bay's PEAR case found a seven-month intrusion only after executives received extortion threats. Log rolling prevented recovery of the exact initial-access method. Security telemetry retention must reflect realistic dwell and litigation periods rather than short operational defaults.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
10Threat / Category

Incomplete remediation

Restoring operations left one organization compromised for roughly two years[9]Evidence dated May 13, 2026

Why it mattersAt-Bay found that an earlier incident had never been fully investigated or remediated; persistence and encrypted domain resources survived the operational recovery. Incident closure requires forensic scope, access revocation, persistence removal, clean identity recovery, and post-restoration monitoring.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
11Threat / Category

SEO-poisoned software

A trusted IT workflow delivered Akira and destroyed backups across 60 servers[10]Evidence dated May 13, 2026

Why it mattersAn MSP installed a trojanized AI tool from a poisoned search result, leading to an Akira incident, destroyed backups, and a $10M demand. At-Bay reports isolation in about two hours and a $1.5M settlement; those are case-specific outcomes, while software provenance and backup separation are the repeatable lessons.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
12Threat / Category

Low-cost control uplift

Existing Google Workspace controls can raise the baseline before new tooling is purchased[12]Evidence dated Mar 9, 2026

Why it mattersAt-Bay highlights malware scanning, security checkup, DLP, behavioral phishing detection, and heuristic analysis already available in common productivity workflows. Organizations should verify configuration, licensing, logging, alert ownership, and response rather than assuming default availability equals effective protection.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
13Threat / Category

SonicWall response activity

Multiple response cases with similar SonicWall SSL VPN indicators triggered a disable-or-restrict decision[13]Evidence dated Aug 5, 2025

Why it mattersAt-Bay advised organizations to disable the affected SSL VPN function or restrict access to known IP addresses while investigations continued. The response standard is exact appliance inventory, exposure reduction, credential review and retrospective hunting—not waiting for perfect attribution.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
14Threat / Category

Backup risk assessment

A six-year-old backup design created recovery risk even before a ransomware event[14]Evidence dated Aug 12, 2025

Why it mattersAt-Bay's university assessment found aging infrastructure and no dedicated ransomware protections in the backup environment. The useful lesson is to treat immutability, isolation, credentials, retention and recovery testing as one designed control, not a storage purchase.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
15Threat / Category

Rhysida intrusion chain

A trojanized PuTTY installer turned a trusted admin workflow into six stages of access, theft and evasion[15]Evidence dated Sep 2, 2025

Why it mattersAt-Bay traces SEO poisoning to remote access, RDP movement, network scanning, AzCopy exfiltration of more than 100,000 files and log clearing. A failed cleanup script preserved evidence; ordinary administration tools must be correlated as a sequence.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
16Threat / Category

Q4 observation · extortion shift

Non-encryption extortion rose 450% from Q3 to Q4 in At-Bay's response data[16]Evidence dated Feb 11, 2026

Why it mattersAt-Bay's Pure Extraction research describes operators prioritizing fast data theft and pressure over encryption. Recovery readiness remains necessary, but identity, exfiltration detection, legal preparation and executive communications now determine outcome even when systems stay online.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
17Threat / Category

PEAR operating model

PEAR paired long dwell with a 24-hour exfiltration burst and direct executive pressure[16]Evidence dated Feb 11, 2026

Why it mattersIn At-Bay's casework, the actor spent months inside, then used WinSCP to remove roughly 732 GB within 24 hours before extortion. Detection alerts without full containment allowed the operation to continue; executive contact can be the first visible sign of a long-running compromise.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodJul 29, 2025Jul 28, 2026365 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Underwrite exact technologies and operations[4][5][11]Evidence dated Apr 22, 2026

    Lesson Learned

    A generic control label can hide the device, version, configuration, exposure, identity, and monitoring conditions that drive loss.

    Minimum Operating Standard

    Maintain evidence for every remote-access technology, supported version, management path, authentication policy, owner, exposure history, and compensating control.

  2. 2

    Best Practice

    Separate restoration from remediation[6][9]First cited source May 13, 2026 · Latest cited source Jul 14, 2026

    Lesson Learned

    Systems can return to service while malware, persistence, damaged identity, or attacker access remains.

    Minimum Operating Standard

    Require forensic scope, known-clean rebuild criteria, backup sanitization, credential and session revocation, persistence validation, and post-restore monitoring before closure.

  3. 3

    Best Practice

    Measure monitored response capability[5][6][7]First cited source Apr 22, 2026 · Latest cited source Jul 14, 2026

    Lesson Learned

    EDR installation does not prove that someone can interpret and contain activity continuously.

