Offcanvas Logo

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact Us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

info@xitx.com
856-282-4100
1 Executive Drive Suite 100 Marlton, NJ 08053
+1 856-282-4100
Facebook-f X-twitter Instagram Linkedin-in Youtube
Xact IT Solutions
Let’s Talk
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Xact IT Solutions
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Let’s Talk

Dwell Time: What FBI IC3 Data Reveals About Attackers Hiding Inside Small Business Networks for Months

Dwell Time: What FBI IC3 Data Reveals About Attackers Hiding Inside Small Business Networks for Months

Dwell time – the gap between when an attacker first enters a network and when anyone detects them – is one of the most underreported dimensions of modern cybercrime. The FBI Internet Crime Complaint Center (IC3) annual report and a growing body of public incident response disclosures reveal a consistent and uncomfortable pattern: attackers are not smashing and grabbing. They move in quietly, learn your business, and wait. By the time a wire transfer disappears or ransomware locks your files, the attacker may have been reading your email for four months. This is not a fringe scenario. It is the dominant playbook against small and mid-sized businesses right now.

  1. The Numbers: IC3 Data and the Dwell Time Problem
  2. The Attacker Playbook: How Silent Reconnaissance Actually Works
  3. Who Is Most Affected and Why Small Businesses Are the Target
  4. Public Breach Disclosures and What They Show About Discovery Gaps
  5. Why the Breach Date and Discovery Date Are Almost Never the Same
  6. The Only Realistic Defense Posture Given This Reality
  7. What to Ask Your IT Firm About Dwell Time and Detection

The Numbers: IC3 Data and the Dwell Time Problem

The FBI IC3 2023 annual report – the most recently published full-year data as of mid-2025, with 2024 supplemental advisories building on those trends – recorded $12.5 billion in cybercrime losses, a 22% increase over the prior year. Business Email Compromise alone accounted for $2.9 billion of those losses. What the headline numbers hide is the methodology behind those crimes. Business Email Compromise is not a brute-force attack. It requires weeks or months of silent observation – and an extended dwell time – before a single fraudulent email is sent. You can review the full data directly at the FBI IC3 official website.

Mandiant’s M-Trends 2024 report, which aggregates global incident response data, placed the global median dwell time at 10 days for cases where an external party notified the victim. For organizations that discovered breaches on their own – without a third-party tip – median dwell time was 26 days. For small businesses without formal security monitoring, independent research and public breach disclosures consistently show dwell times measured in months, not days.

The Verizon 2024 Data Breach Investigations Report found that in financially motivated intrusions targeting small businesses, credential theft and email access were the most common initial vectors. The time between initial compromise and the execution of the actual financial crime averaged 90 to 120 days in documented cases. That is an entire business quarter of silent, invisible reconnaissance – a dwell time window that gives attackers everything they need to succeed.

The Attacker Playbook: How Silent Reconnaissance Actually Works

dwell time - Wide shot of a server room or network cabinet with blinking indicator lights and cables, photographed at an angle to convey the passage of time and ongoing hidden activity within infrastructure.

Most people picture a cyberattack as a sudden event: alarms, locked files, a ransom note on screen. The reality of how sophisticated financial crimes against small businesses are executed looks almost nothing like that – at least not at the start. Understanding the attacker’s step-by-step process is the first step toward reducing your exposure window.

The typical intrusion chain against a small business looks like this:

  • Initial access via credential theft or phishing: A single employee’s Microsoft 365 or Google Workspace login is compromised – often through a credential stuffing attack using passwords leaked in an unrelated breach, or through a convincing phishing email. No malware is deployed. No alerts fire. The attacker simply logs in as your employee.
  • Email monitoring begins immediately: The attacker sets up silent forwarding rules or periodically logs in to read email threads. They are learning: who approves wire transfers, what your invoice format looks like, which vendors you pay regularly, and how your leadership communicates internally.
  • Financial workflow mapping: Over weeks and months, the attacker builds a detailed picture of your accounts payable process. They note the dollar thresholds that require dual approval. They study the CFO’s or owner’s communication style. They identify the accounts that move the most money.
  • Internal system exploration: If the compromised account has access to file shares, accounting software, or other internal tools, the attacker maps those as well – looking for credentials stored in documents, banking portal logins saved in browsers, or direct access to financial platforms.
  • Strike execution – the only visible moment: After months of observation and an extended dwell time, the attacker sends a single, precisely crafted email impersonating the CEO or CFO, instructing accounts payable to wire funds to a new vendor account. The email looks legitimate because the attacker has read hundreds of your real ones. By the time the wire is questioned, the money is gone.

This is not theoretical. The FBI IC3 has documented this exact pattern in thousands of cases, and CISA has published detailed technical advisories describing the phased approach attackers use before executing financial fraud. CISA’s resources on advanced persistent threats outline how patient, methodical intrusions differ from opportunistic attacks.

