Attackers love your long weekend. Strangely enough, many of them are rather fond of their own.

There is a moment on Friday afternoons when civilization collectively begins shutting down.

Someone in accounting closes Excel. Someone in HR turns on an out-of-office message. Someone in IT glances at the monitoring dashboard one last time, sees nothing actively on fire, and makes the dangerous and very human decision to go home and have a life.

Somewhere else, somebody has been waiting for exactly this moment.

One of the more persistent clichés about cybercrime is the lone hacker in a dark room, hoodie up, pounding Red Bull at 3:00 in the morning while green letters cascade down six monitors. The reality has become considerably more corporate. Modern ransomware crews can have departments, managers, recruitment processes, payroll schedules, vacation policies and disgruntled employees complaining about work-life balance.

And this creates one of cybercrime's more delicious paradoxes:

The criminals may take the weekend off. Their malware does not.

The timing is not accidental. The FBI has been warning about criminals studying victim staffing patterns for years. In a 2010 speech, Steven R. Chabinsky, then Deputy Assistant Director of the FBI Cyber Division, described criminals paying attention to when IT security teams were least staffed—nights, weekends and federal holidays—and scheduling crimes accordingly. More recently a joint CISA–FBI Cybersecurity Advisory, (AA21-243A, “Ransomware Awareness for Holidays and Weekends", Feb.2022), warned that holidays and weekends are attractive precisely because fewer network defenders are present.

Then there is the other side of our story: cybercriminals themselves eventually get bored, take vacations, buy ridiculous cars, go clubbing, fly somewhere sunny and—occasionally—transform years of careful online anonymity into a surprisingly efficient law-enforcement opportunity.

So pour yourself something festive and turn on your out-of-office reply.

We are going on vacation with the hackers.

Apparently the ransomware gang has an HR department

The 2022 leak of internal communications from the notorious Conti ransomware organization offered an extraordinary glimpse behind the curtain. What emerged was not merely a bunch of criminals chatting about malware.

It was an office.

Conti had managers. Coders. Administrators. Recruiters. Salaried employees. Internal squabbles. Performance expectations. Budgets. Onboarding. Employees asking for advances because of family problems. Employees complaining that other employees were useless. Employees asking whether their vacation had been approved.

There was even payroll.

An academic analysis of the Conti messages found that more than 80 percent of the group's communications occurred between 8 a.m. and 8 p.m. Moscow time. Only 5 percent of messages were sent on weekends. Activity fell dramatically on Russian holidays, from an average of 308 messages on ordinary days to 69 on holidays. Conti reportedly paid employees on the first and fifteenth of the month and sometimes recruited technical workers through legitimate employment sites.

This means that one of the world's most notorious ransomware operations apparently understood an important principle that has eluded many perfectly legal American corporations:

People would prefer not to answer Slack on Sunday.

Leaked Conti conversations make the absurdity even more delicious. One member objected to the expectation of being reachable around the clock, arguing that it was a direct route to burnout. Others asked to finish early or checked whether requested holidays had been approved. At one point management wanted another hundred malware workers recruited before much of the gang returned from summer vacations in Crimea.

Imagine that meeting.

“Okay, team. Outstanding quarter. Excellent extortion numbers. Fantastic work crippling those businesses. Reminder that expense reports are due Thursday, Dimitri is covering while Sergei is at the beach, and please welcome our new junior ransomware developer from Indeed.”

The humor stops, of course, at what these organizations actually do. Conti was not a mischievous software startup. Its victims included businesses, governments and healthcare organizations, and its operators extracted enormous sums while causing real human damage.

But understanding the corporate structure matters because it destroys an unhelpful myth.

Cybercrime is not necessarily chaotic.

It can be managed.

And once crime is managed, it can be scheduled.

Your weekend is a feature, not a bug

If an intruder already has access to a company network, there are obvious advantages to choosing 11:47 p.m. Saturday rather than 11:47 a.m. Tuesday for the loudest portion of an attack.

Fewer people are watching. Fewer department heads can be reached. An alert that would trigger a five-minute phone call on Wednesday may spend forty-five minutes waiting for somebody to notice it on Sunday. The person who knows why one particular server absolutely must never be shut down may be camping somewhere without cellular coverage. Vendors may be on reduced staffing. Executives who can authorize emergency decisions may be scattered across three golf courses and a wedding reception.

Attackers do not need the defenders to be absent forever.

Sometimes they only need them to be slow.

