- How it starts
- Attackers identify and exploit exposed remote-access appliances or use credentials associated with them.
- Attacker outcome
- Privileged network entry followed by ransomware, data theft, or recovery-system targeting.
- What to monitor
- Exact appliance inventory, exposure, versions, configuration drift, admin changes, anomalous VPN sessions, and post-patch credential use.
At-Bay InsurSec Claims & Cyber Risk Rolling Intelligence Card
A source-cited rolling one-year synthesis of At-Bay claims research, InsurSec reporting, cyber case studies, threat research, underwriting signals, and practical security guidance. The chronology now spans August 2025 through July 2026 and connects initial access and control failure to claim frequency, severity, interruption, fraud recovery, litigation, extortion, and post-incident resilience without presenting At-Bay's insured population as a universal incident census.
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | What At-Bay's public underwriting, claims, security, response, and InsurSec publications reveal about the controls and operating conditions that materially change cyber loss frequency, severity, recovery, and insurability. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | Which technologies and access paths drive At-Bay claims? Which controls change outcomes rather than merely checking a box? Why do restoration and remediation diverge? How quickly must fraud and ransomware decisions be made? Which findings are portfolio statistics, individual case outcomes, product statements, or broadly applicable defensive lessons? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | At-Bay's current corpus connects remote access to measurable loss. Its 2026 InsurSec reporting says VPNs initiated 73% of ransomware claims and VPN plus RDP initiated 87%; Akira represented more than 40% of ransomware claims, with SonicWall present in 86% of Akira attacks. Small businesses under $25M in revenue experienced a 21% ransomware-frequency increase and 40% severity increase. Current case studies add the failure modes behind those numbers: poisoned search results, stolen credentials, weak identity telemetry, unsanitized backups, incomplete remediation, short log retention, and MSP operations without continuous security monitoring.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16]First cited source Aug 5, 2025 · Latest cited source Jul 14, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
Complete Tier 0–8 counts are shown here. The 16 retained sources and their claim treatment are identified in Citations. Planned integrations are not counted as checked or selected. |
Reporting-Period Statistics
Rolling 1-Year Intelligence Snapshot
At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.
Period Coverage
Jul 29, 2025–Jul 28, 2026
365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.
6,500+[5]
Claims Evidence Base
Claims analyzed in At-Bay's 2026 InsurSec reporting; not a national incident count.Evidence dated Apr 22, 2026
Policy-Year Evidence
At-Bay cyber policy years underlying the report.Evidence dated Apr 22, 2026
73%[5]
VPN Share of Ransomware
Share of At-Bay 2025 ransomware claims beginning with VPN access.Evidence dated Apr 22, 2026
87%[5]
Remote-Access Share
VPN and RDP combined share of At-Bay ransomware claims.Evidence dated Apr 22, 2026
Evidence-Prioritized Access Paths
Top Initial Access & Account-Takeover Vectors
At-Bay's evidence places remotely accessible infrastructure, valid credentials, trusted software acquisition, and weak third-party security operations ahead of exotic malware as the access conditions most likely to translate into insured loss.
Publisher-observed access path
Exposed or weakly governed RDP[5]Evidence dated Apr 22, 2026
Retained At-Bay evidence; local exposure and prevalence require validation
- How it starts
- Remote desktop is reachable or protected by reusable credentials and insufficient authentication controls.
- Attacker outcome
- Interactive access, lateral movement, staging, and ransomware deployment.
- What to monitor
- Internet reachability, failed-to-successful logins, unusual source infrastructure, new sessions, privilege changes, and remote tooling.
Publisher-observed access path
Stolen credentials and legacy authentication[7]Evidence dated Jul 14, 2026
Retained At-Bay evidence; local exposure and prevalence require validation
- How it starts
- An attacker acquires valid credentials and selects an older or unusual authentication path.
- Attacker outcome
- Account takeover that can bypass user suspicion and conventional malware detection.
- What to monitor
- Impossible geography, low-cost cloud sources, never-before-used protocols, session changes, and access outside normal behavior.
Publisher-observed access path
SEO-poisoned software[10]Evidence dated May 13, 2026
Retained At-Bay evidence; local exposure and prevalence require validation
- How it starts
- A user or service provider downloads a trojanized tool from a manipulated search result.
- Attacker outcome
- Execution through a trusted administrative workflow followed by ransomware and backup destruction.
- What to monitor
- Approved software catalogs, signatures and hashes, download origin, first-run child processes, MFA anomalies, and rapid lateral spread.
- How it starts
- Operational providers restore or administer systems without sufficient threat detection, forensic scope, or validation.
- Attacker outcome
- Long dwell, persistent access, reinfection, incomplete closure, or downstream impact.
