Hackers Do Their Best Work on Long Weekends. This One Starts Tonight.

By tonight, most offices in the country will be empty until Tuesday. Attackers know the schedule as well as you do, and the record says they plan around it. The good news: the checks that matter most before a long weekend take about an hour, and the ones that matter after that can be handed off.
This is not a scare line invented by the security industry. It has a federal advisory, current survey data, and a fresh anniversary, and all three point the same way.
The pattern has a federal advisory
In 2021, the FBI and CISA published a joint advisory with an unusually plain title: Ransomware Awareness for Holidays and Weekends. It reports an increase in highly impactful ransomware attacks "occurring on holidays and weekends," when offices are normally closed, and it was released on August 31, days before that year's Labor Day.
The advisory reads like a season recap. In May 2021, leading into Mother's Day weekend, ransomware actors hit the IT network of a U.S. energy sector company and operations stayed suspended for a week. Over Memorial Day weekend, an attack on a food and agriculture company stopped meat production in the U.S. and Australia. And over the July 4th weekend, attackers compromised a remote management tool used by IT providers, reaching hundreds of downstream organizations in one move. Reporting later showed many of them were small and medium businesses whose only IT staff was the provider that got hit.
Three holiday weekends, three of the year's most disruptive attacks. The advisory's authors did not call that a coincidence, and neither should you.
The numbers have not aged out
Five years later, the pattern shows up in current data, not just old case studies.
Semperis, an identity security firm, surveyed organizations across ten countries for its 2025 Ransomware Holiday Risk Report, released this past November. Among organizations that experienced a ransomware attack, 52 percent were targeted on a holiday or weekend. The same study found 78 percent of companies cut security operations staffing by half or more during holidays and weekends, and some cut it entirely. The two numbers explain each other.
Sophos, whose incident response and detection teams worked 661 cases across 70 countries in the year ending October 2025, measured the timing directly in its 2026 Active Adversary Report: 88 percent of ransomware payloads were deployed outside business hours, and 79 percent of data theft happened off-hours too. Those are cross-industry figures, including plenty of small and midsize companies, and they describe a simple strategy: break in when you can, detonate when nobody is watching.
One more number worth holding onto from that report: the median attacker now spends about three days inside a network before being detected. The attack that ruins a long weekend usually did not start on the long weekend. It started midweek, quietly, and the weekend is when it finishes.
And the record is fresh. Halcyon, a ransomware defense firm, counted 727 confirmed ransomware attack claims in December 2025, the heaviest month it had ever tracked, up about 15 percent from the previous peak. The expected holiday slowdown, its researchers noted, never arrived.
Last Labor Day weekend, it was a carmaker
On Sunday, August 31, 2025, the day before last year's Labor Day, Jaguar Land Rover detected an attack that forced it to shut down production the next morning. The factories stayed down for about five weeks. Published estimates put the cost near 50 million pounds a week, and the UK's Cyber Monitoring Centre put the total damage to the British economy at an estimated 1.9 billion pounds, with severe cash-flow strain reported among the small suppliers downstream of the giant.
Your business is not a global carmaker. In one way that is worse: JLR had a security operation to call on a Sunday. In most small and medium businesses, there is no security operations center to thin out for the weekend, because the security operations center is the owner, the office manager, or the one IT person, and this weekend that person is at the lake with everyone else.
Why the long weekend works
Put the pieces together and the attacker's preference is not mysterious.
Three quiet days give encryption and data theft time to finish before anyone logs back in. A dark help desk means the fake "IT support" call and the fake password reset work better, the way the vishing playbook is designed to work. Out-of-office replies tell a fraudster exactly who is unreachable and until when, which is why the urgent wire-change email so often lands at 4:52 on a Friday afternoon: the FBI has tracked exposed losses from that one scam category, business email compromise, at 55 billion dollars over a decade. And everything automated in your business, mail rules, sync jobs, AI tools and agents, keeps running unattended, with nobody around to notice it doing something new.
The hour before you leave
The federal advisory's own recommendations, adapted for a business your size, fit in the last hour of today:
Confirm multifactor authentication is actually on for email and any remote access, for every account, including the owner's. Install the updates you have been postponing and restart the machines. Make sure a current backup exists somewhere that is not connected to the network, and that someone has tested restoring from it. Turn off remote access nobody needs this weekend. Write down, on paper, who gets the call if something looks wrong, with a phone number, and make sure that person knows they are it. And tell the team one sentence before they leave: any payment or banking change requested over the weekend waits until Tuesday and gets verified by phone, no exceptions, no matter how senior the name on the email.
The honest part
That hour reduces the risk. It does not eliminate it, and we will not pretend otherwise. The three-day dwell time means some of this weekend's victims were compromised on Wednesday, and no Friday checklist undoes that. The real gap is not the checklist; it is that in most small and medium businesses, detection sleeps when the people do. A firewall does not call you at 2 a.m. on Sunday. Something has to be watching that does not take the weekend off.
Where we fit
That watching layer is what we sell, so weigh what follows accordingly, but the logic holds no matter who provides it. Our Managed Email Security (powered by Check Point Harmony) filters phishing and wire-fraud attempts around the clock, including the Friday afternoon special. Our Managed Endpoint Protection (powered by SentinelOne) puts detection and response on every machine, so a laptop that starts encrypting files at 2 a.m. on Sunday can be isolated at 2 a.m. on Sunday, not discovered on Tuesday. And our Managed AI Security watches the newest unattended layer, the AI tools and agents your staff left running, the rest of the year. None of it replaces the hour of basics above; it covers the 72 hours after it.
The question worth asking before you go
Not "are we compliant." Ask the weekend question: if something on your network starts going wrong at 2 a.m. on Sunday, who notices before Tuesday morning?
We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you are in Washington DC, Northern Virginia, Maryland, or anywhere in the country and the honest answer to that question is "nobody," book a free 15-minute call for next week. Then go enjoy the weekend. That part is not optional either.

Comments