Sophos examined more than 150 incident-response cases from 2023 and found that 90 percent of ransomware deployments occurred outside normal business hours. Its analysis of 2022 produced 94 percent. Across both years, 92 percent of the observed ransomware deployments occurred outside the conventional workday. Sophos appropriately cautions that its incident-response cases are not every ransomware attack on Earth, but the pattern is overwhelming within the dataset.

An FBI cyber podcast in 2026 cited another dataset in which 88 percent of ransomware payloads were deployed during non-business hours and 79 percent of data exfiltration occurred off-hours. The FBI representative then pointed specifically to major attacks occurring around holiday weekends, including REvil activity, (REvil ransomware attacks, including the July 2021 Kaseya supply-chain compromise that affected up to 1,500 downstream businesses), around the Fourth of July, when defenders were out of the environment.

So when a security chief says, “Nobody will be in the office Monday because it's a holiday,” a ransomware operator hears something quite different:

“Excellent. Thank you for the change window.”

Christmas Eve, 00:01

Few organizations could illustrate the point more neatly than the Scottish Environment Protection Agency.

SEPA was hit by ransomware on December 24, 2020.

Not merely sometime around Christmas.

According to SEPA's own post-incident report, analysis determined that data theft occurred shortly before the ransomware was activated at 00:01 on Christmas Eve. The agency's emergency management team was meeting by 9:30 that morning. Audit Scotland later reported that the majority of SEPA's data had been encrypted, stolen or deleted overnight.

Midnight plus one minute.

There are subtler ways to communicate “we know what day it is,” but not many.

It is worth being careful here: a timestamp does not allow us to read the attackers' minds. We cannot prove merely from the clock that somebody ceremonially waited for Christmas Eve and yelled “NOW!” But the choice sits comfortably inside a much broader, well-documented pattern of criminals exploiting periods of reduced staffing. CISA itself subsequently issued warnings specifically devoted to ransomware during holidays and weekends.

And the victim was not some neglected little company whose administrator's password was admin123.

Audit Scotland reported that reviews found SEPA's cyber defenses had been good.

That is another important part of this story. Holiday attacks are not magical attacks. They do not penetrate a firewall because Santa Claus has temporarily disabled TLS. What the calendar can give an attacker is time—more time before detection, more time before coordinated human response, more time before somebody understands that three individually weird alerts are actually one unfolding catastrophe.

Security controls remain controls.

Human beings remain part of the control system.

Memorial Day: please hold the ransomware, we're grilling

Five months after the SEPA incident came another almost painfully American collision between holidays and cybercrime.

On Sunday, May 30, 2021, meat-processing giant JBS determined that it was under cyberattack. The timing put the incident squarely into the U.S. Memorial Day weekend. Operations in North America and Australia were disrupted, and JBS temporarily halted cattle slaughter at all of its U.S. plants for a day. The company subsequently paid an $11 million ransom.

There is something almost too symbolically perfect about a ransomware attack against a meat processor landing on Memorial Day weekend.

Millions of Americans are outside enthusiastically converting beef into smoke, while somewhere deep in the supply chain the computers responsible for an enormous quantity of future beef are having an extremely bad day.

The JBS incident arrived less than a month after the Colonial Pipeline ransomware crisis and helped reinforce that ransomware was no longer merely an IT inconvenience. Disrupt the right computer systems and you can interfere with fuel, food, hospitals, government services or industrial production.

The computer may be virtual.

The consequence is not.

And attackers had discovered something military planners have understood for several thousand years: timing is part of the weapon.

Independence Day: the grocery stores surrender

Then REvil apparently decided Memorial Day had gone rather well.

On Friday, July 2, 2021—the beginning of the U.S. Independence Day weekend—customers of Kaseya's VSA remote-management software began reporting unusual activity. Ransomware was being executed on endpoints managed through on-premises VSA servers.

Kaseya reacted by telling on-premises customers to shut their VSA servers down and taking its own SaaS infrastructure offline. The company later said fewer than 60 of its direct customers had been compromised, but because many of those customers were managed service providers, the effects cascaded outward to as many as 1,500 downstream businesses.

This is where the holiday-timing problem met the supply-chain problem.

Instead of kicking down a thousand individual doors, the attackers had compromised technology used by organizations whose job was to manage other organizations' computers.

One door.

Many rooms.

