Ransomware stopped before a single file was encrypted.
A regional healthcare practice retained SignalPoint for managed EDR following their cyber insurance renewal. Eleven weeks into the engagement, our analysts detected and contained a Rhysida ransomware pre-execution event at 2:47am on a Sunday — before a single file was touched.
The incident
At 2:47am on a Sunday, SignalPoint's EDR platform flagged anomalous PowerShell execution on a clinical server — a living-off-the-land (LOTL) technique consistent with ransomware staging. An analyst began triage immediately.
Within 8 minutes, the analyst confirmed a true positive — Rhysida ransomware staging via a scheduled task created through a compromised service account. The endpoint was isolated from the network before the payload executed. No files were encrypted. No patient data was exfiltrated.
Root cause
A phishing email had compromised a billing coordinator's credentials three days earlier. The attacker established persistence via a WMI event subscription, then moved laterally using the stolen credentials before deploying the ransomware staging toolkit. The attack was entirely fileless until the staging phase.
Outcome
The practice continued operating normally through the Monday morning shift. Staff were unaware an attack had occurred until the Monday morning briefing. The compromised credential was revoked, the WMI subscription removed, and a root cause report delivered within 24 hours — with regulatory notification guidance for HIPAA breach assessment (no notification was required, as no PHI was accessed).
Want this level of protection for your business? SignalPoint provides the same 24/7 managed EDR and threat hunting to businesses across Chattanooga and the Tennessee Valley — starting at a price point built for SMBs.
Book a free 30-minute consultation