Table of Contents
- How phishing email attacks start
- The insider twist: a negotiator who helped the hackers
- Why phishing email attacks keep working
- How to defend your business
- Frequently asked questions
Phishing email attacks remain the way most ransomware begins — and the weakest link in the chain is still the person clicking. That was the blunt message of a widely shared column by Florida technology executive Blake Dowling, who points to everything from everyday social engineering to a Florida ransomware negotiator who secretly helped the criminals he was hired to fight. If your business relies on email, here is what you need to know about how phishing email attacks work — and how to stop them.
How phishing email attacks start
Ransomware has been around since 1989, when researcher Joseph Popp distributed roughly 20,000 floppy disks labeled “AIDS Information” that carried an early form of ransomware. Today the delivery method is far more sophisticated, but the trigger is often ordinary: an email that looks relevant to your job.
Dowling offers a simple scenario from a cybersecurity presentation he gave with a colleague this summer: an HR department receives a Dropbox link titled “Resumes.” The sender is unknown, but the company has several jobs posted. Do you open it? No. Security tools do not always flag a seemingly clean file, because malicious content can be layered or embedded in ways designed to slip past defenses — which is why the human decision matters so much.
The insider twist: a negotiator who helped the hackers
Dowling also highlights a striking Florida case that shows how deeply attackers exploit trust. According to the U.S. Department of Justice, Angelo Martino, a former ransomware negotiator from Land O’Lakes, abused his position at a cyber incident-response company in 2023. While advising ransomware victims, he provided BlackCat/ALPHV attackers with confidential information about clients’ negotiating positions — helping the criminals maximize their ransom demands. He also conspired with other former cybersecurity professionals to attack additional U.S. victims.
Federal prosecutors say Martino and his co-conspirators extorted about $1.2 million in Bitcoin from one victim. Law enforcement seized $10 million in assets from Martino, and he was sentenced in July to 70 months in federal prison as part of the FBI’s Operation Riptide — a campaign that has produced more than 200 arrests, six infrastructure takedowns, and the seizure of 170 domains and servers.
Why phishing email attacks keep working
Phishing email attacks keep succeeding because they target the way people actually communicate. Employees trust their inboxes: an invitation to a party you never heard of, a message that looks like it is from Microsoft asking you to verify a password, a bank email asking you to confirm a routing number, a text saying your Netflix payment is late. Each one is a hook built on a real behavior.
Artificial intelligence is making the problem worse. AI-generated messages, images, and voices are more convincing than the poorly spelled scams of a few years ago, and criminals are using AI to impersonate executives, vendors, and even government agencies with alarming accuracy. The emotional triggers are the same ones that have always worked: urgency, authority, and trust.
How to defend your business
There is no single fix — but a layered approach closes most of the gaps phishing email attacks depend on:
- Train people to verify before clicking. Check the actual sender address, hover before you click, and confirm unexpected financial requests through an official channel — never by replying to the message.
- Run phishing simulations. Regular, realistic tests turn awareness into habit and show you which employees need more help.
- Require multi-factor authentication. Stolen passwords become worthless when a second factor stands in the way.
- Use strong, unique passwords. Password managers make this practical; reused credentials are how one breach becomes many.
- Keep systems patched and monitored. Updated endpoints and managed cybersecurity services block many attacks before anyone sees them.
- Maintain offline, tested backups. A strong backup strategy means ransomware has less leverage — and reduces the temptation to negotiate at all. CISA’s StopRansomware Guide lays out the full playbook.
Frequently Asked Questions
How common are phishing email attacks?
Email remains the top delivery method for ransomware. Most successful attacks trace back to a phishing email, a stolen password, or a malicious attachment.
Can security software stop phishing email attacks?
Good tools stop many attacks, but they depend on how well your security posture is configured. Layered defenses — filtering, MFA, training, and monitoring — are the realistic standard.
What should I do if I clicked a suspicious link?
Disconnect the device if possible, report it to your IT team immediately, and change your password from a different device. Time matters more than embarrassment.
Is paying the ransom ever the right move?
Law enforcement and security experts advise against it. Payment does not guarantee recovery and funds further attacks — which is why tested, offline backups are the real answer.
The weakest link in cybersecurity is human — but humans can also be the strongest layer when they are trained, supported, and protected by the right tools. Nextek IT helps South Florida businesses turn employees into a human firewall with managed IT, security awareness training, and phishing-resistant technology. Contact Nextek IT to harden your defenses before the next phishing email lands in an inbox.
Sources: Florida Politics — “Blake Dowling: Ransomware’s weakest link is still the person clicking” (Sept. 2026); U.S. Department of Justice press release — Florida ransomware negotiator sentencing (July 2026).