In Sweden, Coop discovered that its cash-register systems had been affected through the chain of service providers. The result was spectacularly physical: the supermarket company closed all 800 of its stores because it could not operate the registers.

Consider how beautifully ridiculous that is from the perspective of anyone who still thinks “cybersecurity” means protecting mysterious files that live inside computers.

The ransomware did not have to understand Swedish agriculture.

It did not have to sabotage a refrigeration compressor.

It did not have to attack a truck.

It made the cash registers stop working.

And eight hundred grocery stores became buildings full of food that could not easily be sold.

Reuters reported at the time that security specialists explicitly suspected the Friday-before-a-long-weekend timing was intended to help the attack spread while employees were away. CISA and the FBI soon issued their dedicated holiday-and-weekend ransomware warning.

Happy Fourth of July.

Please reboot your civilization.

Memorial Day again: MOVEit moves fast

By 2023, the holiday trick had evolved beyond the classic image of ransomware detonating across desktops.

Mandiant found the earliest evidence of mass exploitation of the MOVEit Transfer zero-day on May 27, 2023—the Saturday of the U.S. Memorial Day weekend.

The objective was data theft.

Attackers exploited the vulnerability, deployed web shells and stole information. In some cases Mandiant found that data theft began within minutes of the web shell being installed. Progress publicly disclosed the vulnerability on May 31. The Clop extortion operation subsequently claimed responsibility for the campaign and threatened to publish stolen information unless victims paid.

That incident nicely demonstrates why “we have good backups” is no longer an adequate response to modern extortion.

If attackers steal the information rather than merely encrypting it, restoring yesterday's files does not put the stolen copies back inside the building.

It also demonstrates what automation does to holiday risk. A criminal crew does not necessarily have to sit awake all weekend manually typing commands into every victim network. Once discovery, exploitation and collection can be sufficiently automated, the attacker can manufacture activity at a scale that would require an army of human defenders to match manually.

The bad guys can, theoretically, go to the beach.

The exploit does not need sunscreen.

But wait. Who gives the cybercriminals their vacation?

Here the story takes a much more entertaining turn.

Remember Conti, the criminal organization with vacation requests and burnout complaints?

In November 2021, a Conti member using the handle “Skippy” mentioned plans to travel abroad during the new year. A manager warned that leaving Russia created the possibility of arrest. The advice was essentially: if you're going anyway, make sure the phone is clean and don't bring the laptop.

That conversation exposes one of the fundamental asymmetries of transnational cybercrime.

A person sitting behind a computer in a jurisdiction unwilling or unable to arrest them may feel almost untouchable.

Then that person gets on an airplane.

Suddenly borders matter again.

Treaties matter.

International police cooperation matters.

Passports matter.

The anonymous digital supervillain has transformed himself into a tired guy standing at passport control holding a little wheeled suitcase.

Roman goes to the Maldives

Roman Seleznev was exactly the sort of cybercriminal who benefited from distance and jurisdiction.

U.S. investigators accused him of hacking point-of-sale systems and stealing massive quantities of payment-card data. For years, reaching him presented the familiar difficulty of pursuing a Russian cybercrime suspect from the United States.

Then Seleznev went on vacation.

To the Maldives.

In 2015, a Justice Department official summarized the operation with almost comic economy: foreign partners had arrested the “notorious Russian hacker” the previous year, and “He was vacationing in the Maldives.” Seleznev was subsequently brought to the United States, convicted and sentenced to 27 years in prison.

That is the cybercriminal equivalent of spending ten years building an impregnable castle and then stepping outside because the resort brochure looked nice.

He was not identified because he ordered a piña colada. An enormous investigative effort preceded the arrest. The vacation mattered because travel put a wanted man somewhere law enforcement could physically reach him.

That distinction is important.

Vacation did not solve the case.

Vacation changed the geography of the case.

And geography can be the difference between “we know exactly who he is” and “we have him.”

Alexander goes to Greece

Alexander Vinnik provides another example.

U.S. authorities accused Vinnik of operating or controlling accounts associated with BTC-e, the cryptocurrency exchange that prosecutors alleged had handled more than $4 billion and facilitated transactions connected to hacking, ransomware, fraud, identity theft and other crimes.

Vinnik was Russian.

But in July 2017, Vinnik was not in Russia.

He was on holiday in a seaside village in Greece.

Greek authorities arrested him on a U.S. warrant. What followed was a years-long international extradition struggle involving Greece, France, Russia and the United States. Vinnik eventually pleaded guilty in the United States in 2024 to conspiracy to commit money laundering; he was later returned to Russia in the 2025 exchange that freed American Marc Fogel.

