SabiSys - Your Network Is Always On.
Support
Home Services
OverviewCloud & collaborationNetwork & WiFiHardwareInternet & fibreLandline & mobile telephonyMaintenanceBackup & continuity
Managed IT Cybersecurity Security check-up About Blog FAQ Contact Request your free audit
FREN
Security check-up · My IP · Speed test
+32 4 325 51 40 support@sabisys.be Office: Mon-Fri 9am-5pm · SLA clients: extended availability
← All articles Cybersecurity

Ransomware: why attackers wait until you go on holiday

In late July, half of Belgium shuts up shop or runs on a skeleton staff. That is exactly what ransomware groups are waiting for. The American authorities have been watching it for years: the most destructive attacks are launched at weekends and on public holidays, when no one is looking at the screens. And this week, the Centre for Cybersecurity Belgium published a detailed report on Qilin, one of the most active groups around right now. Here is what you need to know, and above all what to check before you close.

The timing is no accident

The FBI and CISA, the American cybersecurity agency, have long warned about a well-honed pattern: ransomware operators prepare their attack for weeks, then trigger the encryption at the moment the company is least able to react. A Friday evening, the eve of a public holiday, the annual leave period. The longer detection takes, the further the damage spreads: every hour without a response lets them encrypt more servers and steal more data.

The logic is relentless. An intrusion spotted on a Tuesday at 10am is often limited to a workstation or two. The same intrusion on a Saturday in July, when the IT manager is abroad and no one is checking the alerts, ends with the entire IT environment encrypted by Monday morning.

Qilin: the group the CCB is watching closely

On 22 July, the Centre for Cybersecurity Belgium (CCB) published an intelligence report on Qilin, also known as Agenda. Active since 2022, this group runs like a real business: it rents out its malware to "affiliates" who carry out the attacks, and actively recruits experienced operators from groups that have been dismantled. The result: its activity grows year after year, and 2026 is already shaping up to be worse than 2025 in the number of victims.

Qilin practises double extortion: your data is both encrypted AND stolen. Even if you restore your backups, the group threatens to publish your client files, contracts and HR data if you do not pay. Belgian organisations already feature among the recorded victims. And contrary to a common belief, these groups do not only go after large organisations: an SME that pays quickly and quietly is an ideal target.

The one-sentence takeaway

Attackers pick the moment your business is most vulnerable: if no one is watching your IT over the holidays, your security goes on holiday at the same time you do.

Six checks before you close

Good news: the essentials can be put in place in a few days, and most of these protections already exist in your Microsoft 365 licences. You just have to switch them on.

  1. Install updates before you leave. Attackers go first for known but unpatched vulnerabilities. Servers, firewalls, workstations: everything must be up to date before you close, not when you get back.
  2. Check MFA on every account. Two-factor authentication must cover all remote access, including administrator accounts and VPN access. A single forgotten account is enough.
  3. Test a backup restore. A backup that has never been tested is a hope, not a plan. Make sure at least one copy is offline or immutable, out of reach of an attacker who takes control of your network.
  4. Disable dormant accounts. Departed interns, former staff, test accounts: every unused account is a potential way in. Now is the time to clear them out.
  5. Name someone who can be reached. Who receives the alerts while you are closed? Who is allowed to pull the plug on a server in an emergency? A name, a number, one simple instruction: it makes all the difference on a Sunday in August.
  6. Be wary of summer "HR" emails. Summer phishing campaigns imitate internal departments: leave schedules, payroll changes, staff notices. Remind your teams of the rule before they leave: any unusual request is verified by phone, on a known number.

And if no one is keeping watch at your place?

That is precisely the role of managed IT: someone receives the alerts and reacts, even when your business is closed. If you want to know where you stand first, our free security check-up places you in three minutes: eleven questions, a score, and your main weak point. And for a full run through your setup, a free, no-obligation audit takes place at your premises, in an hour.

Would your business hold up over a weekend with no one watching?

Three minutes are enough to find out.

Take the security check-up

Sources: Centre for Cybersecurity Belgium · CISA / FBI · Bitdefender · Atalayar

Terms and conditions · SabiSys
Download the PDF

This site uses only technical cookies essential to its operation. No advertising cookies, no tracking.

FREN