Ransomware does not start with encrypted files. It starts weeks earlier, with an attacker quietly inside your network, mapping systems, stealing credentials, identifying backup locations, and preparing for maximum impact. According to Mandiant’s M-Trends report, attackers are often inside networks for over two weeks before being detected, long before ransomware is deployed.
Recognizing the early indicators of a breach gives your team the window to respond before encryption occurs. If you are already past that point, DCG’s 24/7 incident response team can contain and recover, but this guide is about catching it before it gets there.

Unusual Network Traffic Is the Most Overlooked Early Warning Sign in California Organizations
Outbound Spikes
A sudden increase in outbound traffic, particularly to unfamiliar IP addresses or cloud storage endpoints, is one of the clearest indicators of data exfiltration in progress. Attackers transfer stolen data before deploying ransomware, and that transfer generates volume. Most organizations do not have baseline traffic profiles to detect this anomaly.
Off-Hours Activity
Network activity at 2 AM on a server that is normally idle is not coincidence. Attackers deliberately operate during off-hours when security teams are understaffed and automated alerts go unreviewed. Any significant after-hours network activity on normally quiet systems warrants investigation.
Internal Lateral Movement
Legitimate users access the systems they need to do their jobs. When a standard workstation starts connecting to servers it has never touched before, or when a user account generates authentication attempts across multiple systems in rapid succession, the pattern suggests compromised credentials being used to map the environment.
How do you distinguish normal network activity from attacker reconnaissance when the traffic looks legitimate? A structured approach like how to build an effective incident response plan template helps define what normal vs suspicious behavior looks like.
Unknown Admin Accounts Appearing on Your Network Is a Breach Signal, Not a Configuration Error
Ghost Accounts
Attackers create new administrative accounts to maintain persistent access even after their initial entry point is discovered and closed. These accounts are designed to look legitimate, generic names, plausible creation timestamps, but they have no corresponding HR record or IT ticket. A regular audit of privileged accounts that compares current state against provisioning records catches this.
Privilege Escalation
A standard user account that suddenly has domain admin privileges has either been compromised or is the result of a misconfiguration. Both require immediate investigation. Most organizations do not have alerts configured for privilege escalation events, they are sitting in log files no one reviews.
Dormant Account Activity
Accounts belonging to former employees, service accounts attached to decommissioned applications, and test accounts that were never disabled represent low-hanging fruit for attackers. When these accounts show authentication events, the cause is almost never benign.
System Lockouts and Authentication Failures Are Rarely Just User Error
Credential Stuffing Patterns
A wave of account lockouts across multiple users in a short time window indicates either a credential stuffing attack using a breached password list or an attacker actively testing compromised credentials. Either scenario requires investigation, the pattern does not appear in normal usage.
MFA Fatigue
Attackers have refined techniques for bypassing multi-factor authentication, including flooding users with push notifications until one is accidentally approved, and exploiting MFA vulnerabilities in legacy protocols. If users are reporting unexpected authentication prompts they did not initiate, treat it as an active attack indicator.
If a user approves an MFA push they did not expect, has the network already been compromised?
Data Transfers to Unknown Locations Are Not a Misconfiguration; They Are Exfiltration
Cloud Storage Destinations
Megabytes or gigabytes moving to cloud storage endpoints outside your approved vendor list, Mega, anonymous S3 buckets, unfamiliar FTP destinations, indicate data staging for exfiltration. Attackers often compress and encrypt data before transfer, so deep packet inspection is required to identify the content, but volume analysis alone can flag the behavior.
Compressed Archive Creation
Unusual creation of large .zip, .7z, or .rar files on servers that do not normally generate archives is a staging indicator. Forensic tools that track file system activity can identify when and where these archives were created, and sometimes where they were sent. A complete digital forensics investigation process explained can uncover how attackers staged and moved this data.
Unexplained Software and Process Activity Points to Active Attacker Tooling
Remote Access Tools
Legitimate remote access software, AnyDesk, TeamViewer, ScreenConnect, appearing on systems where IT never installed them is a serious red flag. Attackers frequently install legitimate remote administration tools to maintain access while evading endpoint detection tools that flag known malware but trust commercial remote access software.
Disabled Security Tools
Antivirus silently disabled. Endpoint detection alerts stopped generating. Firewall rules changed without a corresponding change ticket. Attackers disable security tooling before deploying ransomware, and these changes often go unnoticed because the tools themselves stop reporting once disabled.
Ransomware Notes Before Encryption
Some ransomware operators drop readme files or text notes containing ransom demands in advance of or during the encryption process. Discovering these files, even before any systems appear encrypted, means the attack is already in progress. This is an immediate containment situation.
If you are seeing any of these indicators, the right response is containment first and investigation immediately after. Our step-by-step ransomware response guide walks through what to do in the first 24 hours.
Understanding which threat actors operate these techniques, and how they move through networks, is covered in our guide to active ransomware threat actors.
FAQs: Network Breach Indicators
How quickly should we act on a suspected breach indicator?
Immediately. Every hour of delay after an initial indicator is observed is additional time the attacker has to move laterally, exfiltrate data, or prepare for ransomware deployment.
Can we investigate a breach internally without outside help?
Basic triage is possible, but forensic investigation requires specialized tooling and methodology. Improper handling of infected systems destroys evidence and can trigger additional encryption activity.
What logs should we check first when investigating unusual activity?
Start with authentication logs (Windows Event ID 4624, 4625, 4672), firewall traffic logs for unusual outbound destinations, and endpoint detection alerts. These three sources surface the most common attacker behaviors fastest.
Is it possible to have been breached without any visible symptoms?
Yes. Sophisticated attackers operate specifically to avoid triggering visible symptoms during the reconnaissance phase. Regular proactive threat hunting, not just reactive monitoring, is required to catch them.
What is the first call we should make if we suspect a breach?
Your incident response provider or managed security partner. After that call, contact your cyber insurance carrier and legal counsel, in that order.
If any of these indicators match what you are seeing in your environment, do not wait. The window to contain a breach before it becomes a ransomware event is narrow. DCG’s incident response team is available 24/7 to assess, contain, and investigate. Contact us to speak with a specialist today.







































