By Gregory Lemmon | Managing Director, UBIQUITY Ltd
Cybersecurity & Disaster Recovery Consultants to the Caribbean
The storm has passed.
The wind has died down. The streets are starting to clear. Your team is checking in. The damage assessment has begun. Leadership is focused on getting the business back open as quickly as possible.
This is the moment many Caribbean businesses feel the worst is behind them.
It is also the moment cybercriminals have been waiting for.
The first 72 hours immediately following a major hurricane event are consistently the highest-risk window for cyberattacks against businesses. Not during the storm. After it. When attention is on the physical recovery, when defences are at their lowest and when the conditions that opportunistic criminal networks specifically plan for are fully in place.
This is exactly what happens in those first 72 hours, and why businesses that are not prepared for it are facing a second threat they never saw coming.
Hour 1 to 6 – The Reconnaissance Window
Before a ransomware attack is deployed. Before a phishing email is sent. Before any visible attack occurs, the first thing that happens in the post-storm window is reconnaissance.
Automated scanning tools used by criminal networks identify businesses whose systems have gone offline during the storm and are now coming back online. Reconnecting systems after an outage frequently exposes vulnerabilities in software that was running continuously and is now restarting, security tools that need to reinitialise, and network configurations that behave differently when restoring from an outage than they do under normal operating conditions.
This scanning happens silently and at scale. Thousands of endpoints assessed in minutes. Businesses with exposed vulnerabilities flagged for targeting. All of it before a human attacker has made a single decision.
For businesses reconnecting systems after a hurricane without first running security checks, this window is when the foothold gets established.
Hour 6 to 24 – The Phishing Wave
Within the first day after a major Caribbean storm event, phishing campaigns targeted at businesses in the affected region begin arriving in inboxes.
These are not generic phishing emails. They are specifically crafted for the post-storm context and designed to exploit the psychological conditions that exist in the hours after a hurricane.
The insurance notification. An email appearing to come from an insurer advising the business to click a link to begin the claims process. The email matches the insurer’s branding. The link goes to a convincing replica of the insurer’s portal designed to capture login credentials.
The government relief application. An email appearing to come from a government agency advising that emergency business relief funds are available and that the business must complete an application within 24 hours. The urgency is deliberate. The link is fraudulent.
The supplier update. An email appearing to come from a known supplier advising that banking details have changed for upcoming payments the disruption of the storm making the timing of the request feel plausible.
The IT system restoration notice. An email appearing to come from a cloud provider or software platform advising that the account needs to be re-verified following storm-related service disruption. The link captures credentials that give attackers access to business systems.
Every one of these exploits the specific context of the post-storm period. The insurance claim feels urgent because there is real damage to claim for. The government relief application feels timely because the business genuinely needs support. The supplier banking update feels plausible because disruption makes procedural changes feel normal.
And the staff receiving them are exhausted, distracted and operating under pressure exactly the conditions that reduce scrutiny and increase the likelihood of a click.
Hour 24 to 48 – The Credential Harvest
The phishing campaigns of the first 24 hours have one primary objective harvesting credentials.
Usernames and passwords captured through fake login pages give attackers legitimate access to business systems. Not access that triggers security alerts. Legitimate access using real credentials, from locations that may appear normal, accessing systems in ways that look like ordinary business activity.
This is where the attack becomes invisible.
Once inside a system using legitimate credentials, attackers do not immediately deploy ransomware or exfiltrate data. They move quietly. They explore the network. They identify where the valuable data lives. They assess what access the compromised account gives them and what additional access they can reach from it.
They are looking for several things specifically:
Finance system access. Payment platforms, banking portals, accounting software. Understanding the business’s financial workflows is preparation for business email compromise fraudulent payment requests that arrive later, once the attacker understands exactly how the business handles its finances.
Administrative access. Accounts with elevated permissions that can reach more of the network, disable security tools or create new accounts that persist even if the compromised credential is later changed.
Data repositories. Where client data, contracts, financial records and confidential business information is stored. This is preparation for data exfiltration the precursor to ransomware with double extortion demands.
Backup systems. Modern ransomware groups specifically locate and target backup systems before deploying encryption. A ransomware attack that can also encrypt the backup removes the victim’s ability to restore without paying.