The larger lesson survives the complicated legal aftermath.

For certain internationally wanted cybercriminals, the most dangerous piece of consumer electronics they own may not be their computer.

It may be their passport.

And then there is Instagram

Travel, however, is merely one way to drag an online identity into physical reality.

Another is to spend half your waking life yelling LOOK AT ME into a social-media platform.

Which brings us inevitably to Ramon Olorunwa Abbas, better known online as Ray Hushpuppi.

Hushpuppi built a huge social-media following around an image of extraordinary wealth. Designer clothing. Luxury automobiles. Private aviation. Expensive watches. Dubai. Paris. Shopping bags.

The FBI did not have to conduct a clandestine surveillance operation to discover this material.

He posted it.

Publicly.

In the criminal complaint, an FBI agent wrote that the publicly accessible Hushpuppi Instagram account had more than 500 posts and 2.3 million followers by June 2020. Investigators compared its photographs with passport and identification images. Hundreds of Instagram photos depicted Abbas in designer clothing, luxury vehicles, high-end watches and other displays of wealth.

One photograph featured a white Rolls-Royce Cullinan.

The hashtag was:

#AllMine.

There are moments when satire discovers it has arrived too late.

The complaint goes on to describe photos involving Bentleys, Ferraris, Mercedes vehicles, Rolls-Royces, private jets and luxury retailers. Subscriber information tied the Instagram account to an email address and telephone number, while Snapchat information and data from a co-conspirator's phone helped connect the various identities investigators were assembling.

And then came the birthday cakes.

Investigators had identification documents giving Abbas' birthday as October 11, 1982. His Instagram account also provided corroboration. A 2018 post thanked followers for birthday wishes received the previous day. A 2017 photograph displayed a cake bearing the words “Happy Birthday Ramon.”

The FBI put the birthday-cake posts in the affidavit.

Imagine spending years learning money laundering, maintaining aliases and moving money across international boundaries only to discover that Special Agent Innocenti has entered Exhibit: Gucci Birthday Cake into the chronology.

This does not mean Instagram single-handedly caught Hushpuppi. That would make a better meme than a factual account. Investigators had communications, financial records, subscriber information, account data, identification documents and cooperation from multiple countries.

But his public social-media life gave them corroborating material that helped connect the glamorous persona, the accounts and the physical human being.

Abbas was arrested in Dubai in June 2020, brought to the United States, pleaded guilty, and in 2022 received a 135-month federal prison sentence. The court also ordered more than $1.7 million in restitution to two victims. DOJ's sentencing announcement explicitly described his social-media lifestyle as crime-funded.

Operational security lesson number one:

Do not reuse passwords.

Operational security lesson number two:

Perhaps do not annotate the Rolls-Royce with #AllMine.

Cybercrime discovers bottle service

If Hushpuppi seems like an unusually flamboyant historical specimen, allow the United States Department of Justice to introduce the next generation.

Beginning no later than October 2023, according to federal prosecutors, a group of young men who had formed friendships through online gaming platforms developed into what DOJ describes as a cyber-enabled criminal enterprise. Members allegedly specialized in hacking databases, identifying wealthy cryptocurrency holders, socially engineering victims, laundering stolen cryptocurrency and even conducting physical burglaries aimed at hardware wallets.

Federal prosecutors say the enterprise stole more than $263 million.

What did they do with the proceeds?

Apparently they decided subtlety was for losers.

DOJ alleges that members spent as much as $500,000 in a single evening at nightclubs. They bought luxury watches costing hundreds of thousands of dollars. They rented private jets and mansions. They hired private security. They assembled a fleet of at least 28 exotic cars, some worth millions. One indictment announcement summarized the spending as approximately $4 million at nightclubs and $9 million on exotic cars.

There were handbags handed out at parties.

There were houses renting for $40,000 to $80,000 a month.

There were Lamborghinis.

There were Rolls-Royces.

There was, almost inevitably, Miami.

One participant, Evan Tangeman, ultimately admitted laundering at least $3.5 million. After arrests began, prosecutors said he attempted to arrange the destruction of digital devices. In April 2026 he was sentenced to 70 months in prison. The U.S. Attorney's Office described the greed behind the enterprise as so brazen that it “borders on the cartoonish.”

For once, the government press release writer needed no assistance from us.