- What to monitor
- Shared accounts, provider tooling, log retention, backup cleanliness, post-incident persistence checks, and security-monitoring ownership.
| Vector / Evidence | How It Starts | Attacker Outcome | What to Monitor |
|---|---|---|---|
| Attackers identify and exploit exposed remote-access appliances or use credentials associated with them. | Privileged network entry followed by ransomware, data theft, or recovery-system targeting. | Exact appliance inventory, exposure, versions, configuration drift, admin changes, anomalous VPN sessions, and post-patch credential use. | |
2 Publisher-observed access path Exposed or weakly governed RDP[5]Evidence dated Apr 22, 2026 Retained At-Bay evidence; local exposure and prevalence require validation | Remote desktop is reachable or protected by reusable credentials and insufficient authentication controls. | Interactive access, lateral movement, staging, and ransomware deployment. | Internet reachability, failed-to-successful logins, unusual source infrastructure, new sessions, privilege changes, and remote tooling. |
3 Publisher-observed access path Stolen credentials and legacy authentication[7]Evidence dated Jul 14, 2026 Retained At-Bay evidence; local exposure and prevalence require validation | An attacker acquires valid credentials and selects an older or unusual authentication path. | Account takeover that can bypass user suspicion and conventional malware detection. | Impossible geography, low-cost cloud sources, never-before-used protocols, session changes, and access outside normal behavior. |
4 Publisher-observed access path SEO-poisoned software[10]Evidence dated May 13, 2026 Retained At-Bay evidence; local exposure and prevalence require validation | A user or service provider downloads a trojanized tool from a manipulated search result. | Execution through a trusted administrative workflow followed by ransomware and backup destruction. | Approved software catalogs, signatures and hashes, download origin, first-run child processes, MFA anomalies, and rapid lateral spread. |
| Operational providers restore or administer systems without sufficient threat detection, forensic scope, or validation. | Long dwell, persistent access, reinfection, incomplete closure, or downstream impact. | Shared accounts, provider tooling, log retention, backup cleanliness, post-incident persistence checks, and security-monitoring ownership. |
Intended Reader and Decision Context
Persona / Audience
Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.
| Audience Field | Assessment |
|---|---|
| Audience fieldPrimary audience | AssessmentExecutives, CISOs, CIOs, incident-response leaders, threat-intelligence teams, SOC leaders, risk owners, and business-continuity leaders who need a decision-ready view of one publisher's strongest public research. |
| Audience fieldDecision use | AssessmentUse the card to identify recurring access paths, actor and campaign changes, affected technologies, likely business impact, and control priorities that deserve validation inside the reader's own environment. |
| Audience fieldSource posture | AssessmentAt-Bay is the controlling source for publisher-specific observations. External facts repeated in a publication retain the original attribution and are not upgraded into independently verified IntelliOS findings. |
| Audience fieldUpdate model | AssessmentA dedicated publisher agent checks the complete monitored corpus weekly on friday at midday et, keeps a cumulative rolling one-year window, and sends Page Alerts only for material source-backed changes. |
Chronology and Decision Milestones
Timeline of Notable Activity
Entries are ordered from oldest to newest across the full rolling year. Portfolio findings use the end of At-Bay's named claims or observation period; case studies, threat research, and advisories use the stated incident or publication date as labeled. Citations preserve the later public date.
SonicWall response activity
Multiple response cases with similar SonicWall SSL VPN indicators triggered a disable-or-restrict decision
At-Bay advised organizations to disable the affected SSL VPN function or restrict access to known IP addresses while investigations continued. The response standard is exact appliance inventory, exposure reduction, credential review and retrospective hunting—not waiting for perfect attribution.[13]
Backup risk assessment
A six-year-old backup design created recovery risk even before a ransomware event
At-Bay's university assessment found aging infrastructure and no dedicated ransomware protections in the backup environment. The useful lesson is to treat immutability, isolation, credentials, retention and recovery testing as one designed control, not a storage purchase.[14]
Rhysida intrusion chain
A trojanized PuTTY installer turned a trusted admin workflow into six stages of access, theft and evasion
At-Bay traces SEO poisoning to remote access, RDP movement, network scanning, AzCopy exfiltration of more than 100,000 files and log clearing. A failed cleanup script preserved evidence; ordinary administration tools must be correlated as a sequence.[15]
2025 observation · ransomware initial access
Remote access has become the dominant loss path in At-Bay's ransomware claims
At-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.[4][5][11]
2025 observation · SMB loss severity
Small businesses are absorbing a higher financial floor for cyber incidents
For companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.[5][11]
2025 observation · ransomware concentration
Akira industrialized one appliance-focused campaign into portfolio-level loss
At-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.[5][11]
2025 observation · detection and response
EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome
At-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.[5]
2025 observation · secondary loss
Interruption and liability can dominate the cost after initial compromise
At-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.[4][5][11]
2025 observation · financial fraud recovery
The first three days materially change stolen-funds recovery odds
