Security · · 8 min read
It's beginning to look a lot like attack season.
Ransomware crews plan around your holidays: thin staff, frozen changes, a full inbox. Why your quietest fortnight is their busiest, and the ten weeks of work that make it boring again.
By Precision Code Studios, Engineering team
Picture a Sunday, two days after Christmas, at 02:40. An alert lands in a shared channel: a new account has just been added to the domain administrators group, the people who can change anything on the network. The engineer on call is asleep at a relative's house with the phone on silent. The person who could authorise pulling the VPN offline is on a plane. Someone reads the alert on Monday morning, by which time the backups have been deleted and the file servers are encrypted. The scene is invented, but nothing in it is unusual. Nobody did anything wrong. They were on holiday, and someone had planned for that.
The planning is the point. According to the Sophos 2026 Active Adversary Report, which analysed 661 incident response and managed detection cases handled between November 2024 and October 2025, 88% of ransomware payloads were deployed outside business hours, and 79% of data theft happened off-hours too. Ransomware crews work nights, weekends and holidays for the simplest reason there is: you do not.
If you run engineering or security, it is October and December still feels far away. Next year's budget is being argued over, the change freeze is a date in somebody's calendar, and the penetration test that was pencilled in for the third quarter has quietly slipped. That slip matters more than it looks, because how your holidays go is decided in the next ten weeks.
Why your quietest fortnight is their busiest
Every intrusion is a race between how fast an attacker moves and how fast you notice and act. Holidays change only one side of that race: yours, in several separate ways that stack on top of each other.
- Fewer eyes. In the Semperis 2025 Holiday Ransomware Risk Report, a survey of organisations in ten countries, 78% of those with a security operations centre said they cut its staffing by half or more over holidays and weekends, and of the organisations that had suffered a ransomware attack, 52% said it came on a weekend or holiday.
- Fewer hands. The change freeze, sensible in itself, means a fix that would ship in an afternoon in October waits until January unless someone has already agreed how to break the rule.
- Fewer deciders. The people who can approve taking a customer-facing system offline, calling in an incident response firm or notifying a regulator are exactly the people most likely to be unreachable.
- A noisier inbox. Delivery notices, gift-card requests, year-end invoices and payroll changes are all normal in December, which makes them perfect cover. Darktrace reported a 620% rise in Black Friday-themed phishing in the weeks before Black Friday 2025.
None of this is a new discovery. In August 2021 the FBI and CISA, the US government's cybersecurity agency, published a joint advisory after observing an increase in high-impact ransomware attacks on holidays and weekends. That was the year the Colonial Pipeline attack fell on Mother's Day weekend and the Kaseya attack on the weekend before Independence Day. The pattern has held since. What has changed is the speed.
The break-in usually starts before the break
The same Sophos report found that median dwell time, the gap between an attacker getting in and being caught, had fallen to three days, and that once inside, attackers reached the Active Directory server, the system that decides who can log in to what, in 3.4 hours. Work backwards from an encryption on the 26th and the door was plausibly opened during the last working week.
That week has its own texture. People are clearing their desks and approving things quickly so they can leave. Contractors are rolling off. The help desk is fielding calls from people who say they have a new phone and need their multi-factor authentication reset before they fly. Each request is ordinary. One of them may not be.
So the last working week deserves more attention than the holiday itself. Watch for new administrator accounts, authentication resets, newly registered devices, remote logins from unfamiliar places and mailbox rules that forward mail outside the company. And write one rule this autumn, if you write no other: the help desk never resets a password or a second factor on the strength of a phone call, only after calling back a number it already holds.
Freeze the changes, not the fixes
A change freeze is good engineering. Releasing new features into a skeleton crew is how a quiet week becomes a long one. The trouble is that most freezes are written as a ban with no exit, and the first time anyone discovers that is when a critical vulnerability in something internet-facing is published on 18 December.
Write the exception now, while everyone is in the office to argue about it. Decide what qualifies: an actively exploited flaw in a system reachable from the internet, or an action needed to contain an incident. Name two people who can approve it and who have agreed to stay reachable. Agree the minimum testing and the rollback. Then rehearse it once in November with a harmless change, so the first use of the process is not also the first test of it. The aim is a one-hour decision rather than a fortnight's debate by message.