Again, it would be inaccurate to say, “They bought Lamborghinis, therefore the FBI caught them.” Complex criminal investigations do not work like an episode of Scooby-Doo. The prosecution describes extensive investigative work, money laundering, digital evidence, arrests and efforts to destroy evidence.

But extravagant consumption creates a problem for criminals that no VPN can solve.

A Lamborghini is not pseudonymous.

A mansion has an address.

A private jet has a flight plan.

A watch has a dealer.

A nightclub has cameras.

A Rolls-Royce has a vehicle identification number.

The internet permits a person to construct layers between a handle and a human being.

Wealth has an irritating habit of peeling those layers back off.

Pseudonyms are cheap. Meatspace is expensive.

That, ultimately, is what makes the vacation stories more than amusing anecdotes.

Cybercriminals are subject to two very different worlds.

In the digital world, they can obscure IP addresses, use aliases, communicate through encrypted services, move cryptocurrency through complicated chains and operate infrastructure on several continents.

Then they want to enjoy the money.

Enjoyment is inconveniently physical.

You cannot drive a cryptographic hash to Monaco.

You cannot wear a VPN to dinner.

Nobody has yet figured out how to sit beside the virtual swimming pool of a shell corporation.

Eventually someone wants the Ferrari, the beachfront hotel, the watch, the nightclub table, the villa or the first-class boarding pass.

And every movement from abstract wealth toward physical pleasure potentially creates records, witnesses, cameras, border crossings, account relationships and identifiable property.

The criminal's weekend therefore creates the mirror image of the defender's weekend.

Our leisure can make us vulnerable to them.

Their leisure can make them vulnerable to us.

So does everybody in IT have to cancel Christmas?

No.

That is precisely the wrong lesson.

A functioning defensive strategy cannot depend on persuading security personnel never to sleep, go camping, see their children or drink a beer on Christmas Eve. Besides being cruel, that does not scale.

The objective is not to eliminate weekends.

It is to eliminate unprotected weekends.

CISA's holiday guidance tells organizations to identify security personnel who can surge during weekends and holidays if an incident occurs. Its ransomware guidance emphasizes offline backups because ransomware frequently seeks accessible backup systems, and recommends regularly testing restoration rather than merely assuming backups work. CISA also emphasizes patching, multifactor authentication, incident-response preparation and protection of remote-access pathways.

The practical goal is continuity.

Before a holiday begins, somebody should know who has authority to declare an incident. Somebody should know how to reach the cloud provider, MSP, insurer and incident-response firm without looking up phone numbers on a compromised laptop. Critical alerts must reach an actual human. Backups must be isolated enough that the attacker cannot simply encrypt those too. Administrators should not discover during the crisis that their emergency communications system requires the Active Directory server currently being encrypted.

And there is a cultural point here as well.

A skeleton crew should mean fewer people performing a rehearsed mission, not whoever happens to notice Teams exploding while standing in line at Home Depot.

Good resilience gives the security team something cybercriminals have apparently already discovered for themselves:

A vacation policy.

Have a nice weekend

There is a wonderful irony buried beneath all of this.

We imagine cybercriminals as creatures who inhabit some permanent nocturnal underworld, operating beyond the rhythms of ordinary life.

Then their internal messages leak and we discover that they have managers, paydays, vacations, coworkers they hate and opinions about burnout.

They are waiting for our employees to leave early on Friday.

Their own employees would also like to leave early on Friday.

They schedule ransomware for Christmas.

Then they request Christmas off.

They hide behind pseudonyms for years.

Then they fly to the Maldives.

They launder cryptocurrency through layers of technical complexity.

Then somebody buys a Rolls-Royce, parks it in front of a camera and posts a photograph.

#AllMine.

There is a serious security lesson underneath the comedy.

Time is part of the attack surface. Staffing is part of the attack surface. Holidays are part of the attack surface. The enemy does not need to defeat every security technology if it can arrange for the important warning to arrive when nobody is looking.

But cybercriminals have an attack surface too.

They are human.

Humans get tired. Humans take vacations. Humans become vain. Humans fall in love with cars. Humans brag. Humans cross borders. Humans have birthdays.

Sometimes they even photograph the cake.

So by all means, take the weekend off.

Just make sure somebody is watching the network.

And if your weekend plans are being financed by several hundred million dollars in stolen cryptocurrency, perhaps resist the urge to post the Lamborghini.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.