Who Is Most Affected and Why Small Businesses Are the Target

The assumption that small businesses are too small to be worth targeting is one of the most dangerous myths in cybersecurity. The IC3 data dismantles it. Small businesses are disproportionately targeted precisely because they handle real money, they have weaker detection capabilities than enterprise companies, and they often have informal financial controls that a patient attacker can learn to circumvent during a prolonged dwell time period.

The highest-risk business profiles based on IC3 case patterns include:

  • Professional services firms – law offices, accounting practices, consulting companies – that handle client funds or process large vendor payments regularly
  • Healthcare practices that process insurance reimbursements and have high volumes of financial email traffic
  • Construction and real estate companies, where large wire transfers for property closings or contractor payments are routine and expected
  • Non-profit organizations, where a small finance team and a board-approved budget create predictable payment cycles that are easy to exploit
  • Any company that handles payroll changes through email, since attackers routinely intercept payroll redirect requests as a secondary financial target

The common thread is not industry. It is financial workflow predictability combined with limited security monitoring. If your accounts payable process can be learned by reading email threads, a patient attacker will exploit that dwell time advantage to do exactly that.

Public Breach Disclosures and What They Show About Discovery Gaps

Public incident disclosures from companies required to report breaches – through SEC filings, state attorney general notifications, or HHS breach reporting for healthcare entities – consistently reveal discovery gaps that stretch well beyond what most business owners expect.

Several notable patterns emerge from reviewing these disclosures:

  • A regional financial services firm disclosed in a 2023 state AG notification that unauthorized access to its email environment began in February and was not discovered until June – four months of undetected access during which the attacker monitored client communications and account data. That dwell time was long enough to map every significant financial relationship the firm maintained.
  • A healthcare billing company’s HHS breach report documented that an attacker accessed its systems in November of one year and was only identified the following March after a routine audit flagged anomalous login geography. The dwell period exceeded 120 days.
  • Multiple SEC 8-K filings from mid-sized companies in 2024 described intrusions where forensic investigators could only confirm an approximate start date because the attacker’s activity was indistinguishable from legitimate user behavior during the reconnaissance phase.

That last point matters most. The reason dwell time runs so long is not only that small businesses lack monitoring tools. It is that patient attackers, operating through legitimate stolen credentials, generate activity that looks like normal user behavior. There is no obvious alert to trigger. Standard antivirus software sees nothing because no traditional malware was deployed.

Why the Breach Date and Discovery Date Are Almost Never the Same

Every post-incident forensic investigation has to answer two questions: when did the attacker first get in, and when did anyone notice? In virtually every documented case involving credential-based intrusion and email reconnaissance, those two dates are separated by weeks to months. Understanding why is essential to understanding what a real defense looks like – and why compressing dwell time has to be a primary security objective.

The core reasons the discovery gap is so large:

  • No malware means no traditional alerts: Most small business security tools are built to detect malicious software. An attacker logging in with a legitimate username and password looks identical to the actual employee logging in. Without behavioral analysis of login patterns – location, time of day, device fingerprint, access volume – nothing flags.
  • Email forwarding rules are invisible to users: When an attacker sets up a silent forwarding rule in Microsoft 365 or Google Workspace, the legitimate account holder never sees it unless they specifically navigate to their mail settings. Most people never do. Catching new forwarding rules requires active oversight at the administrative level.
  • Reconnaissance generates low data volume: An attacker reading email produces far less network traffic than a normal working day. They are not downloading large files or running noisy scans. The data signal of their presence is small and easily lost in the noise of daily operations.
  • Discovery usually requires a triggering event: Most breaches surface because the attacker makes a mistake, because a financial institution flags an anomalous transaction, or because the victim receives a tip from law enforcement or a third party. Self-detection – the organization catching the intrusion through its own monitoring – remains the exception for small businesses, not the rule.

The FBI IC3 2023 report noted that victim organizations reported losses only after the fraudulent transaction was complete in the vast majority of Business Email Compromise cases. By definition, that means the attacker’s work was done before anyone knew a crime was underway. The reconnaissance phase – months of silent reading and mapping that constitute the dwell time window – concluded successfully and invisibly before a single dollar moved.

Illustration of the dwell time gap: attackers commonly operate undetected for 90 – 120 days before discovery in small business environments.

The Only Realistic Defense Posture Given This Reality

If the breach date and the discovery date are almost never the same, then security strategies built around detecting or stopping an active attack are fundamentally incomplete. A realistic defense has to assume that prevention alone will fail – and that the critical capability is early detection: compressing dwell time from months to hours.

