Hunted Before You Know It: The Quiet Warning Signs That Criminals Are Targeting You for Ransomware
Ransomware has a reputation for appearing without warning—one moment your files are accessible, the next they are encrypted and a demand for payment in cryptocurrency fills your screen. That narrative, while emotionally accurate for victims, misrepresents the mechanics of how most ransomware attacks actually unfold. The encryption event that destroys access to your data is rarely the beginning of the criminal's work. It is closer to the end.
Between the moment a criminal selects a target and the moment they execute their payload, there is a reconnaissance phase. It may last hours. More often it lasts days or weeks. During that window, the attacker is mapping your network, testing your defenses, identifying your most valuable data, and positioning themselves for maximum impact. That window is also your best opportunity to detect and disrupt the attack before it causes irreversible harm.
Understanding what that reconnaissance looks like—and knowing where to look for its traces—is one of the most practical security skills an American household or small business owner can develop.
How Criminals Choose Their Targets
The selection process for ransomware targets operates on two distinct levels. The first is opportunistic and largely automated. Criminal groups run continuous scans across millions of IP addresses, probing for known vulnerabilities in exposed services, outdated software, and misconfigured systems. If your network or devices match a vulnerability profile they are actively exploiting, you may be targeted without anyone ever making a deliberate decision to come after you specifically.
The second level is more deliberate and is increasingly common in attacks on small businesses. A criminal group identifies an organization or household of interest—perhaps through a data breach that exposed email addresses and employment information—and begins a targeted campaign. This type of attack involves more sophisticated reconnaissance and tends to be more damaging when it ultimately executes.
Both pathways leave traces. The difference is that automated opportunistic probing leaves more generic traces, while targeted attacks may produce more specific and interpretable signals.
Failed Login Attempts: The Most Visible Warning Sign
Among the most commonly overlooked early indicators of ransomware reconnaissance is a pattern of failed login attempts across your accounts and devices. Criminals conducting credential-based attacks—attempting to gain access by testing username and password combinations harvested from previous data breaches—generate failed authentication events at a rate that should be conspicuous if you are watching for it.
For individual users, this manifests as security emails from your accounts reporting failed sign-in attempts from unfamiliar locations, often at unusual hours. Many Americans dismiss these notifications as routine noise. They are not. A cluster of failed login attempts from foreign IP addresses, particularly against accounts associated with financial services, cloud storage, or email, is a meaningful signal that someone is actively attempting to establish a foothold.
For small business owners, failed login attempts against remote desktop services, VPN gateways, and administrative portals are among the most reliable early indicators that a targeted reconnaissance campaign is underway. Remote Desktop Protocol, in particular, has been the entry vector for a significant proportion of ransomware attacks against small American businesses over the past several years.
Unusual Network Activity at Unusual Hours
Ransomware operators—particularly those targeting small businesses—have a well-documented preference for executing their final payload during off-hours, typically late at night or over weekends. The logic is straightforward: fewer people are watching, and the encryption process can complete before anyone notices.
What this preference also means is that the reconnaissance phase, during which the attacker is exploring your network and staging their tools, frequently generates network activity during those same off-hours. A router or network monitoring tool that logs outbound connection attempts, data transfers, or internal scanning activity between midnight and five in the morning—particularly to IP addresses in unfamiliar geographic locations—warrants immediate investigation.
Home users with access to their router's traffic logs should make a habit of occasional review. Small business owners should have logging configured as a baseline practice and should treat unexplained late-night traffic spikes as a serious concern rather than a curiosity.
Unfamiliar Processes and Disabled Security Tools
One of the more alarming reconnaissance behaviors that precedes ransomware deployment is the deliberate disabling or degradation of security software. Ransomware operators understand that active antivirus and endpoint protection solutions will flag their payload. A common preparatory step is to attempt to disable or circumvent those tools before executing the encryption.
If your security software begins generating warnings about attempted tampering, if it unexpectedly enters a degraded state, or if you notice that features you rely on appear to have been disabled without your action, treat this as an emergency signal. Legitimate software does not disable your security tools. An attacker who has gained some level of access to your system very often does.
Similarly, the appearance of unfamiliar processes in your system's task manager—particularly processes that consume significant CPU or network resources and cannot be readily identified—may indicate that reconnaissance or staging tools have already been installed.
External Reconnaissance You Might Actually See
Some reconnaissance activity happens at a level visible to ordinary users. Spear-phishing emails—highly targeted messages that reference specific personal details, your employer, your recent purchases, or your family members—indicate that someone has compiled a profile of you prior to making contact. These are not the generic scam emails that filter systems catch easily. They are customized, plausible, and designed to earn your trust.
Receiving one or two such emails in close succession, particularly if they request credential verification or ask you to open an attachment, should be treated as evidence that you are the subject of a targeted campaign rather than a random recipient of mass spam.
What to Do When You Spot These Signals
Recognizing reconnaissance activity is only valuable if it triggers an appropriate response. At the household level, that response should include immediately changing passwords on any accounts that have received failed login notifications, enabling multi-factor authentication on all accounts that support it, and running a full scan with a current, reputable security solution.
At the small business level, the response should escalate further: isolating any systems that have displayed anomalous behavior, reviewing access logs for evidence of unauthorized entry, and engaging a security professional if the scope of the activity is unclear.
Norton's real-time threat monitoring capabilities are specifically designed to surface the kind of anomalous activity that precedes ransomware deployment—unusual process behavior, suspicious network connections, and attempts to modify or disable security functions. Automated detection does not replace the value of an informed user who knows what signals to watch for, but the two working together represent a substantially stronger defensive posture than either alone.
The criminals running ransomware campaigns are patient and methodical. Meeting that patience with informed vigilance is the most effective counter-strategy available.