When a penetration test helps, and when it is too late
A penetration test is worth exactly what you fix afterwards. That makes timing the whole question in autumn. A report that arrives in mid-December is a written list of open doors that you will carry, knowingly, through the holidays. It also lands on a team that is about to go away, which is the worst moment to start triage.
Sometimes the honest answer is that you do not need one. If your last test was recent and nothing material has changed since (no new product, no move to a different cloud, no acquisition, no new AI feature facing customers), the better use of the next ten weeks is closing the findings you already have and practising your response. If the report could land with three weeks to spare before the freeze, test properly and keep time for a retest. If only some fixes would fit, narrow the scope to what an attacker reaches first: the systems facing the internet, and what a stolen password opens.
Our tests use a swarm of AI agents, directed by our security specialists, to attack code, networks and infrastructure the way a real adversary would, and then show exactly what to fix. Before the holidays, two parts of that matter most. The attacker's view of what is reachable from outside is the view that counts at 02:40 on a Sunday. And running the same attacks again after the fixes is how you learn whether they hold, before you are relying on them.
The ten weeks, in order
Plan backwards from the day the freeze starts. For most companies the work falls into this order.
- Mid-October: decide the scope. Pick the systems where a breach would hurt most and those an outsider can reach. If you are testing, book it this month.
- Late October to mid-November: test. Test while the people who will fix the findings are still available to ask questions about them.
- Mid-November to early December: fix and retest. Fix what is reachable from outside first, then rerun the attacks that found it. A finding is closed when the retest says so, not when the ticket does.
- Before the freeze: restore something for real. Pick an important system and bring it back from backup into a clean environment. Time it. Many teams discover here that the backups sit inside the same blast radius as the data, reachable with the same admin account.
- Before the freeze: clean up identity. Disable the accounts of leavers and of contractors whose engagements end in December. Review who holds administrator rights and why.
- Before the freeze: write the holiday runbook. Who is on call, how to reach them by phone, who can approve what, the number for your incident response firm and your insurer's incident line. Print it. The wiki may be on the system that is down.
- The last working week: brief people, then watch. Five minutes on the lures of the season, especially urgent requests for gift cards and changes to a supplier's bank details before the year-end payment run.
Leave the holidays alone
The Semperis report found that the most common reason organisations gave for cutting security staff over holidays and weekends was work-life balance. That is the right instinct. Cancelling leave buys a tired team in December and a resentful one in January, and it does not fix the real problem, which is that too many decisions need a senior person awake.
Reduce those decisions instead. Give whoever is on call written permission to disable any account, isolate any laptop or server and take a non-critical service offline without asking first, and promise in advance that nobody will be blamed for doing it on a false alarm. If you pay a managed detection provider, ask them in writing what coverage they run on 25 December and whom they will call at your company. The name on their list may belong to someone who left in June.
The best possible 27 December is one nobody remembers. That sort of boring is built in October, by people who are still at their desks.
The short film: transcript
Attackers plan around your holidays: the short version (1:26)
The fortnight when your team finally rests is the one ransomware crews have been waiting for all year. Here's why, and what to do while there's still time.
Ransomware crews keep the opposite hours to the people defending against them. Fewer people watching means a slower response, and every hour of delay is another hour to reach the backups.
In one survey by Semperis, more than three quarters of companies with a security operations centre halved its staffing over holidays and weekends. Add a change freeze, and an afternoon's patch waits until January.
Think about that last week before the break: desks being cleared, approvals rushed, someone ringing the help desk for an urgent login reset before their flight. It's an easy week to open a door in.
A penetration test is only worth the fixes that follow it. Book it in October, close what's reachable from the internet first, then run the same attacks again to prove the repairs actually hold.
Don't cancel anyone's holiday. Shrink the number of decisions that need a senior person awake, and promise in advance that nobody gets blamed for acting on a false alarm.
One job for this week: name the two people who may approve an emergency patch during the freeze, and get both to promise they'll answer the phone.
Read the full article at Precision Code Studios.