Our client is a mid-size public university located in the Midwest, serving thousands of students across multiple campuses. Like many higher education institutions, it operates a complex, sprawling IT environment: a mix of on-premises servers, cloud storage, third-party vendors for printing and offsite backups, and a large user base with varying levels of technical sophistication.
Universities are disproportionately targeted by ransomware actors. They hold sensitive student data protected under FERPA, operate with limited IT security budgets relative to their surface area, and face immense pressure to keep academic operations running continuously, making them attractive targets and likely to pay quickly.
The attack did not announce itself. It waited.
The university's offsite cloud storage vendor (responsible for housing the organization's backup data) was hit by a ransomware attack. The vendor failed to notify the university for an entire month. During that window, threat actors quietly mapped the connection between the vendor and the university's internal network. A jump box used to bridge the two environments had been compromised, and Sentinel One (the endpoint detection tool running on that node) was silently disabled.
On a Friday evening, university IT staff noticed databases behaving strangely and backups failing. They assumed a routine technical issue and began troubleshooting.
By Monday morning, the situation had escalated dramatically:
On Tuesday, the first ransom email arrived, but it was buried in an overwhelmed inbox and went unread. IT staff were still treating this as a performance problem, not a security incident.
By Wednesday, the reality was unavoidable:
No single failure caused this incident. It was the intersection of several common, preventable gaps:
Tenfold Security was engaged Wednesday: the day of full network failure. Within hours, our team had a structured plan of action in place.
Our first priority was situational awareness. We created "swim lanes" (a parallel workstream model that allowed different response teams to work simultaneously on network analysis, device triage, forensics, and communication), rather than working sequentially through a crisis.
We immediately deployed Sentinel One and Velociraptor across all university devices. Sentinel One provided real-time endpoint detection and response; Velociraptor allowed us to perform rapid forensic collection and hunt for persistence mechanisms (techniques threat actors use to maintain long-term, uninterrupted access) across the environment, even with the network degraded.
With endpoints deployed, our team worked to identify every compromised device, isolate active threats, and begin clean restoration. Our key actions included:
By Saturday (five days after engagement) all devices were clean and the network was fully restored. The university's student registration process, a critical operational event, proceeded without disruption the following Monday.
Unlike generic incident response firms that deploy off-the-shelf playbooks, Tenfold Security's approach was methodical and environment-specific. We built the response around the university's actual infrastructure, vendor relationships, and operational priorities—not a generic template.
Tenfold Security restored a fully encrypted, fully offline university network in five days. Fast enought to protect one of the most operationally critical events on the academic calendar: student registration.
But the more significant result is what has happened since. In the 3.75 years following the incident, the university has experienced zero ransomware recurrence and zero breaches. That outcome is not accidental, and is the direct result of the systematic remediation and security program improvements implemented following the response.
Post-incident, Tenfold Security worked with the university to address every root cause identified:
Ransomware doesn't discriminate by size or sector. If your organization has open vendor access paths, incomplete MFA coverage, or untested backup procedures, you share the same risk profile this university had before the attack.
The difference between a five-day recovery and a five-month nightmare comes down to preparation and the team you call on Day 1.
Tenfold Security provides:
Contact us today to see how we can help your organization reduce risk and stay ahead of threats.