All of this happens silently in the 24 to 48 hour window. The business is focused on storm recovery. Nobody is monitoring the network. The attacker is learning everything they need to know.
Hour 48 to 72 – The Attack
By the third day after the hurricane the attacker has what they need.
The ransomware is typically deployed overnight or early morning when the chance of immediate detection is lowest. Files encrypt across the network. Backup systems that were located during reconnaissance are hit simultaneously. The ransom note appears.
Or the business email compromise is executed. A carefully crafted email arrives in the finance manager’s inbox appearing to come from the MD using language, tone and context informed by weeks of reading internal communications instructing an urgent wire transfer to a new account. The request is specific, plausible and arrives during a period when the MD’s unavailability during storm recovery makes verification feel difficult.
Or the data exfiltration is quietly completed. Client records, financial data and confidential business information copied out of the network to the attacker’s infrastructure setting up either a ransom demand or a quiet sale on dark web marketplaces.
In all cases the attack lands at the moment the business is least equipped to respond. IT resources stretched. Leadership focused on physical recovery. Staff dealing with their own storm situations. The incident response capacity of the business which was limited before the storm, is at its lowest point.
Why This Pattern Repeats Every Year
Caribbean businesses are not being randomly targeted in the post-storm window. They are being systematically targeted because the pattern is predictable and the conditions it creates are consistently exploitable.
Criminal networks running post-storm campaigns are not making decisions in real time. They prepare in advance. Phishing templates built around Caribbean insurance companies, Caribbean government agencies and Caribbean business context are prepared before hurricane season begins. Scanning infrastructure is positioned. The operations are ready to run the moment a storm makes landfall.
The attack is not improvised. It is a planned operation executed against predictable conditions.
Caribbean businesses on the other side of this need to be equally prepared. Not reactive. Not figuring out the response during the 72-hour window when the attack is already in motion. Prepared before the season, with protections in place that hold through the storm and the recovery period that follows.
What Prepared Caribbean Businesses Do Differently
The businesses across the Caribbean that come through hurricane season without a cyber incident are not the ones that get lucky. They are the ones that closed the specific gaps that post-storm attacks exploit.
They brief staff before the storm not after.
Before a hurricane makes landfall, staff receive a specific briefing on post-storm phishing. What communications to expect from insurers, government agencies and IT providers. What the verification procedure is before clicking any link or making any payment. What to do if something feels wrong.
They maintain monitoring through the recovery period.
Security monitoring does not pause because the office is closed. Systems are configured to alert on unusual activity during and after the storm period. The reconnection of systems after an outage is treated as a security event requiring verification not just a routine restart.
They run security checks before reconnecting systems.
Before systems come back online after a storm-related outage, a basic security review confirms that reconnection does not expose vulnerabilities. This is not a lengthy process. It is a deliberate step that the businesses without this habit skip entirely.
They enforce verification procedures for financial transactions.
A standing policy that any payment instruction received in the 72 hours following a storm event requires voice verification from a known number regardless of how plausible or urgent it appears, stops the majority of business email compromise attempts in the post-storm window cold.
Their backup is offsite and tested.
A backup stored on-site or connected to the primary network is vulnerable to the same ransomware that hits the primary systems. An offsite, cloud-based, tested backup removes the leverage that ransomware depends on in the post-storm recovery period.
The Window Is Predictable. The Preparation Is Not Optional.
Every Caribbean business owner reading this knows hurricane season is coming. The storm track is uncertain. The timing is uncertain. The intensity is uncertain.
What is not uncertain is what happens in the 72 hours after it passes.
The phishing campaigns will arrive. The scanning tools will run. The credential harvesting will begin. The attacks will be deployed against the businesses that did not prepare for them.
The businesses that come through intact are the ones that understood this pattern before the season started and put the protections in place while there was still time to do it properly.
That window is still open.
But it closes when the storm arrives.
UBIQUITY Ltd provides cybersecurity and disaster recovery services to businesses across the Caribbean. Disaster Recovery and Cybersecurity Assessments are available this hurricane season, including a specific review of post-storm vulnerability and recovery readiness.
Contact Us-
Email: info@ubiquityltd.com
Phone: +1 (284) 547-6754
Calendly Link- https://calendly.com/glemmon-wpi/15min?month=2026-07