At-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.[5][11]
Q4 observation · extortion shift
Non-encryption extortion rose 450% from Q3 to Q4 in At-Bay's response data
At-Bay's Pure Extraction research describes operators prioritizing fast data theft and pressure over encryption. Recovery readiness remains necessary, but identity, exfiltration detection, legal preparation and executive communications now determine outcome even when systems stay online.[16]
PEAR operating model
PEAR paired long dwell with a 24-hour exfiltration burst and direct executive pressure
In At-Bay's casework, the actor spent months inside, then used WinSCP to remove roughly 732 GB within 24 hours before extortion. Detection alerts without full containment allowed the operation to continue; executive contact can be the first visible sign of a long-running compromise.[16]
Low-cost control uplift
Existing Google Workspace controls can raise the baseline before new tooling is purchased
At-Bay highlights malware scanning, security checkup, DLP, behavioral phishing detection, and heuristic analysis already available in common productivity workflows. Organizations should verify configuration, licensing, logging, alert ownership, and response rather than assuming default availability equals effective protection.[12]
Long dwell and extortion
Seven months of quiet access erased the evidence needed to identify initial entry
At-Bay's PEAR case found a seven-month intrusion only after executives received extortion threats. Log rolling prevented recovery of the exact initial-access method. Security telemetry retention must reflect realistic dwell and litigation periods rather than short operational defaults.[8]
Incomplete remediation
Restoring operations left one organization compromised for roughly two years
At-Bay found that an earlier incident had never been fully investigated or remediated; persistence and encrypted domain resources survived the operational recovery. Incident closure requires forensic scope, access revocation, persistence removal, clean identity recovery, and post-restoration monitoring.[9]
SEO-poisoned software
A trusted IT workflow delivered Akira and destroyed backups across 60 servers
An MSP installed a trojanized AI tool from a poisoned search result, leading to an Akira incident, destroyed backups, and a $10M demand. At-Bay reports isolation in about two hours and a $1.5M settlement; those are case-specific outcomes, while software provenance and backup separation are the repeatable lessons.[10]
Recovery integrity
A clean restore is not guaranteed when the backup repository still contains malware
In an At-Bay case, a routine restore began reintroducing a malicious macro document from the original breach. Behavioral detection stopped execution and the response removed the file from both the restored system and source repository. Recovery testing must include malware validation and backup sanitization, not only successful restoration.[6]
Identity detection
One anomalous legacy-authentication event can reveal stolen-credential access
At-Bay describes a U.S. finance user authenticating from a low-cost cloud server in Ukraine through legacy systems the user had never used. Geographic, behavioral, and authentication-path anomalies enabled session revocation before exfiltration.[7]
Bottom Line Up Front
BLUF
Remote access has become the dominant loss path in At-Bay's ransomware claims: At-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.[4][5][11]Evidence dated Apr 22, 2026
Small businesses are absorbing a higher financial floor for cyber incidents: For companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.[5][11]Evidence dated Apr 22, 2026
Akira industrialized one appliance-focused campaign into portfolio-level loss: At-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.[5][11]Evidence dated Apr 22, 2026
EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome: At-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.[5]Evidence dated Apr 22, 2026
Interruption and liability can dominate the cost after initial compromise: At-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.[4][5][11]Evidence dated Apr 22, 2026
The first three days materially change stolen-funds recovery odds: At-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.[5][11]Evidence dated Apr 22, 2026
Decision Context
Executive Summary
At-Bay's most important contribution is connecting technical exposure to financial outcome. Its 2026 InsurSec reporting draws on more than 100,000 policy years and over 6,500 claims, giving executives a portfolio view of which access paths, controls, and response conditions correlated with frequency and severity inside At-Bay's book. Those results are decision evidence, not a national incident census.[4][5][11]Evidence dated Apr 22, 2026
Remote access dominates the ransomware story. VPNs initiated 73% of reported ransomware claims and VPN plus RDP initiated 87%. Akira's concentration around SonicWall shows why generic control questions are too weak: leadership needs an owned inventory of exact appliances, versions, configurations, exposure history, identities, logs, and compensating monitoring.[4][5][11]Evidence dated Apr 22, 2026
The case studies show that technical recovery and security closure are different outcomes. Malware can remain in backups, attacker persistence can survive restoration, identity access can remain active, and old evidence can disappear before extortion is discovered. A restore test that measures only whether systems boot is not proof that the environment is clean or the incident is closed.[6][8][9]First cited source May 13, 2026 · Latest cited source Jul 14, 2026
At-Bay's loss data makes time an executive control. Rapid fraud notification materially improved recovery rates, monitored detection changed ransomware outcomes in its Akira data, and business interruption multiplied severity. Escalation thresholds, insurer and bank contacts, containment authority, evidence retention, and recovery priorities must exist before the event.[5][7][10][11]First cited source Apr 22, 2026 · Latest cited source Jul 14, 2026
