8 min read

It Costs $4 to Attack Your Business. It Takes Weeks to Recover.

It Costs $4 to Attack Your Business. It Takes Weeks to Recover.
It Costs $4 to Attack Your Business. It Takes Weeks to Recover.
14:19

AI MADE RANSOMWARE CHEAP. STOLEN PASSWORDS MAKE IT EASY.

It's the second week of harvest. Trucks are lined up past the scale house, and the ticketing system won't load. Neither will anything else on the network. The office manager restarts, tries again, and then notices every screen in the building is showing the same message.

Nobody at an Iowa co-op wants to picture that in October. But a version of it played out at four dairy plants this summer.

On July 16, Coca-Cola disclosed in an SEC filing that fairlife, its dairy company, had identified unauthorized access by a third party to its systems, including production-related systems, in connection with a ransomware event. U.S. production was temporarily suspended. On July 27, eleven days later, Coca-Cola announced fairlife had resumed the majority of production at its four facilities. Store shelves stayed “largely unimpacted, due to the availability of existing inventory,” according to the company.

Fairlife had enough product in the warehouse to ride it out. Most plants don't. Neither does a grain elevator in the middle of harvest.

In August it was Boston Scientific. The medical device maker identified a cybersecurity incident on August 25 that, according to its SEC filing, caused “a global disruption” to its ability to process and ship customer orders. MD+DI didn't report manufacturing, order fulfillment, and shipping as fully restored until September 11. Even then, CEO Mike Mahoney said the company still needed “a better handle” on the financial impact.

Then on September 2, researchers at Cybernews published what they'd found on a criminal's exposed server. An AI agent had been running ransomware attacks against more than 30 companies at once, and the AI cost the attacker as little as $0.40 to $4.00 per company.

So the attacker spends a few dollars, and the company on the other end spends weeks getting back to normal. That lopsided math is why this matters to a 150-person business in Iowa, whether it's a plant, a co-op, a clinic, or a trucking company, not just to Coca-Cola.

 

How are hackers using AI in ransomware attacks?

Some ransomware crews now hand most of the work to an AI agent, which lets one person go after dozens of companies at a time for almost nothing.

The server Cybernews found belonged to an affiliate of a ransomware group called The Gentlemen. On it were 3.1 terabytes of stolen data from more than 30 companies, plus an AI agent and 86 AI-generated scripts. The victims ran the gamut: manufacturing, healthcare, transportation, real estate, consulting, software, telecommunications, and marketing. The researchers say the agent searched each victim's network, pulled out sensitive data, wrote custom scripts for each environment, and drafted the ransom demands. The person running it mostly handed it a target and a login.

By the researchers' count, “a single attack costs as low as $0.40-$4.00 in tokens per company, not counting the supporting infrastructure costs.”

AI is also shrinking the window between a software flaw going public and someone using it against you. The Food and Ag-ISAC's September threat report, as covered by Industrial Cyber, found that exploit code that once took days to develop can now be generated in hours.

And The Gentlemen aren't some small-time outfit. Black Kite Research Group's 2026 Manufacturing & Distribution Ransomware Report, published September 17, ranks them second among ransomware groups hitting manufacturers this year, with 142 victims from January through July. The Food and Ag-ISAC has them second in food and agriculture too, with 31 attacks through July.

 

Why do ransomware attackers target mid-sized businesses?

Because a mid-size company can't afford to be down, and usually doesn't have anyone watching its network around the clock. Manufacturing and food and agriculture have some of the clearest numbers on this, but the pattern holds well beyond them.

The 2026 Manufacturing & Distribution Ransomware Report counted 1,183 ransomware incidents against manufacturers in the first seven months of this year, up 39.7% from the same stretch in 2025. Among victims whose revenue was known, 70.2% brought in between $10 million and $100 million a year. The median victim made $42.9 million.

That isn't a list of household names. It's the family-owned fabricator down the road, the co-op that just merged with the one a county over, the regional distributor, and the trucking company with drivers spread across three states.

Food and ag is headed the same direction. The Food and Ag-ISAC counted 227 ransomware incidents against the sector through July, up 62% from 140 over the same period in 2025.

When an attack only costs a few dollars, the attacker doesn't need a big company. They need one that will pay to get running again. A feed mill in October, a plant behind on a big order, or a clinic that can't pull up patient records feels that pressure fast, and attackers know it.

 

How do ransomware attackers get into a network?

More often than people expect, they just log in.

The AI agent in the Cybernews case didn't start with some clever hack. It started with a web address, a username, and a password. The researchers say those credentials were likely obtained from stealer logs or purchased from initial access brokers.

Stealer logs come from infostealer malware. It gets onto a laptop, often a personal or contractor device, grabs saved passwords and login sessions, and ships them off to be sold. In the words of the Manufacturing & Distribution Ransomware Report, credentials leak continuously through infostealer infections on employee and contractor devices, and no patch cycle drains that pool.

It shows up in the victims, too. The share of manufacturing ransomware victims with stealer log findings at the time the attack was disclosed went from 25.0% in 2023 to 41.8% in 2026. Size doesn't protect you, either. Among manufacturers with more than $1 billion in revenue, the same report found 69.1% have employee or system credentials circulating in those markets.

Here's the part most security vendors won't lead with. You probably don't need another tool. You need someone watching for stolen passwords, someone awake when the alert fires at 2 a.m., and backups you know will restore. None of that means outspending an attacker.