    Minimum Operating Standard

    Test alert ownership, 24/7 response, isolation authority, escalation time, coverage gaps, and evidence preservation through exercises and real telemetry.

  4. 4

    Best Practice

    Retain evidence for realistic dwell[8]Evidence dated May 13, 2026

    Lesson Learned

    Short log retention erased the initial-access story in a seven-month intrusion.

    Minimum Operating Standard

    Set identity, endpoint, network, cloud, email, and administrative log retention from threat dwell, legal, insurance, and investigation requirements.

  5. 5

    Best Practice

    Make financial-fraud response same-day[5][11]Evidence dated Apr 22, 2026

    Lesson Learned

    Recovery probability declined sharply when notification was delayed.

    Minimum Operating Standard

    Pre-authorize bank recall, insurer notice, counsel, law enforcement, transaction preservation, and executive escalation immediately after suspected fraud.

  6. 6

    Best Practice

    Govern trusted software acquisition[10]Evidence dated May 13, 2026

    Lesson Learned

    A familiar search result and useful tool name can become an initial-access mechanism.

    Minimum Operating Standard

    Use approved catalogs, vendor-direct sources, signature and hash validation, restricted installation rights, sandboxing, and first-run monitoring.

Automation Transparency

AI Agent Run Status

AgentAt-Bay Rolling Intelligence Card Publisher
StatusActive · rolling one-year automation
CadenceWeekly on Friday at midday ET
Previous run26 Jul 2026 · material revision · Run at-bay-publisher-activity-2026-07-26-initial
Previous resultKept the full-year product and backfilled At-Bay's chronology to August 2025 with SonicWall response evidence, backup-risk assessment, Rhysida casework, and PEAR data-theft-only extortion findings; moved 2025 portfolio findings to their observation-period endpoint.
What the previous run found
  • Enumerated the monitored At-Bay collection pages and retained individual publications that control displayed conclusions.
  • Created 17 source-cited briefing points plus a publication chronology, victimology, actor, campaign, technology, access, and response sections.
  • Kept first-party observations, third-party claims, survey data, and product statements in their proper evidence classes.
  • Enabled subscriber alerts for material revisions and suppressed routine no-change email.
Next runWeekly on Friday at midday ET
Sources monitored
  • At-Bay Underwriting Archive — https://www.at-bay.com/teams/underwriting/
  • At-Bay Newsroom — https://www.at-bay.com/about/newsroom/
  • At-Bay Cybersecurity Knowledge Center — All Content Types — https://www.at-bay.com/learn/cyber-security/
  • PETRA report database query constrained to the active rolling one-year publication window; duplicate matches are reconciled to the direct publisher source
Publication and alert policyCheck weekly on friday at midday et. Publish and alert only when a new At-Bay publication materially changes an actor, campaign, technology, initial-access, victimology, impact, response, resilience, or executive conclusion. No-change checks are logged but do not email subscribers.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv1Date26 Jul 2026ChangeCreated the At-Bay rolling one-year publisher card with Research Framing, Timeline, BLUF, Executive Summary, top-ten findings, victimology, campaigns, actors, technologies, access vectors, operational practices, AI agent status, and citations.MonitoringWeekly on Friday at midday ET; material-change-only Page Alerts.
Versionv2Date26 Jul 2026ChangeKept the full-year product and backfilled At-Bay's chronology to August 2025 with SonicWall response evidence, backup-risk assessment, Rhysida casework, and PEAR data-theft-only extortion findings; moved 2025 portfolio findings to their observation-period endpoint.MonitoringWeekly on Friday at midday ET; material-change-only Page Alerts.

Citations

Retained Sources and Claim Treatment

Source1PublisherAt-BayPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentRequested first-party underwriting lane monitored weekly. The archive returned no posts at initial publication, so it controls no current finding until At-Bay publishes qualifying material.SourceAt-Bay Underwriting Archive

https://www.at-bay.com/teams/underwriting/

Source2PublisherAt-BayPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party company-news index. News releases can identify new research or services, but promotional statements do not independently establish loss prevalence or control effectiveness.SourceAt-Bay Newsroom

https://www.at-bay.com/about/newsroom/

Source3PublisherAt-BayPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party corpus index monitored across All, Article, Case Study, Document, eBook, Report, Threat Research, Webinar, Worksheet, and Video. Individual retained publications control findings.SourceAt-Bay Cybersecurity Knowledge Center — All Content Types

https://www.at-bay.com/learn/cyber-security/

Source4PublisherAt-BayPublished2026-04-22Publication / evidenceSource indexincident responseWhy used / claim treatmentAt-Bay analysis based on more than 100,000 policy years and over 6,500 claims. Results describe At-Bay's insured and claims population, not all U.S. businesses or incidents.SourceThe 2026 InsurSec Report

https://www.at-bay.com/2026-insursec-report/

Source5PublisherAt-BayPublished2026-04-22Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party release summarizing the 2026 InsurSec Report. Percentages, severities, demands, payments, and recoveries remain bounded to At-Bay's described claims population.Source1 in 3 Ransomware Claims Started with SonicWall in 2025

https://www.at-bay.com/press_releases/2026-insursec-report-ransomware-vpn-sonicwall-attacks/

