Ransomware: How We Got Here and Why Small Businesses Are Paying the Price
Ransomware Image
Published October 5, 2026 | By Nick Turner | AegisPro CyberShield TX
TL;DR
Ransomware has gone from a curiosity on floppy disks in 1989 to one of the most profitable criminal enterprises in history. Small businesses bear the worst of it.
▪ 88% of small and midsize business breaches now involve ransomware, compared to 39% for large organizations
▪ Over two-thirds of ransomware attacks in the past two years targeted businesses with fewer than 500 employees
▪ Recovery costs for small businesses range from $120,000 to $1.24 million per incident, not counting the ransom itself
▪ 69% of businesses that paid the ransom were attacked again within a year
▪ Employees at small businesses face 350% more social engineering attacks than their counterparts at larger companies
The bottom line: Ransomware isn't just a big-company problem. If your business handles customer data, processes payments, or simply relies on its computers to operate, you are already a target.
A Floppy Disk, a P.O. Box, and the Birth of Ransomware
It started with actual mail.
In 1989, a biologist named Joseph Popp sent 20,000 floppy disks to attendees of a World Health Organization AIDS conference. The disks were labeled as an interactive survey about AIDS risk factors. Instead, they installed a program that hid file names on the victim's computer and demanded $189 be sent to a P.O. box in Panama.
The "AIDS Trojan" was crude by any standard. The encryption was simple, the distribution method was painfully slow, and Popp was eventually caught. But the concept was proven: lock someone out of their own data, and some of them will pay to get it back.
For the next decade and a half, not much happened. Ransomware was a novelty, an academic footnote. The internet hadn't yet created the conditions for it to thrive.
That changed in the early 2000s.
The Slow Build: From Nuisance to Business Model
Between 2004 and 2012, ransomware started finding its legs. Early variants like GPCode spread through phishing emails and demanded small ransoms of around $20. In 2011, WinLock pioneered a new approach: instead of encrypting files, it locked users out of their devices entirely and displayed a fake law enforcement notice claiming the victim had committed a crime.
Two developments during this period transformed ransomware from a fringe annoyance into a genuine threat.
The first was Bitcoin. Launched in 2009, cryptocurrency gave attackers something they had never had before: a way to collect payment that was fast, borderless, and extremely difficult to trace. Before Bitcoin, ransomware operators had to rely on wire transfers, prepaid cards, and P.O. boxes. All of those created trails. Cryptocurrency removed the bottleneck.
The second was Ransomware-as-a-Service (RaaS). In 2012, a variant called Reveton introduced a model where the malware developers didn't carry out the attacks themselves. Instead, they licensed their tools to affiliates who did the actual hacking in exchange for a cut of the profits. Suddenly, you didn't need to be a skilled programmer to launch a ransomware attack. You just needed to be willing.
CryptoLocker Changes Everything
The year 2013 is when ransomware went mainstream. CryptoLocker used military-grade 2,048-bit RSA encryption that was essentially unbreakable without the decryption key. It spread through email attachments, encrypted victims' files, and demanded payment in Bitcoin within a deadline. Miss the deadline, and the price went up.
CryptoLocker generated an estimated $27 million in just two months.
That number got the attention of organized criminal groups worldwide. From that point forward, ransomware wasn't a hobby for lone hackers. It was a business, and a highly profitable one.
The Escalation: WannaCry, Double Extortion, and the Modern Era
The next few years brought wave after wave of escalation.
In 2017, WannaCry tore across more than 150 countries in a single day, hitting hundreds of thousands of machines. It exploited a vulnerability in Windows that had been discovered (and stockpiled) by the NSA, then leaked by a hacking group. The U.K.'s National Health Service was crippled. Factories shut down. The total damage was estimated in the billions.
That same year, NotPetya took things further. Disguised as ransomware, it was actually a wiper. It didn't just encrypt files. It destroyed them. Companies like Maersk and FedEx lost hundreds of millions of dollars each.
Then in 2019, a group called Maze introduced double extortion. Encrypt the data, yes. But also steal it first, and threaten to publish it online if the victim doesn't pay. Now businesses faced two threats: losing access to their files and having sensitive data exposed publicly. Since then, triple extortion has emerged, adding DDoS attacks or threats to contact customers directly.
Today, ransomware groups like LockBit (disrupted by international law enforcement in 2024, but already showing signs of reorganization), BlackCat, and others operate like legitimate businesses. They have customer support portals, affiliate programs, negotiation teams, and even press releases. Some post victim names on dark web "shame sites" to pressure payment.
Why Small Businesses? Because the Math Works.
Here's the part that matters most for business owners in DFW and across Texas.
There's a persistent myth that ransomware is mainly a problem for hospitals, pipelines, and Fortune 500 companies. The headline-grabbing attacks support that narrative. But the data tells a very different story.
Verizon's 2025 Data Breach Investigations Report found ransomware in 88% of breaches at small and midsize businesses, compared to 39% at large organizations. The same report counted nearly four times as many small and midsize victims as large ones.
