My old team just dealt with 4 infections of MSP clients in the last couple weeks.
EVERY one of them was a phishing email, they opened an attachment.
"All employees must fill out and sign the attached expense report, blah" - very official looking..
It is worse than anyone describes.
This was a Win7 machine with no shadow copies, no backups of Desktop/Documents, trained to use a network share - and they did - but the virus encrypted the entire network share as well.
We ended up having to go withdraw $300 from the ATM, get a greendot, and send them the money.
There were files on the shares that it wasn't worth the $300 to have to go back a day or two in backups to retrieve.
What a nightmare.
Infection 2 and 3 were in the same office, they 'double encrypted' a network a share, which was a disaster, we had a good backup in S3 and cleaned/restored from backup.
Infection 4 was an executive, most important things were in Dropbox, looked at the list of encrypted files and said 'not worth it, wipe it - lets' start over'
Since then - I'm totally shocked at how bad this thing is, it seems like we had a nice 15~ year run where viruses weren't destroying data, and now they are again. It's sad.
Seriously, the last 15 years, a virus meant your machine was spamming, or you saw ads, or they were getting your banking info, but your data was always fine.
SELL MORE BACKUPS. PEOPLE MUST HAVE GOOD BACKUPS.
IT IS TIME.