Warning signs include rapid movement through file shares, unusual access to employee records or booking systems, mass archive creation, and signs that sensitive information was staged for theft before encryption. If attackers comment on the network being disorganised or stop short of further damage, that usually means they have already located useful data and assessed the environment’s weak points.
What the warning signs usually look like before encryption starts
The clearest indicators are operational, not theatrical. Attackers who have found valuable data usually spend time mapping file shares, opening employee records, exploring booking or finance systems, and staging archives for later theft. Those behaviours show they are learning where the sensitive material lives and which paths let them move quietly before they launch encryption or extortion.
A useful way to read the activity is by sequence. First comes discovery, then broad but selective access, then collection and staging. When that pattern appears, the network is no longer just under intrusion, it is already being used to assess what can be monetised. That is why rapid movement across shares and unusual access to high-value business systems matter more than a single noisy alert.
In practice, the most important clue is that the attacker’s behaviour becomes purposeful. They are no longer testing random systems, they are choosing systems that likely contain personal records, payment-related information, operational documents, or other data that would increase leverage in an extortion event. That change in focus is often visible before the encryption phase begins.
What attacker behaviour suggests they have already found something worth stealing
Mass archive creation, bulk file copying, and compressed staging folders are strong signals because they usually indicate preparation for exfiltration. When those actions appear alongside remote admin use, credentialed access from unusual hosts, or movement through systems that normally see little cross-user traffic, the attacker is likely collecting material they have already identified as valuable.
Another sign is selective disruption. If the intruder starts to comment on the environment being disorganised, pauses, or stops short of further damage, that often suggests they have already seen enough to know the organisation is vulnerable and that the data set is worth extorting. The attacker may not need to destroy everything immediately if they already have leverage from what they found.
That is why the question is not simply, “Is the network noisy?” It is whether the activity shows judgement about which systems, folders, or users matter. Once the adversary begins separating high-value data from ordinary activity, the incident has shifted from access to exploitation planning.
What defenders should conclude from staging, focus, and restraint
When the pattern includes discovery, staging, and restraint, the safest assumption is that the attacker has already located usable data and is deciding how to maximise pressure. That means the response should treat confidentiality exposure as likely, not hypothetical. The presence of encryption later does not erase the earlier signs of data discovery, and waiting for file damage can be too late to limit exfiltration impact.
This is also why “they did not finish the job” is not reassuring. A group may hold back on immediate destructive action because it already has enough leverage from the material it found, or because it is preserving access for a second phase. Either way, the organisation should assume the adversary has learned which systems matter and has begun shaping the extortion playbook around them.
Risk and Threat Considerations
Once ransomware operators have identified valuable data, the risk shifts from encryption alone to double extortion, targeted pressure, and longer dwell time. The same access that enables file staging can also expose employee records, customer data, and business-critical documents before any payload is deployed.
Failure mechanism: Attackers use discovery, credentialed access, and archive staging to identify high-value data, then preserve or exfiltrate it before triggering encryption.
Impact: The organisation faces greater extortion leverage, higher breach impact, and a stronger likelihood that sensitive information has already been copied out of the environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1078 — Valid Accounts | Credentialed discovery and selective access often rely on abused accounts. |
| T1021 — Remote Services | Attackers frequently move through shares and remote admin paths before staging data. | |
| T1560 — Archive Collected Data | Mass archive creation is a direct sign of data staging for exfiltration or theft. | |
| Recommendation — Correlate unusual account use with lateral discovery and isolate the abused identities. Hunt for remote-service use that precedes archive staging and restrict exposed admin paths. Flag archive creation on sensitive hosts as a likely pre-exfiltration action. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Reviewing correlated activity is necessary to spot discovery and staging patterns. |
| Recommendation — Analyze logs for cross-share access, archive bursts, and unusual system selection. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Log visibility is essential for identifying the access pattern behind staged theft. |
| Recommendation — Centralize logs so discovery, staging, and exfiltration indicators can be correlated quickly. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and network services are monitored to find potentially adverse events | The answer depends on noticing abnormal movement and access across the network. |
| Recommendation — Monitor share access and abnormal host-to-host movement for adverse activity. | ||
Practitioner Guidance
What to verify: Confirm whether the same host or account touched multiple file shares, staging locations, and sensitive business systems in a short window. Look for archive creation, unusual remote access, and transfers that align with lateral discovery rather than normal user work.
What to prioritise: Treat signs of data staging as a containment trigger, not just an investigation clue. If the attacker has already demonstrated interest in sensitive stores, the priority is to preserve evidence, cut off access paths, and assess what data could have been exposed.
Practitioner takeaway: The most important distinction is between noisy encryption and deliberate pre-encryption discovery, because the latter usually means the attacker has already found data worth leveraging and the incident should be handled as an exposure event as well as a ransomware event.
Related resources from NHI Mgmt Group
- What are the signs that backup data may already be compromised by ransomware?
- What are the signs that ransomware operators are using a bank network for both access and data theft?
- What are the signs that attackers may already be operating inside healthcare network infrastructure?
- How do attackers turn a supply-chain incident into wider NHI compromise?