Why? Because attackers are running a volume game. A large enterprise might have a dedicated security operations center, a seven-figure cybersecurity budget, and an incident response team on retainer. A 30-person accounting firm in Fort Worth probably has an IT guy who also manages the office printers.
Ransomware operators know this. They know that small businesses are less likely to have:
▪ Multi-factor authentication on critical systems
▪ Regular, tested backups stored offline
▪ Employees trained to recognize phishing attempts
▪ An incident response plan of any kind
▪ Cyber insurance with ransomware coverage
75% of small businesses reported they could not continue operating if ransomware hit their systems. That's not a scare tactic. That is business owners being honest about how dependent they are on the systems they haven't secured.
The Human Factor Is the Front Door
If you're wondering how ransomware actually gets into a small business, the answer is almost always people.
Phishing remains the most common entry point, and it is getting significantly harder to spot. AI-generated phishing emails now achieve open rates between 54% and 78%, compared to roughly 12% for traditional phishing. The average employee clicks a phishing link within 21 seconds of opening the email. Employees at small businesses experience 350% more social engineering attacks than those at larger organizations.
Compromised credentials account for another 22% of breaches. That means stolen or reused passwords, often from entirely unrelated data breaches, being used to walk right into business systems.
52% of small businesses rely on untrained internal staff for cybersecurity management. That's not a criticism of those employees. It's a structural problem. You wouldn't ask your receptionist to handle your tax audit. But many businesses are essentially doing the cybersecurity equivalent.
What Texas Small Businesses Can Do Right Now
The good news is that ransomware protection doesn't require a six-figure security budget. Most small business ransomware attacks succeed because of basic gaps that are straightforward to close.
Start with the fundamentals. Enable multi-factor authentication on every account that supports it. Enforce strong, unique passwords through a password manager. These two steps alone block the majority of credential-based attacks.
Back up everything, and test those backups. The single most effective defense against ransomware is a reliable, tested backup stored somewhere the ransomware can't reach it. If your backups are connected to the same network as your production systems, they will be encrypted too. Air-gapped or immutable cloud backups are the standard.
Train your people. Not a once-a-year compliance video. Regular, practical training that teaches employees what phishing actually looks like in 2026, including the AI-generated variety. Build a culture where reporting a suspicious email is rewarded, not embarrassing.
Get a risk assessment. You cannot protect what you haven't evaluated. A professional security assessment identifies the specific gaps in your environment, prioritizes them by risk, and gives you a concrete plan.
Know your legal landscape. Texas SB 2610 created a cybersecurity safe harbor for businesses with fewer than 250 employees. If your business is sued after a breach, having a qualifying cybersecurity program in place shields you from exemplary (punitive) damages. It does not make the lawsuit go away, but it takes the most unpredictable part of the exposure off the table. What counts as "qualifying" scales with the size of your business:
| Business Size | What the Safe Harbor Requires |
|---|---|
| Fewer than 20 employees | Simplified requirements, including password policies and cybersecurity training for staff |
| 20 to 99 employees | CIS Controls Implementation Group 1 |
| 100 to 249 employees | A full recognized framework such as the NIST Cybersecurity Framework |
The protection only applies if the program was in place at the time of the breach. You cannot build it afterward.
This Is a Business Decision, Not an IT Problem
Ransomware has evolved from a novelty on a floppy disk to a multibillion-dollar criminal industry with professional operations, franchise models, and customer service desks. The attackers treat it like a business. Small business owners need to think about their defenses the same way.
The question is not whether your business is a target. The data is clear on that. The question is whether you will be ready when an attack comes.
Find Your Gaps Before an Attacker Does.
AegisPro will come to your location for 30 minutes, review how your business handles backups, logins, and email, and give you an honest read on your ransomware readiness. No cost, no contract, no obligation.
Schedule Free WalkthroughOr call AegisPro directly at (817) 993-9427
AegisPro CyberShield TX
Cybersecurity Built for Texas Small Businesses
Sources Referenced
Verizon, "2025 Data Breach Investigations Report", Verizon.com link: https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf
Verizon, "2025 DBIR Small- and Medium-Sized Business Snapshot", Verizon.com link: https://www.verizon.com/business/resources/infographics/2025-dbir-smb-snapshot.pdf
Verizon, "2024 Data Breach Investigations Report", Verizon.com link: (add the 2024 report URL from Verizon.com)
Barracuda, "Spear Phishing: Top Threats and Trends Vol. 7", Barracuda Blog, 2022 link: https://blog.barracuda.com/2022/03/16/spear-phishing-report-social-engineering-and-growing-complexity-of-attacks
"60 Small Business Cybersecurity Statistics to Know in 2026", Spacelift link: https://spacelift.io/blog/small-business-cybersecurity-statistics
"The History and Evolution of Ransomware Attacks", TechTarget link: https://www.techtarget.com/cybersecurity/feature/The-history-and-evolution-of-ransomware-attacks
Texas Legislature, "Senate Bill 2610 (Business and Commerce Code, Chapter 542)", LegiScan link: https://legiscan.com/TX/supplement/SB2610/id/586612