The practical operating standard is continuous and specific: secure every remote-access path, retire legacy authentication, monitor identity and endpoint behavior, verify software provenance, sanitize backups, retain useful logs, scope MSP trust, and require forensic closure after restoration. Brokers and underwriters can then evaluate evidence of operation rather than control names alone.[5][6][7][8][9][10][12]First cited source Mar 9, 2026 · Latest cited source Jul 14, 2026
Executive Briefing Priorities
Top 10 Briefing Points
- 1
Remote access has become the dominant loss path in At-Bay's ransomware claims — At-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence.[4][5][11]Evidence dated Apr 22, 2026
- 2
Small businesses are absorbing a higher financial floor for cyber incidents — For companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues.[5][11]Evidence dated Apr 22, 2026
- 3
Akira industrialized one appliance-focused campaign into portfolio-level loss — At-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised.[5][11]Evidence dated Apr 22, 2026
- 4
EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome — At-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware.[5]Evidence dated Apr 22, 2026
- 5
Interruption and liability can dominate the cost after initial compromise — At-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations.[4][5][11]Evidence dated Apr 22, 2026
- 6
The first three days materially change stolen-funds recovery odds — At-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs.[5][11]Evidence dated Apr 22, 2026
- 7
A clean restore is not guaranteed when the backup repository still contains malware — In an At-Bay case, a routine restore began reintroducing a malicious macro document from the original breach. Behavioral detection stopped execution and the response removed the file from both the restored system and source repository. Recovery testing must include malware validation and backup sanitization, not only successful restoration.[6]Evidence dated Jul 14, 2026
- 8
One anomalous legacy-authentication event can reveal stolen-credential access — At-Bay describes a U.S. finance user authenticating from a low-cost cloud server in Ukraine through legacy systems the user had never used. Geographic, behavioral, and authentication-path anomalies enabled session revocation before exfiltration.[7]Evidence dated Jul 14, 2026
- 9
Seven months of quiet access erased the evidence needed to identify initial entry — At-Bay's PEAR case found a seven-month intrusion only after executives received extortion threats. Log rolling prevented recovery of the exact initial-access method. Security telemetry retention must reflect realistic dwell and litigation periods rather than short operational defaults.[8]Evidence dated May 13, 2026
- 10
Restoring operations left one organization compromised for roughly two years — At-Bay found that an earlier incident had never been fully investigated or remediated; persistence and encrypted domain resources survived the operational recovery. Incident closure requires forensic scope, access revocation, persistence removal, clean identity recovery, and post-restoration monitoring.[9]Evidence dated May 13, 2026
- 11
A trusted IT workflow delivered Akira and destroyed backups across 60 servers — An MSP installed a trojanized AI tool from a poisoned search result, leading to an Akira incident, destroyed backups, and a $10M demand. At-Bay reports isolation in about two hours and a $1.5M settlement; those are case-specific outcomes, while software provenance and backup separation are the repeatable lessons.[10]Evidence dated May 13, 2026
- 12
Existing Google Workspace controls can raise the baseline before new tooling is purchased — At-Bay highlights malware scanning, security checkup, DLP, behavioral phishing detection, and heuristic analysis already available in common productivity workflows. Organizations should verify configuration, licensing, logging, alert ownership, and response rather than assuming default availability equals effective protection.[12]Evidence dated Mar 9, 2026
- 13
Multiple response cases with similar SonicWall SSL VPN indicators triggered a disable-or-restrict decision — At-Bay advised organizations to disable the affected SSL VPN function or restrict access to known IP addresses while investigations continued. The response standard is exact appliance inventory, exposure reduction, credential review and retrospective hunting—not waiting for perfect attribution.[13]Evidence dated Aug 5, 2025
- 14
A six-year-old backup design created recovery risk even before a ransomware event — At-Bay's university assessment found aging infrastructure and no dedicated ransomware protections in the backup environment. The useful lesson is to treat immutability, isolation, credentials, retention and recovery testing as one designed control, not a storage purchase.[14]Evidence dated Aug 12, 2025
- 15
A trojanized PuTTY installer turned a trusted admin workflow into six stages of access, theft and evasion — At-Bay traces SEO poisoning to remote access, RDP movement, network scanning, AzCopy exfiltration of more than 100,000 files and log clearing. A failed cleanup script preserved evidence; ordinary administration tools must be correlated as a sequence.[15]Evidence dated Sep 2, 2025
- 16
Non-encryption extortion rose 450% from Q3 to Q4 in At-Bay's response data — At-Bay's Pure Extraction research describes operators prioritizing fast data theft and pressure over encryption. Recovery readiness remains necessary, but identity, exfiltration detection, legal preparation and executive communications now determine outcome even when systems stay online.[16]Evidence dated Feb 11, 2026
- 17
PEAR paired long dwell with a 24-hour exfiltration burst and direct executive pressure — In At-Bay's casework, the actor spent months inside, then used WinSCP to remove roughly 732 GB within 24 hours before extortion. Detection alerts without full containment allowed the operation to continue; executive contact can be the first visible sign of a long-running compromise.[16]Evidence dated Feb 11, 2026
Source-Bound Exposure and Targeting
Victimology Matrix
This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.