We run into the same three gaps again and again:

  • Passwords nobody is watching. Your company's logins may already be for sale, and there's usually no way to tell from the inside. When someone finally uses one, it looks like a normal sign-in.
  • Alerts that come in after hours. Ransomware doesn't wait for Monday. If nobody's watching after 5, an attacker has all night, or all weekend, to work through your network.
  • Backups that have never been restored. Plenty of companies have backups. Fewer have actually restored from them. The morning after an attack is a bad time to find out which group you're in. The first real test shouldn't be the morning after an attack.

For a practical recovery planning guide, see Disaster Recovery Checklist for Manufacturers.

 

What should your business do about ransomware right now?

Start with the basics that keep a stolen password from turning into a shutdown. None of this is new, but it matters more now that testing your defenses costs an attacker next to nothing.

Find out if your passwords are already out there. Dark web monitoring watches for your company's credentials in breach dumps and stealer markets, so you can reset them before someone uses them. Pair it with security awareness training so your people can spot the phishing emails and fake downloads that plant this kind of malware in the first place. For more on that, read The Human Firewall.

Put multi-factor authentication on anything people log into from outside the building. Start with email and Microsoft 365, then remote access, file sharing, and the rest of your business apps. A stolen password is a lot less useful when it isn't the only thing standing in the way.

Have someone watching overnight. Managed detection and response keeps eyes on your network, endpoints, and Microsoft 365 around the clock. Through our partnership with Arctic Wolf, high and critical alerts trigger an immediate call to a Koltiv technician, day or night.

Know how many days you can go. Fairlife had inventory to cover eleven days. Sit down with your team and figure out what a week without the systems you run on would actually cost, whether that's your production system, your ERP, your dispatch software, or Agvance. Then test whether you can restore faster than that.

 

What about the AI tools your own team is using?

If someone steals a login, they get whatever that account can see. That includes what your AI tools can see, and AI makes digging through it fast.

In the Cybernews case, the AI agent didn't stop at encrypting files. It went through the stolen data, picked out what was sensitive, and put together pressure files on each victim. The less a single login can reach, the less there is to dig through.

So before you turn on Microsoft 365 Copilot or roll out another AI tool, it's worth a look under the hood: who can see what in SharePoint and OneDrive, whether sensitive files are labeled, and whether data loss prevention rules are in place to keep sensitive information from walking out through email or file sharing. For more on that risk, read Your Employees Are Already Using AI. Do You Know What They're Sharing?

Our AI Data Security Assessment covers exactly that. We review SharePoint permissions, sensitivity labels, data loss prevention, and conditional access, so you know what an AI tool, or someone with a stolen login, could get to. It's part of our AI Advisory Services, along with an AI governance framework that sets the rules for what data goes into the tools your team is already using.

 

Where does a partner fit?

You don't need to build a security department to handle this. You need someone paying attention to the things attackers are betting you'll miss.

That's the work we do for businesses across Iowa and the Midwest, with deep roots in manufacturing and agriculture. We start by finding out where you actually stand, then help close the gaps that matter most. Sometimes that's a cybersecurity risk assessment. Sometimes it's 24/7 managed detection and response, security awareness training, or a disaster recovery plan somebody has actually tested. Our ARMOR and FORTRESS managed IT packages include MDR, dark web monitoring, security awareness training, and data loss prevention for Microsoft 365.

You know your operation. We know this side of it. And if it turns out you're in better shape than you thought, we'll tell you that too.

 

Next steps

  • Start with where you stand. Our cybersecurity team will look at your environment and give you a clear, prioritized list of what to fix first.
  • Compare managed IT packages. See which tiers include MDR, dark web monitoring, security awareness training, and data loss prevention for Microsoft 365.
  • If you're already using AI tools, or planning to, start with an AI Data Security Assessment so you know what your data exposure looks like before an attacker, or an AI tool, finds it first.

The attacker's math is simple. A few dollars in AI and a stolen password, pointed at a company that can't afford to sit idle. Yours can be simple too. Watching for stolen logins, turning on MFA, and making sure somebody answers the 2 a.m. alert cost a lot less than eleven days shut down. October is a good month to run the numbers.

It's Cybersecurity Awareness Month, which makes it a good time to ask a few uncomfortable questions around the office: where your passwords might be, who's watching overnight, and how long you could really run without your systems. If the answers make you a little uneasy, you're in good company. That's usually where the useful conversations start. Give us a call and we'll work through it with you.

 

Sources

 

Ready to GET STARTED?

10 Ways Managed IT Security Cuts Downtime in 2026

9 min read

10 Ways Managed IT Security Cuts Downtime in 2026

WHAT THE RIGHT SECURITY PRACTICES ACTUALLY PREVENT, AND WHY THE PROVIDER BEHIND THEM MATTERS AS MUCH AS THE TECHNOLOGY. A production line going dark...

Read More
What Is Microsoft Copilot and Is It Right for My Business?

3 min read

What Is Microsoft Copilot and Is It Right for My Business?

THE POTENTIAL AND LIMITATIONS OF MICROSOFT AI The adoption of AI continues to accelerate across industries, including manufacturing. According to...

Read More
Copilot Training That Actually Sticks: Why Generic Demos Don't Work

2 min read

Copilot Training That Actually Sticks: Why Generic Demos Don't Work

GOOD IMPLEMENTATION VS. RUSHED ROLL OUT Imagine this scenario: A COO approves Microsoft Copilot licenses eager to unlock new productivity gains. The...

Read More
Meet the Team: Jacob Collinson

4 min read

Meet the Team: Jacob Collinson

Jacob Collinson has been at Koltiv for six years. He is our cybersecurity consultant and vCISO, which covers both the engineering side and the...

Read More