There is a mental model that most security teams carry, often implicitly, about how ransomware attacks unfold. An attacker gains initial access through some vector — a phishing email, a stolen credential, an unpatched vulnerability. They establish a foothold. They conduct reconnaissance. They move laterally. This process takes time — hours, often days — and that time creates opportunity for defenders to detect and intervene before the attack reaches its most destructive phase.
That mental model is now dangerously out of date.
Mandiant's M-Trends 2026 report documents one of the most consequential shifts in the threat landscape: the rapid compression of the time between initial access and ransomware deployment. In 2022, the median time between initial access and the handoff to a secondary threat group — typically the ransomware operator — was greater than 8 hours. By 2025, that median time had fallen to 22 seconds.
Twenty-two seconds. The time it takes to read this paragraph.
The Division of Labor That Changed Everything
To understand why this happened, you need to understand how the cybercrime ecosystem has industrialized. Modern ransomware operations increasingly involve two distinct roles: initial access partners, who specialize in gaining footholds in organizations, and secondary groups, who specialize in high-impact operations like ransomware deployment.
In 2025, 9% of Mandiant's investigated incidents followed this "division of labor" model — up from 4% in 2022. These are not loosely affiliated criminal networks. They are structured partnerships with defined roles, established relationships, and in some cases, contractual arrangements where initial access partners receive 20-50% of any ransom payment in exchange for the access they provide.
The 22-second figure reflects the most closely integrated version of this model — where the initial access partner effectively delivers the compromised environment directly to the ransomware operator in an automated, nearly instantaneous handoff. There is no underground forum advertisement. No waiting for a buyer. No negotiation. The malware is distributed directly on behalf of the secondary group from the moment of initial compromise.
What This Means for Alert Triage
The operational implication of 22-second handoffs is that the traditional approach to alert prioritization — where low-impact initial access events get deprioritized in favor of higher-severity alerts — is now actively dangerous.
Mandiant documents this explicitly: organizations hunting solely for high-impact tactics and techniques may not have high-priority detections in place for the low-impact initial intrusion vectors that precede the handoff. A FAKEUPDATES infection — a JavaScript downloader distributed via drive-by download or malicious advertising — is a low-severity alert. It does not look like a ransomware attack. It looks like a routine malware cleanup.
But in the documented partnership between UNC1543 (the initial access partner) and UNC2165 (the ransomware operator), FAKEUPDATES infections are the precursor to RansomHub deployment. Security teams who understand this relationship can treat FAKEUPDATES alerts as high-priority ransomware precursors. Security teams who do not understand it will deprioritize them.
The Window Defenders Have
The critical insight from Mandiant's analysis is that the window for defenders to intervene exists, but it is narrower than most teams realize — and it begins at the moment of initial access, not at the moment ransomware is detected.
In the division-of-labor model, the clock starts when the initial access partner gains their first foothold. The earliest interactive activity by the secondary group — reconnaissance, lateral movement — is the moment when the attack transitions from containable to potentially catastrophic. Between those two moments, there is an opportunity: break the access, change compromised passwords, and prevent the secondary group from activating their foothold.
In the 22-second model, that window is effectively zero for automated response. But not all handoffs are instantaneous. Even in cases where the handoff is fast, there is typically a period — sometimes hours — between the secondary group receiving access and their earliest interactive activity. That period is where early detection makes the difference between a single compromised endpoint and a full network encryption event.
How to Respond to the New Reality
Mandiant's recommendations for operating in this environment are practical and grounded in what they observed working in the field:
Treat low-impact alerts as potential ransomware precursors. The types of malware used by initial access partners — infostealers, JavaScript downloaders, drive-by compromise payloads — may be individually low-severity. But if your threat intelligence identifies a known relationship between that malware family and a ransomware operator, the alert should be escalated accordingly. Context transforms priority.
Build a baseline of expected behavior. One of the most effective approaches Mandiant recommends is creating a clear inventory of approved tools and expected behaviors for each business unit. When activity falls outside that baseline — an unusual process execution, an unexpected outbound connection, an unrecognized binary — detection is faster and more reliable. The smaller the haystack, the easier it is to find the needle.
Optimize for speed of remediation, not just detection. The 22-second handoff means that detection alone is not sufficient. The response workflow — containing the compromised endpoint, resetting credentials, blocking C2 communication — needs to execute fast enough to interrupt the secondary group before they become interactive. Automation of containment steps is increasingly necessary.
The 22-second handoff is not a vulnerability in any piece of software. It is a structural feature of how organized cybercrime now operates. The defenses that work against it are speed of detection, quality of threat intelligence about initial access partner relationships, and automation of early-stage containment. Organizations that build those capabilities are significantly better positioned than those still optimizing their response for the 8-hour timeline that no longer exists.
See what continuous testing finds in your environment.
Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.
Request early access →