| Victim / exposure population | Sectors | Geography | Confirmation status | How companies should use it |
|---|---|---|---|---|
| Victim / exposure populationBusinesses with exposed VPN or RDP services[4][5][11]Evidence dated Apr 22, 2026 | SectorsCross-industry | GeographyAt-Bay's U.S.-focused insured population | Confirmation statusPortfolio claims analysis; not an internet-wide exposure census | How companies should use itInventory exact products, restrict exposure, require phishing-resistant access, review historical authentication, and test rapid isolation. |
| Victim / exposure populationBusinesses under $25M in revenue[5][11]Evidence dated Apr 22, 2026 | SectorsSMB and lower-middle-market | GeographyAt-Bay portfolio | Confirmation statusAt-Bay segment-level frequency and severity analysis | How companies should use itPlan for a higher minimum loss, validate cash-flow and downtime tolerance, and prove recovery rather than relying on organization size as protection. |
| Victim / exposure populationOrganizations dependent on MSPs[6][8][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026 | SectorsFinance, media, real estate, and cross-industry | GeographyCase-specific U.S. examples | Confirmation statusSeveral individual At-Bay case studies | How companies should use itSeparate IT operations from security monitoring; govern software sourcing, identity visibility, logging, backup hygiene, and incident closure. |
| Victim / exposure populationFinance teams and payment workflows[5][11]Evidence dated Apr 22, 2026 | SectorsCross-industry | GeographyAt-Bay claims population | Confirmation statusPortfolio fraud and recovery observations | How companies should use itImplement dual approval, out-of-band verification, same-day escalation, bank recall, insurer notice, and evidence preservation. |
| Victim / exposure populationOrganizations restoring from backup after an incident[6][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026 | SectorsCross-industry | GeographyCase-specific | Confirmation statusAt-Bay response cases | How companies should use itScan repositories and restored content, rebuild identity safely, remove persistence, validate known-clean state, and monitor after cutover. |
Distinct Operational Records
At-Bay Research Themes & Operations
Akira and SonicWall-focused ransomware activity
At-Bay links portfolio-level Akira concentration to systematic exploitation of a specific remote-access technology and documents one SEO-poisoning case with destructive backup impact.[5][10][11]First cited source Apr 22, 2026 · Latest cited source May 13, 2026
PEAR long-dwell extortion
A quiet seven-month intrusion progressed to data theft and direct executive pressure after old evidence had rolled off.[8]Evidence dated May 13, 2026
Stolen-credential account takeover
Behavioral differences in location, cloud hosting, and legacy-authentication use enabled containment before exfiltration.[7]Evidence dated Jul 14, 2026
Backup-mediated malware reinfection
Unclean backup content attempted to reintroduce malware during ordinary restoration.[6]Evidence dated Jul 14, 2026
Persistent access after incomplete remediation
Operational recovery without forensic closure allowed compromise evidence and access to survive for roughly two years.[9]Evidence dated May 13, 2026
Source-Bound Actor Context
Threat Actors, Operators & Decision Owners
Akira
At-Bay's leading ransomware strain in the report population, tied to appliance-focused activity and a separate case involving SEO-poisoned software, 60 encrypted servers, and destroyed backups.[5][10][11]First cited source Apr 22, 2026 · Latest cited source May 13, 2026
PEAR
Named in At-Bay's seven-month finance-sector intrusion and data-extortion case; the original access method remained unknown because logs had rolled off.[8]Evidence dated May 13, 2026
Credential-access operators
Use stolen credentials, cloud infrastructure, unusual geography, and legacy authentication paths to establish access that can resemble legitimate user activity.[7]Evidence dated Jul 14, 2026
SEO-poisoning distributors
Trojanize or impersonate wanted software so administrators and service providers execute the initial payload through a trusted workflow.[10]Evidence dated May 13, 2026
Financial-fraud operators
Exploit payment authority and delay; At-Bay's recovery statistics show why detection and notification speed materially affect loss.[5][11]Evidence dated Apr 22, 2026
Enterprise Exposure
Affected Technologies & Trust Boundaries
SonicWall and other VPN appliances
At-Bay's claims data elevates exact appliance exposure, configuration, credential, and historical-access review above generic 'VPN present' questionnaires.[4][5][11]Evidence dated Apr 22, 2026
RDP and remote administration
RDP completes the 87% remote-access share and should be removed from direct exposure or strongly brokered, monitored, and identity-protected.[5]Evidence dated Apr 22, 2026
EDR and MDR operations
Product presence alone did not prevent many reported Akira compromises; monitored detection, authority, and containment are the meaningful capability.[5][6][7]First cited source Apr 22, 2026 · Latest cited source Jul 14, 2026
Backup repositories and Active Directory
Backups can carry malware and restored environments can retain persistence or damaged identity resources.[6][9][10]First cited source May 13, 2026 · Latest cited source Jul 14, 2026
Google Workspace
Built-in malware, phishing, DLP, heuristic, and security-review features can strengthen the baseline when configured, logged, and owned.[12]Evidence dated Mar 9, 2026
Current Carry-Forward Watchlist
Top 10 Specific Threats to Monitor
Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.
| # | Threat / Category | Why It Matters | What to Monitor | IntelliOS Coverage |
|---|---|---|---|---|
| 1 | Threat / Category 2025 observation · ransomware initial access Remote access has become the dominant loss path in At-Bay's ransomware claims[4][5][11]Evidence dated Apr 22, 2026 | Why it mattersAt-Bay reports that VPNs initiated 73% of its 2025 ransomware claims and VPN plus RDP initiated 87%. The underwriting and defensive decision is to treat exposed remote access as a loss-control system with asset ownership, supported versions, phishing-resistant authentication, configuration review, and historical login evidence. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 2 | Threat / Category 2025 observation · SMB loss severity Small businesses are absorbing a higher financial floor for cyber incidents[5][11]Evidence dated Apr 22, 2026 | Why it mattersFor companies under $25M in revenue, At-Bay reports ransomware frequency up 21% and ransomware severity up 40% year over year to $422K; average severity across all incident types for that segment rose 26%. The measures are At-Bay portfolio results, but they make tested recovery and cash-flow resilience immediate SMB governance issues. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 3 | Threat / Category 2025 observation · ransomware concentration Akira industrialized one appliance-focused campaign into portfolio-level loss[5][11]Evidence dated Apr 22, 2026 | Why it mattersAt-Bay attributes more than 40% of its ransomware claims to Akira and says SonicWall appliances were present in 86% of Akira attacks. The finding supports device-specific exposure review and behavioral hunting without implying that every SonicWall deployment was vulnerable or compromised. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 4 | Threat / Category 2025 observation · detection and response EDR presence did not prevent many Akira losses; continuously monitored response changed the outcome[5]Evidence dated Apr 22, 2026 | Why it mattersAt-Bay says 60% of Akira victims had a leading EDR product, while the businesses in its data that avoided full encryption had EDR backed by 24/7 MDR. Treat this as portfolio evidence for monitored response and containment capability—not a guarantee that any specific MDR service prevents ransomware. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 5 | Threat / Category 2025 observation · secondary loss Interruption and liability can dominate the cost after initial compromise[4][5][11]Evidence dated Apr 22, 2026 | Why it mattersAt-Bay reports ransomware claims involving business interruption were three times more severe on average, one in ten affected organizations experienced more than 30 days of downtime, and third-party liability severity increased 70% year over year. Recovery objectives, dependency maps, evidence preservation, and post-incident legal readiness belong in underwriting conversations. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 6 | Threat / Category 2025 observation · financial fraud recovery The first three days materially change stolen-funds recovery odds[5][11]Evidence dated Apr 22, 2026 | Why it mattersAt-Bay reports that policyholders notifying it within three days recovered funds 70% of the time, compared with 27% after more than 30 days. Finance teams need same-day escalation, bank contact, transaction evidence, insurer notice, and law-enforcement workflows before a fraudulent transfer occurs. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 7 | Threat / Category Recovery integrity A clean restore is not guaranteed when the backup repository still contains malware[6]Evidence dated Jul 14, 2026 | Why it mattersIn an At-Bay case, a routine restore began reintroducing a malicious macro document from the original breach. Behavioral detection stopped execution and the response removed the file from both the restored system and source repository. Recovery testing must include malware validation and backup sanitization, not only successful restoration. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 8 | Threat / Category Identity detection One anomalous legacy-authentication event can reveal stolen-credential access[7]Evidence dated Jul 14, 2026 | Why it mattersAt-Bay describes a U.S. finance user authenticating from a low-cost cloud server in Ukraine through legacy systems the user had never used. Geographic, behavioral, and authentication-path anomalies enabled session revocation before exfiltration. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 9 | Threat / Category Long dwell and extortion Seven months of quiet access erased the evidence needed to identify initial entry[8]Evidence dated May 13, 2026 | Why it mattersAt-Bay's PEAR case found a seven-month intrusion only after executives received extortion threats. Log rolling prevented recovery of the exact initial-access method. Security telemetry retention must reflect realistic dwell and litigation periods rather than short operational defaults. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 10 | Threat / Category Incomplete remediation Restoring operations left one organization compromised for roughly two years[9]Evidence dated May 13, 2026 | Why it mattersAt-Bay found that an earlier incident had never been fully investigated or remediated; persistence and encrypted domain resources survived the operational recovery. Incident closure requires forensic scope, access revocation, persistence removal, clean identity recovery, and post-restoration monitoring. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 11 | Threat / Category SEO-poisoned software A trusted IT workflow delivered Akira and destroyed backups across 60 servers[10]Evidence dated May 13, 2026 | Why it mattersAn MSP installed a trojanized AI tool from a poisoned search result, leading to an Akira incident, destroyed backups, and a $10M demand. At-Bay reports isolation in about two hours and a $1.5M settlement; those are case-specific outcomes, while software provenance and backup separation are the repeatable lessons. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 12 | Threat / Category Low-cost control uplift Existing Google Workspace controls can raise the baseline before new tooling is purchased[12]Evidence dated Mar 9, 2026 | Why it mattersAt-Bay highlights malware scanning, security checkup, DLP, behavioral phishing detection, and heuristic analysis already available in common productivity workflows. Organizations should verify configuration, licensing, logging, alert ownership, and response rather than assuming default availability equals effective protection. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 13 | Threat / Category SonicWall response activity Multiple response cases with similar SonicWall SSL VPN indicators triggered a disable-or-restrict decision[13]Evidence dated Aug 5, 2025 | Why it mattersAt-Bay advised organizations to disable the affected SSL VPN function or restrict access to known IP addresses while investigations continued. The response standard is exact appliance inventory, exposure reduction, credential review and retrospective hunting—not waiting for perfect attribution. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 14 | Threat / Category Backup risk assessment A six-year-old backup design created recovery risk even before a ransomware event[14]Evidence dated Aug 12, 2025 | Why it mattersAt-Bay's university assessment found aging infrastructure and no dedicated ransomware protections in the backup environment. The useful lesson is to treat immutability, isolation, credentials, retention and recovery testing as one designed control, not a storage purchase. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 15 | Threat / Category Rhysida intrusion chain A trojanized PuTTY installer turned a trusted admin workflow into six stages of access, theft and evasion[15]Evidence dated Sep 2, 2025 | Why it mattersAt-Bay traces SEO poisoning to remote access, RDP movement, network scanning, AzCopy exfiltration of more than 100,000 files and log clearing. A failed cleanup script preserved evidence; ordinary administration tools must be correlated as a sequence. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 16 | Threat / Category Q4 observation · extortion shift Non-encryption extortion rose 450% from Q3 to Q4 in At-Bay's response data[16]Evidence dated Feb 11, 2026 | Why it mattersAt-Bay's Pure Extraction research describes operators prioritizing fast data theft and pressure over encryption. Recovery readiness remains necessary, but identity, exfiltration detection, legal preparation and executive communications now determine outcome even when systems stay online. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 17 | Threat / Category PEAR operating model PEAR paired long dwell with a 24-hour exfiltration burst and direct executive pressure[16]Evidence dated Feb 11, 2026 | Why it mattersIn At-Bay's casework, the actor spent months inside, then used WinSCP to remove roughly 732 GB within 24 hours before extortion. Detection alerts without full containment allowed the operation to continue; executive contact can be the first visible sign of a long-running compromise. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by At-Bay exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
Operational Standards from the Evidence
Best Practices and Lessons Learned
The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.