Source6PublisherAt-BayPublished2026-07-14Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party case study of one response outcome. The case demonstrates a control failure mode but does not establish prevalence or guarantee comparable MDR outcomes.SourceMalware in the Backups: How a Restoration Almost Brought the Attacker Back

https://www.at-bay.com/case-studies/malware-in-backups-mdr/

Source7PublisherAt-BayPublished2026-07-14Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party case study of a single account-takeover detection and containment. Outcome and response timing are case-specific.SourceOne Unusual Login: How Behavioral Analysis Stopped an Account Takeover

https://www.at-bay.com/case-studies/stop-account-takeover-mdr/

Source8PublisherAt-BayPublished2026-05-13Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party response case involving PEAR, long dwell, exfiltration, and extortion. The exact initial access could not be recovered because historical logs had rolled off.Source7 Months Inside: How Threat Actors Reached the C-Suite

https://www.at-bay.com/case-studies/long-dwell-attack-case-study/

Source9PublisherAt-BayPublished2026-05-13Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party case study of incomplete remediation and persistent access. It demonstrates why operational restoration is not proof of incident closure.SourceThe Breach That Never Closed: A 2-Year-Old Compromise That Survived Backup Restoration

https://www.at-bay.com/case-studies/incomplete-ransomware-remediation-case-study/

Source10PublisherAt-BayPublished2026-05-13Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party case study of one Akira incident, containment, and negotiation. The demand, settlement, server count, and timeline are case-specific and not expected outcomes.SourceInside an Akira Ransomware Attack: 60 Servers, Destroyed Backups, and an 85% Negotiated Reduction

https://www.at-bay.com/case-studies/akira-ransomware-attack-case-study/

Source11PublisherAt-BayPublished2026-04-22Publication / evidenceSource indexincident responseWhy used / claim treatmentAt-Bay interpretation of its claims report, including frequency, severity, ransomware, fraud, interruption, and liability findings. Metrics remain bounded to the report methodology.Source5 Key Findings From the 2026 InsurSec Report

https://www.at-bay.com/articles/insursec-report-2026-key-findings-cyber-risk/

Source12PublisherAt-BayPublished2026-03-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentDefensive guidance about built-in Google Workspace capabilities. Product descriptions and third-party statistics retain their original attribution and require configuration-specific validation.SourceThe Cybersecurity Tools Hidden in Google Workspace

https://www.at-bay.com/articles/google-workspace-cybersecurity-free-tools/

Source13PublisherAt-BayPublished2025-08-05Publication / evidenceSource indexincident responseWhy used / claim treatmentAt-Bay defensive advisory informed by multiple response investigations with similar indicators. Similarity does not prove one common actor or compromise in every exposed appliance.SourceSonicWall SSL VPN Zero-Day: What Businesses Need to Know

https://www.at-bay.com/articles/sonicwall-ssl-vpn-zero-day/

Source14PublisherAt-BayPublished2025-08-12Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party account of one security assessment and remediation program. It demonstrates an exposure pattern but not the prevalence or guaranteed effectiveness of the recommendations.SourceUniversity Reduces Ransomware Risk With Backup Overhaul

https://www.at-bay.com/case-studies/university-reduces-ransomware-risk-with-backup-overhaul/

Source15PublisherAt-BayPublished2025-09-02Publication / evidenceSource indexincident responseWhy used / claim treatmentTechnical analysis of a documented Rhysida intrusion. The observed chain is case-specific and does not establish universal Rhysida behavior.SourceRhysida: Evading Detection Through a Trojanized PuTTY Installer

https://www.at-bay.com/threat-research/rhysida-evading-detection/

Source16PublisherAt-BayPublished2026-02-11Publication / evidenceSource indexincident responseWhy used / claim treatmentAt-Bay response-data analysis and PEAR casework. The reported growth and demand figures remain bounded to At-Bay's stated incident population and public leak-site observations.SourcePure Extraction: Ransomware Groups Prioritize Data Theft

https://www.at-bay.com/threat-research/pure-extraction-ransomware-groups-prioritize-data-theft/