Skip to content
Skip to main content
Cyber Incidents & Offender Methods Investigation walkthrough

A cyber incident may be relevant to my investigation. What happens next?

A logistics company reports that dispatch files are being encrypted, staff cannot access delivery schedules and a ransom note has appeared on several systems. The incident is still developing. This walkthrough separates urgent harm reduction from evidential preservation, works below the security alerts to the source events and develops the account, session and device evidence towards a suspect.

The working principle
Protect people and systems while preserving the history needed to explain what happened. Containment, recovery and investigation are related tasks. Each can change the evidence, so the decisions and their timing must become part of the incident record.
Reported harm
Affected systems
Source events
Incident response
Account and session
Device evidence
Suspect

The incident can be established before the offender is known. Attribution develops by preserving and correlating what the affected systems, providers, responders and suspect devices independently recorded.

The incident report

Northway Logistics · incident INC-6207
First report06:42 on 21 July 2026: dispatch documents inaccessible.
Affected systemsFile server FILE-03, dispatch application and backup console.
Initial alertAL-88021: rapid file modifications under administrative session SES-4C18.
Immediate impactDelivery schedules unavailable; live operations moved to manual arrangements.

The security alert is a lead produced by a detection rule. An alert does not by itself prove an attack, while the inaccessible files, system events and ransom note provide direct evidence of disruption that must be explained.

Initial security extract
incident_id=INC-6207alert_id=AL-88021first_observed=2026-07-21T05:38:14Zhost=FILE-03session_id=SES-4C18event=RAPID_FILE_MODIFICATION
Established the named system recorded this activity against FILE-03 and session SES-4C18Still open the full incident scope, how the session was obtained and who controlled it
EstablishedNorthway's systems are suffering deliberate-looking file disruption with material operational impact.
Still openWhether data was also stolen, the initial access route, the complete affected estate and the person or group responsible.

Work the live incident

01 · Establish what is happening now

The incident is continuing on two network segments, but dispatch safety is maintained through manual procedures and the affected servers can be isolated.

Whether an incident is still happening determines the urgency and the evidence at risk. Record affected services, business impact, safety concerns, current sessions and the actions already taken. Assess continuing harm before treating preservation as a reason to leave damaging activity running.

Identify the system owner, incident lead, technical contacts and investigator. One person may perform several roles, but the decisions should remain clear. Specialist support is particularly important where live malware, encrypted systems, cloud accounts or business-critical services are involved.

Investigator action
Create one incident chronology recording what is affected, what harm is continuing, who controls each system, volatile evidence, every containment or recovery action, and the person responsible for each decision.

02 · Preserve what response activity may change

Endpoint telemetry, active-session details, authentication records, backup audit events, the ransom note and response communications are preserved before routine retention or containment removes context.

Evidence may disappear quickly through log rollover, session termination, volatile memory loss, provider retention or system rebuild. Immediate preservation should focus on relevant volatile and short-lived records, not indiscriminately copy every system.

Isolation and account revocation may be necessary. Record the source state and action first where safely possible, then document what changed. Containment can affect remote-session evidence, but that is a reason for coordination and recording - not for allowing harm to continue.

Priority preservation map
Identity serviceSES-4C18login, factor, token and session events
Endpoint platformFILE-03 / ADMIN-07process, file and remote-session telemetry
Backup serviceJOB-2218catalogue access, deletion attempt and account events
Response recordINC-6207alerts, decisions, chat, calls, containment and recovery
Preserve the source records behind screenshots and analyst summaries

03 · Go below the alert and ransom note

Authentication, remote-access, endpoint and backup events establish a coherent sequence before the first file-encryption alert.

Ask which underlying records support the alert. The alert explains why activity was noticed; source events describe what the systems recorded. The ransom note establishes a demand and may reveal wording or identifiers. A ransom note does not identify its author.

04:51:09 UTCDormant support account nv-support authenticates and creates session SES-4C18.
05:06:44 UTCSession accesses backup catalogue job JOB-2218.
05:21:17 UTCEndpoint ADMIN-07 begins remote administration of FILE-03.
05:38:14 UTCRapid file modifications begin; note NW-README-77 is created.
06:42 localDispatch team reports operational impact.

Ransomware may involve more than encryption. Here the source events support deliberate disruption and attempted backup interference. They do not yet prove data theft, and encryption does not establish exfiltration.

04 · Reconstruct access, control and purpose

The active session uses a support account assigned to former contractor Nora Bell and connects through a device not enrolled to Northway.

The account was left active after Nora's contract ended. That is a control failure and a strong line of enquiry, not proof that Nora used it. A successful login does not prove the password was known; stolen sessions or credentials remain possible.

Identity records show a fresh authentication rather than a reused Northway session. Remote-access logs associate it with browser instance BR-8824 and source address 198.51.100.143. Relevant-time subscriber records resolve the connection to Nora's home service. An address identifies a connection, not the person at the keyboard, but it independently aligns the account, time and access route.

Endpoint events record the same session viewing backup status, accessing selected dispatch shares and creating the ransom note. Evidence showing the sequence of a ransomware incident and deliberate disruption is stronger than the generic label “ransomware attack”.

EstablishedSupport account nv-support, session SES-4C18 and browser BR-8824 carried the recorded access and disruption sequence.
Still openWho controlled the session, how the credentials were obtained and whether another person directed or assisted the activity.

05 · Join the incident to suspect evidence

A laptop lawfully recovered from Nora contains the relevant browser profile, remote-access records and a draft matching the ransom note's distinctive wording.

The browser profile records session SES-4C18 and access to Northway's support portal. Local remote-client history identifies ADMIN-07. A text file predating the incident contains the unusual phrase and payment reference used in note NW-README-77. Messages with an associate discuss Northway's backup arrangements and a share of any payment, without containing technical instructions.

No single fact carries the attribution. Assigned account, fresh authentication, relevant-time home connection, matching browser and remote-client records, distinctive note material and communications independently converge on Nora. This is strong circumstantial evidence, while the associate's role and any alternative access remain testable propositions. Ransomware attribution should distinguish incident facts, infrastructure or tooling similarities and evidence linking human actors.

EstablishedNorthway, provider and recovered-device evidence converges on Nora-associated control of the account, session and material used in the disruption.
Still openNora's explanation, the associate's participation, whether data left the network and the full intended financial or disruptive purpose.

Where this leaves the investigation

IncidentSource events establish file encryption, attempted backup interference and operational disruption.
Response historyPreservation, containment and recovery actions are retained within one chronology.
Primary suspectAccount, connection, session and recovered-device evidence provides a strong route to Nora Bell.
Further line of enquiryTest Nora's account, the associate's role and any evidence of completed data theft separately from the proven disruption.
Operational takeaway
Incident response preserves the business; disciplined recording preserves the case. Establish current harm, protect volatile source records, document every response action and build attribution through independent account, session, provider and device evidence.
Reference: CIM-000Cyber Incidents & Offender Methods