- 1
Lesson Learned
A generic control label can hide the device, version, configuration, exposure, identity, and monitoring conditions that drive loss.
Minimum Operating Standard
Maintain evidence for every remote-access technology, supported version, management path, authentication policy, owner, exposure history, and compensating control.
- 2
Best Practice
Separate restoration from remediation[6][9]First cited source May 13, 2026 · Latest cited source Jul 14, 2026
Lesson Learned
Systems can return to service while malware, persistence, damaged identity, or attacker access remains.
Minimum Operating Standard
Require forensic scope, known-clean rebuild criteria, backup sanitization, credential and session revocation, persistence validation, and post-restore monitoring before closure.
- 3
Best Practice
Measure monitored response capability[5][6][7]First cited source Apr 22, 2026 · Latest cited source Jul 14, 2026
Lesson Learned
EDR installation does not prove that someone can interpret and contain activity continuously.
Minimum Operating Standard
Test alert ownership, 24/7 response, isolation authority, escalation time, coverage gaps, and evidence preservation through exercises and real telemetry.
- 4
Best Practice
Retain evidence for realistic dwell[8]Evidence dated May 13, 2026
Lesson Learned
Short log retention erased the initial-access story in a seven-month intrusion.
Minimum Operating Standard
Set identity, endpoint, network, cloud, email, and administrative log retention from threat dwell, legal, insurance, and investigation requirements.
- 5
Lesson Learned
Recovery probability declined sharply when notification was delayed.
Minimum Operating Standard
Pre-authorize bank recall, insurer notice, counsel, law enforcement, transaction preservation, and executive escalation immediately after suspected fraud.
- 6
Best Practice
Govern trusted software acquisition[10]Evidence dated May 13, 2026
Lesson Learned
A familiar search result and useful tool name can become an initial-access mechanism.
Minimum Operating Standard
Use approved catalogs, vendor-direct sources, signature and hash validation, restricted installation rights, sandboxing, and first-run monitoring.
Automation Transparency
AI Agent Run Status
| Agent | At-Bay Rolling Intelligence Card Publisher |
|---|---|
| Status | Active · rolling one-year automation |
| Cadence | Weekly on Friday at midday ET |
| Previous run | 26 Jul 2026 · material revision · Run at-bay-publisher-activity-2026-07-26-initial |
| Previous result | Kept the full-year product and backfilled At-Bay's chronology to August 2025 with SonicWall response evidence, backup-risk assessment, Rhysida casework, and PEAR data-theft-only extortion findings; moved 2025 portfolio findings to their observation-period endpoint. |
| What the previous run found |
|
| Next run | Weekly on Friday at midday ET |
| Sources monitored |
|
| Publication and alert policy | Check weekly on friday at midday et. Publish and alert only when a new At-Bay publication materially changes an actor, campaign, technology, initial-access, victimology, impact, response, resilience, or executive conclusion. No-change checks are logged but do not email subscribers. |
Related Intelligence and CARDS Records
Other IntelliOS Products
Rolling Intelligence
Government Cybersecurity Actions & Advisories
Official advisories, exploited technologies, deadlines, and government response priorities that can validate or constrain publisher reporting.
Open productCARDS
Threat Actor Cards
Canonical actor identities, aliases, attribution boundaries, behaviors, relationships, and linked campaigns.
Open productCARDS Actor Record
Akira Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Pear Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productPublication History
Version Change Log
| Version | Date | Change | Monitoring |
|---|---|---|---|
| Versionv1 | Date26 Jul 2026 | ChangeCreated the At-Bay rolling one-year publisher card with Research Framing, Timeline, BLUF, Executive Summary, top-ten findings, victimology, campaigns, actors, technologies, access vectors, operational practices, AI agent status, and citations. | MonitoringWeekly on Friday at midday ET; material-change-only Page Alerts. |
| Versionv2 | Date26 Jul 2026 | ChangeKept the full-year product and backfilled At-Bay's chronology to August 2025 with SonicWall response evidence, backup-risk assessment, Rhysida casework, and PEAR data-theft-only extortion findings; moved 2025 portfolio findings to their observation-period endpoint. | MonitoringWeekly on Friday at midday ET; material-change-only Page Alerts. |
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Publication / Evidence | Why Used / Claim Treatment | Source |
|---|---|---|---|---|---|
| Source1 | PublisherAt-Bay | PublishedNot available | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentRequested first-party underwriting lane monitored weekly. The archive returned no posts at initial publication, so it controls no current finding until At-Bay publishes qualifying material. | SourceAt-Bay Underwriting Archive https://www.at-bay.com/teams/underwriting/ |
| Source2 | PublisherAt-Bay | PublishedNot available | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentAuthoritative first-party company-news index. News releases can identify new research or services, but promotional statements do not independently establish loss prevalence or control effectiveness. | SourceAt-Bay Newsroom https://www.at-bay.com/about/newsroom/ |