What early detection requires in a small business environment:

  • Identity and login monitoring: Every authentication event – successful and failed – should be logged and analyzed for anomalies. A user logging in from New Jersey at 9am and from Eastern Europe at 2am on the same day is a detection event. It is only detectable if someone is watching.
  • Email rule auditing: Administrative oversight of email forwarding rules, delegate access grants, and inbox filter changes should be reviewed on a scheduled basis. This is not a complex process, but it requires someone to own it and actually run it. Most small businesses have no one doing this.
  • Multi-factor authentication on every account that touches money: Multi-factor authentication does not make credential theft impossible, but it eliminates the largest and simplest class of attacks – credential stuffing using passwords leaked from unrelated breaches. The attacker who has your password still cannot log in without your second factor. NIST’s digital identity guidelines, available at NIST SP 800-63, are explicit: phishing-resistant multi-factor authentication is the single highest-impact credential control for reducing unauthorized access and shortening potential dwell time.
  • Endpoint behavioral monitoring: Watching for unusual process activity, unexpected outbound connections, or off-hours system access at the device level can catch attacker activity that credential monitoring misses – particularly when an attacker escalates from email access to broader network exploration.
  • Financial control verification that runs out of band: Any change to banking details, wire transfer instructions, or payroll routing should require a second verification through a channel completely separate from email – a phone call to a known number, a verification code sent to a different device. Email cannot verify email when the attacker is already reading it.

The goal of this stack is not to build a wall so high no attacker can climb it. The goal is to make the attacker’s presence detectable within hours rather than months – because the dwell time data shows that a patient attacker who remains undetected for 90 days almost always succeeds. Compress that window, and the calculus changes entirely.

For organizations that want to understand how these controls map to a recognized framework, our cybersecurity services page describes how we build and maintain detection-first environments for the businesses we work with. You can also explore our broader managed IT services to see how continuous monitoring integrates into day-to-day network management.

If you want to know whether your current environment would catch an attacker operating inside it right now, Book a Free Cybersecurity Strategy Call. It’s a 20-minute conversation – no obligation, no sales pressure – and you’ll leave with a clear read on where your detection gaps are.

What to Ask Your IT Firm About Dwell Time and Detection

The dwell time problem is an IT firm accountability problem as much as it is a technology problem. If the firm managing your environment is not actively monitoring for signs of silent intrusion, extended dwell time is the predictable outcome. These questions will tell you quickly whether your current provider has a detection-first posture or is operating on a break-fix assumption that attacks announce themselves:

  • How often do you review our email environment for unauthorized forwarding rules, delegate access, or new mail filters – and can you show me the last report?
  • If an attacker logged into one of our Microsoft 365 accounts from a foreign country at 3am, would you be alerted, and how quickly would you respond?
  • What is your process for detecting login anomalies – unusual geography, device changes, or impossible travel events – across our user accounts?
  • When did you last review our administrative access permissions to confirm that only the right people have elevated access?
  • If we experienced a Business Email Compromise-style intrusion today, what forensic capability do you have to determine when the dwell time began – not just when we noticed the attack?
  • Do you review our endpoint activity logs for behavioral anomalies, or only for known malware signatures?
  • What is your protocol when you detect suspicious activity – who gets notified, how fast, and what is the containment process?

An IT firm that cannot answer these questions specifically – with reference to actual tools, actual schedules, and actual documented processes – is not operating a detection-first environment. They are managing your technology reactively. In the context of the dwell time data, reactive management means the attacker wins by default.

The IC3 data and the public breach record point to the same conclusion: the breach date and the discovery date are almost never the same, and the gap between them – the dwell time – is where the real damage happens. Reducing that gap from months to hours is not a product you buy. It is a discipline you build – or hire for. The organizations that get this right are the ones that never have to explain a fraudulent wire transfer to their board.

Get a Second Opinion

Sometimes the best thing you can do for your business is have someone outside your current vendor relationship take a fresh look. That’s what a strategy call gives you — 20 focused minutes with our team and a no-strings-attached read on what we’d recommend.

Talk to an IT Strategist

Recent Posts

  • Ransomware Backup Destruction: How Attackers Erase Your Recovery Data Before the Ransom Note Appears
  • Dwell Time: What FBI IC3 Data Reveals About Attackers Hiding Inside Small Business Networks for Months
  • Credential Stuffing Attacks in 2025: Why Password Reuse Is Still Winning
  • AI Tools for Business Are Saving You Hours – and Saving Attackers Days
  • AI Contract Review for Small Businesses: Your First-Pass Playbook Before You Call a Lawyer

Categories

  • AI for Business
  • Backup & Recovery
  • Blog
  • Business
  • Buyer Guides
  • CMMC
  • Compliance
  • Cybersecurity
  • Healthcare
  • Managed IT
  • News & Analysis
  • Threat Intelligence

Share

FRUSTRATED WITH YOUR CURRENT IT PROVIDER? LET’S TALK.

Get a Free IT Consultation
Xact IT Solutions
  • info@xitx.com
  • +1 856-282-4100
  • 1 Executive Drive Suite 100 Marlton NJ 08053

Follow Us

Quick Links
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Contact
Services
  • IT Support
  • Cybersecurity Services for SMBs | Xact IT Solutions
  • IT Compliance
Recent Blogs
  • Supply-Chain Ransomware Attack Impacts 60 Credit Unions
  • Comcast Xfinity Data Breach Exposes 36 Million Customers’ Data
  • Crown Equipment’s Cyberattack: Recovery and Lessons Learned
Copyright © 2026. Website Design by Xact IT Solutions
  • Privacy Policy and Terms & Conditions
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Contact