Services Who We Are Resources Success Stories Contact Speak to a consultant
Case study

Buried Skeletons

How a preventable ransomware attack ended a pharmaceutical distributor. Based on a real Cyber Armed Security engagement.

Case summary
Ransomware/ Pharmaceutical Distributor/ Christmas Period
The context

A free review, and a clear warning

We gave a mid-sized UK pharmaceutical distributor a complimentary Open-Source Intelligence (OSINT) review, the same passive, non-intrusive assessment we use to show organisations their real exposure.

The findings were significant. Exposed credentials, unsecured infrastructure, and a public digital footprint that would give a real attacker more than enough to plan an intrusion. We shared this openly: this organisation had the profile of an active, realistic ransomware target.

The decision

The proposal was declined

We proposed a full penetration test and remediation programme to close the gaps we had found, and briefed the executive team on why it mattered. After consideration, the decision was made not to proceed.

Part of that briefing included a detail specific to the time of year: attackers often target the Christmas period deliberately, knowing that reduced staffing and slower monitoring give them more room to operate undetected. We raised this as a realistic possibility worth planning around.

"We shared what we'd found, what it would take to fix, and why timing mattered. The business chose to hold off."

The timeline

From free review to closed doors

01

Initial engagement

We deliver a free OSINT review, identify serious exposure, and brief leadership directly on the risk.

02

Proposal declined

We propose a full penetration test and remediation plan, including a note on the added risk around the Christmas period. The organisation decides not to proceed at that time.

03

Christmas period

The organisation is hit by a ransomware attack while staffing and monitoring are at their lowest. Systems are encrypted and operations grind to a halt.

04

The aftermath

They come back to us to help contain and respond. Alongside the ransom demand itself, regulatory penalties for the resulting data exposure add significantly to the financial impact.

05

The outcome

The combined weight of the ransom, recovery costs, and regulatory fines proves unrecoverable. The business ceases to operate.

This wasn't a story about being caught out by the unknown. The exposure had been identified, the fix had been costed, and the timing risk had been discussed.

Why attackers wait for holidays

This wasn't a one-off. It's the pattern.

Ransomware groups deliberately target the periods when defenders are stretched thinnest. Industry-wide data shows just how consistent that pattern is.

52%

of ransomware attacks in the past year struck on a weekend or holiday, when offices are running skeleton crews.

78%

of organisations cut security operations staffing by half or more during these exact windows.

6%

eliminate security monitoring entirely over holidays and weekends, no one watching at all.

60%

of attacks follow a period of organisational disruption, a merger, acquisition, or round of layoffs, where focus is already elsewhere.

Why defenders stand down
Work/life balance for staff62%
Business closed for the holiday47%
Didn't think they'd be targeted29%
Source: Semperis, 2025 Ransomware Holiday Risk Report (1,500 IT and security professionals, 10 countries). The pharmaceutical distributor in this case study fit the pattern exactly, the warning was given, the timing risk was named, and the attack landed on schedule.
What this case shows

Knowing is not the same as closing

Most organisations that suffer a serious incident are not oblivious. Somewhere in the business, the risk was known. What separates outcomes is whether the gap between knowing and closing was ever actually crossed.

Reconnaissance is cheap

An attacker can profile your organisation from public data alone, without touching a single system. That work costs them almost nothing.

Timing is deliberate

Holidays and shutdown periods are chosen on purpose, because reduced staffing means longer dwell time before anyone notices.

The cost compounds

The ransom is rarely the whole bill. Recovery, downtime and regulatory penalties for exposed data stack on top of it.

Get in touch

Find out what's already exposed

An OSINT review is passive, needs no access to your systems, and turns around in seven days. It's the simplest place to start.

Book a scoping call with our team

Tell us your domain, and we'll show you what's already public.

+44 20 7862 3837 [email protected] cyberarmedsecurity.com