Ransomware groups are increasingly timing their attacks to coincide with weekends and holidays, exploiting periods when organizations have reduced Security Operations Center (SOC) staffing and slower response times. According to a Semperis report, over half of ransomware incidents in the past year occurred during these off-hours, with 78% of organizations cutting SOC coverage by at least half and 6% leaving their SOCs completely unstaffed outside the regular workweek. This strategic timing allows threat actors to penetrate deeper into networks before detection, leading to longer investigations, higher financial losses, and significant business disruptions. The trend is consistent across regions and sectors, and is exacerbated by internal events such as mergers, acquisitions, and restructurings, which introduce vulnerabilities in identity systems that attackers are quick to exploit.
The persistent threat of ransomware during these vulnerable periods is compounded by the challenge of maintaining work-life balance for cybersecurity professionals, with many reporting missed holidays and increased burnout. Automated alerting and outsourced monitoring are cited as partial mitigations, but the consensus among experts is that vigilance must be maintained even during off-hours. The "assume breach" mindset is gaining traction, as organizations recognize that attackers are patient and opportunistic, leveraging any lapse in coverage to maximize impact. The financial and operational consequences of delayed response underscore the need for robust crisis management frameworks and continuous monitoring, especially during times when internal resources are stretched thin.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting amplified the report's findings and recommended measures such as automation, network segregation, tabletop exercises, incident response documentation, and on-call rotations to reduce risk during holidays and other low-staffed periods. The coverage emphasized that AI and automation can help but do not replace maintaining baseline human security coverage.
The same Semperis report found that 60% of ransomware incidents followed organizational change such as mergers, acquisitions, or restructuring, with M&A identified as the most common trigger. It also highlighted gaps in identity remediation and recovery preparedness that can prolong downtime after attacks.
A Semperis report found that more than half of organizations that experienced ransomware in the past year were attacked during weekends, holidays, or other off-hours, when SOC staffing and investigative capacity are typically reduced. The report also said many organizations cut SOC coverage significantly during these periods, increasing attacker dwell time before detection.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.