Had an incident at a client's site, posting with their permission and without naming names. Not trying to scare anyone, just showing how the process works.
Noticed it on a Friday night. File extensions on the file server had changed and a text file was dropped in every folder.
First thing we did was right: didn't shut down systems, just isolated them from the network. Shutting down destroys memory evidence, isolating stops the spread.
Then we answered three questions in order: where did they get in, how far did it spread, is our backup clean.
The answer to the first question wasn't what we expected. No vulnerability. There was a remote desktop connection open to the outside and a user's password had leaked from somewhere else. So not a technical flaw, just an open door.
The backup question saved us, but barely. Daily backups were being taken, but the backup server was on the same network and accessible with the same credentials. The only reason it wasn't encrypted is that the process was stopped before it finished that night.