Most visitors decide in 5 seconds whether they understand what you do. Ours is a free, no-pressure look at your site.

Insider ThreatRansomwareCyber Forensics

When Your IT Provider Is the Attacker

Patryk Stanczak, Founder & CEOMarch 5, 20267 min read
GH

Geek Heros War Stories

The Call No One Expects

Imagine getting a call on a Monday morning that your domain controller and SQL server are encrypted. Ransomware. Every file locked, every service down, attorneys unable to access case files, email, or billing systems. That's terrifying enough. Now imagine learning that the person who deployed the ransomware was an employee of your own IT provider.

That's exactly what happened to a professional services firm we were called in to assist. The firm had been using an outside IT company for years — a local operation with a decent reputation. The relationship seemed fine. Response times were adequate, systems mostly stayed up, and the monthly invoices were paid without much scrutiny.

Then everything went dark.

What the Forensic Investigation Found

When we were brought in to conduct the forensic analysis, the evidence trail was remarkably clear — because the attacker made mistakes. The ransomware executable was still present on the domain controller. Login records showed the exact account used to deploy it — an administrative credential belonging to a technician at the IT provider. Timestamps on the login matched the encryption event precisely.

The attacker had used legitimate remote management tools — the same tools the IT company used for daily support — to access the server, upload the payload, and execute it. From a network perspective, it looked like a routine maintenance session. No alarms were triggered because the access came from a trusted source using trusted credentials.

What the attacker forgot to do was clean up. The executable wasn't removed. The event logs weren't wiped. The RDP session records were intact. Every breadcrumb pointed directly back to the IT provider's infrastructure.

The Aftermath

We compiled a comprehensive forensic report documenting every artifact: login timestamps, file creation records, network connection logs, and the ransomware binary itself. This report was delivered to the firm's attorneys and subsequently submitted to the FBI Cyber Crimes Division.

The situation was made even more extraordinary by the fact that the owner of the IT company was a sitting city official — a public figure with significant local influence. The investigation created ripples well beyond the immediate incident.

Meanwhile, the firm needed to get back online. We rebuilt their infrastructure from the ground up — new virtual machines, clean Active Directory, restored data from the most recent verified backup. The firm was operational within 72 hours, but the trust damage was permanent.

What This Means for Your Firm

This incident illustrates the most dangerous blind spot in IT security: the people you trust with your keys. Your IT provider has administrative access to every system in your environment. They can read your email, access your files, modify your backups, and control your security tools. If that access is abused, the damage is catastrophic — and it bypasses every security control you have in place.

Here's what every firm handling sensitive client data should demand from their IT provider:

- Background checks on all technicians with access to your systems - Named account access — no shared admin credentials - Session logging on all remote access to your environment - Credential separation — your provider should not be the only party holding admin passwords - Regular access audits — who accessed what, when, and why

Your IT provider should welcome this scrutiny. If they resist transparency about who has access to your systems and how that access is monitored, that resistance is itself a red flag.

> 📋 Read the full case study → [View the Insider Threat Forensics case study](#case-studies)

The most sophisticated firewall in the world won't protect you from someone who already has the keys. Vet your IT provider like you'd vet anyone with access to your clients' most sensitive information — because that's exactly what they have.

Ready to evaluate your IT provider relationship? [Take our free site audit](#assessment) and we'll help you identify the risks you can't afford to ignore.

Get Your Free Site Audit

Find out where your firm stands on security, compliance, and IT performance — at no cost.

Related Articles

Ready to see where your brand stands?