| Source3 | PublisherAt-Bay | PublishedNot available | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentAuthoritative first-party corpus index monitored across All, Article, Case Study, Document, eBook, Report, Threat Research, Webinar, Worksheet, and Video. Individual retained publications control findings. | SourceAt-Bay Cybersecurity Knowledge Center — All Content Types https://www.at-bay.com/learn/cyber-security/ |
| Source4 | PublisherAt-Bay | Published2026-04-22 | Publication / evidenceSource indexincident response | Why used / claim treatmentAt-Bay analysis based on more than 100,000 policy years and over 6,500 claims. Results describe At-Bay's insured and claims population, not all U.S. businesses or incidents. | SourceThe 2026 InsurSec Report https://www.at-bay.com/2026-insursec-report/ |
| Source5 | PublisherAt-Bay | Published2026-04-22 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party release summarizing the 2026 InsurSec Report. Percentages, severities, demands, payments, and recoveries remain bounded to At-Bay's described claims population. | Source1 in 3 Ransomware Claims Started with SonicWall in 2025 https://www.at-bay.com/press_releases/2026-insursec-report-ransomware-vpn-sonicwall-attacks/ |
| Source6 | PublisherAt-Bay | Published2026-07-14 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party case study of one response outcome. The case demonstrates a control failure mode but does not establish prevalence or guarantee comparable MDR outcomes. | SourceMalware in the Backups: How a Restoration Almost Brought the Attacker Back https://www.at-bay.com/case-studies/malware-in-backups-mdr/ |
| Source7 | PublisherAt-Bay | Published2026-07-14 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party case study of a single account-takeover detection and containment. Outcome and response timing are case-specific. | SourceOne Unusual Login: How Behavioral Analysis Stopped an Account Takeover https://www.at-bay.com/case-studies/stop-account-takeover-mdr/ |
| Source8 | PublisherAt-Bay | Published2026-05-13 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party response case involving PEAR, long dwell, exfiltration, and extortion. The exact initial access could not be recovered because historical logs had rolled off. | Source7 Months Inside: How Threat Actors Reached the C-Suite https://www.at-bay.com/case-studies/long-dwell-attack-case-study/ |
| Source9 | PublisherAt-Bay | Published2026-05-13 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party case study of incomplete remediation and persistent access. It demonstrates why operational restoration is not proof of incident closure. | SourceThe Breach That Never Closed: A 2-Year-Old Compromise That Survived Backup Restoration https://www.at-bay.com/case-studies/incomplete-ransomware-remediation-case-study/ |
| Source10 | PublisherAt-Bay | Published2026-05-13 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party case study of one Akira incident, containment, and negotiation. The demand, settlement, server count, and timeline are case-specific and not expected outcomes. | SourceInside an Akira Ransomware Attack: 60 Servers, Destroyed Backups, and an 85% Negotiated Reduction https://www.at-bay.com/case-studies/akira-ransomware-attack-case-study/ |
| Source11 | PublisherAt-Bay | Published2026-04-22 | Publication / evidenceSource indexincident response | Why used / claim treatmentAt-Bay interpretation of its claims report, including frequency, severity, ransomware, fraud, interruption, and liability findings. Metrics remain bounded to the report methodology. | Source5 Key Findings From the 2026 InsurSec Report https://www.at-bay.com/articles/insursec-report-2026-key-findings-cyber-risk/ |
| Source12 | PublisherAt-Bay | Published2026-03-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentDefensive guidance about built-in Google Workspace capabilities. Product descriptions and third-party statistics retain their original attribution and require configuration-specific validation. | SourceThe Cybersecurity Tools Hidden in Google Workspace https://www.at-bay.com/articles/google-workspace-cybersecurity-free-tools/ |
| Source13 | PublisherAt-Bay | Published2025-08-05 | Publication / evidenceSource indexincident response | Why used / claim treatmentAt-Bay defensive advisory informed by multiple response investigations with similar indicators. Similarity does not prove one common actor or compromise in every exposed appliance. | SourceSonicWall SSL VPN Zero-Day: What Businesses Need to Know https://www.at-bay.com/articles/sonicwall-ssl-vpn-zero-day/ |
| Source14 | PublisherAt-Bay | Published2025-08-12 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party account of one security assessment and remediation program. It demonstrates an exposure pattern but not the prevalence or guaranteed effectiveness of the recommendations. | SourceUniversity Reduces Ransomware Risk With Backup Overhaul https://www.at-bay.com/case-studies/university-reduces-ransomware-risk-with-backup-overhaul/ |
| Source15 | PublisherAt-Bay | Published2025-09-02 | Publication / evidenceSource indexincident response | Why used / claim treatmentTechnical analysis of a documented Rhysida intrusion. The observed chain is case-specific and does not establish universal Rhysida behavior. | SourceRhysida: Evading Detection Through a Trojanized PuTTY Installer https://www.at-bay.com/threat-research/rhysida-evading-detection/ |
| Source16 | PublisherAt-Bay | Published2026-02-11 | Publication / evidenceSource indexincident response | Why used / claim treatmentAt-Bay response-data analysis and PEAR casework. The reported growth and demand figures remain bounded to At-Bay's stated incident population and public leak-site observations. | SourcePure Extraction: Ransomware Groups Prioritize Data Theft https://www.at-bay.com/threat-research/pure-extraction-ransomware-groups-prioritize-data-theft/ |
