How a Ransomware Attack Hit a 137-Year-Old Shoe Business | Mike Schuler

Mike Schuler of Schuler Shoes shares what happened when ransomware hit his family’s 137-year-old footwear business — and the cybersecurity lessons every independent retailer should understand before an attack happens.

Most independent retailers don’t expect a cyberattack to happen to them.

Until it does.

For Mike Schuler and the team at Schuler Shoes, that moment came over a holiday weekend when systems began going down, files were being encrypted, and the business suddenly had to figure out how to keep 10 stores operating while dealing with a ransomware attack.

This wasn’t a hypothetical cybersecurity exercise.

It was happening in real time.

Schuler Shoes is a fourth-generation family footwear business based in the Minneapolis area. The company has been operating for 137 years.

And like most retailers, their focus has always been on serving customers, fitting people well, managing inventory, supporting employees, and running stores.

Cybersecurity wasn’t why anyone got into the shoe business.

But technology has become so deeply connected to retail operations that protecting those systems is now part of protecting the business itself.

In this episode of The Footwear Retailer Podcast, Mike joins me to share exactly what happened, what the first few hours looked like, how his team kept selling, how long recovery actually took, and what Schuler Shoes changed afterward.

The Call No Retailer Wants to Receive

Mike was away on vacation when he first heard that something wasn’t right.

His IT person had received notifications that systems weren’t responding properly.

He headed into the office to investigate.

Then things started snowballing.

Files were being encrypted.

Machines and servers stopped responding.

Passwords were being changed.

The attackers were attempting to maintain access while locking the company out of its own systems.

And Mike wasn’t even there.

He was away from the business over a holiday weekend, trying to make decisions remotely while the extent of the attack was still becoming clear.

That creates an uncomfortable question very quickly:

What do we do first?

The First Big Decision: Shut Down the Internet

Schuler Shoes had recently purchased cyber liability insurance.

That decision became incredibly important.

Mike and his team contacted their insurance provider, which quickly connected them with people experienced in responding to ransomware attacks.

One of the first recommendations sounded extreme.

Shut down the internet.

For a modern retailer, that’s a significant decision.

Internet connectivity touches almost everything.

  • Point-of-sale systems
  • Credit card processing
  • Email
  • Shared files
  • Vendor websites
  • Cloud applications
  • Internet-based phone systems
  • Administrative tools

And the stores were open.

It was Memorial Day weekend, a time when customers were out shopping and the business didn’t exactly want to make buying shoes more difficult.

But the cybersecurity team explained something important.

Leaving everything connected could allow the attack to keep spreading.

The short-term pain of disconnecting could prevent significantly more damage later.

So they did it.

How Do You Keep Selling When Your Systems Are Down?

Fortunately, Schuler Shoes had one major advantage.

Their point-of-sale system could operate offline.

That allowed the stores to continue ringing up purchases.

Credit cards were another challenge.

The company had backup card readers available, but those devices still needed an internet connection.

The solution was relatively simple:

Hotspots.

The team connected the backup payment devices separately and continued processing customer transactions.

It wasn’t perfect.

Some Schuler Shoes locations normally had four, five, or even six POS stations.

Suddenly, they might have only one or two backup payment devices available.

That created bottlenecks.

But the stores stayed open.

Customers could still buy shoes.

And Mike credits his team with doing an incredible job of keeping the retail side of the business functioning.

The Bigger Disruption Happened Behind the Scenes

The stores were able to keep selling.

The office was another story.

Administrative employees needed internet access to work with vendors, access shared files, review spreadsheets, use email, and handle countless other daily tasks.

Those systems had to remain unavailable until the response team knew they were safe.

The company’s phones were internet-based too.

Those went down.

Shared servers were disconnected.

Email access disappeared.

Some employees were essentially unable to do their jobs.

Mike estimates that some members of the team were on paid leave for roughly a week, possibly extending into a second week, while the systems were gradually restored.

And that creates another challenge during a cyberattack.

After the initial emergency passes, everyone starts asking the same question:

Are we back yet?

Recovery Couldn’t Be Rushed

The answer wasn’t as simple as turning everything back on.

At one point, the team tested a machine that had been infected.

The malicious activity started again.

Back off it went.

That machine was compromised.

It couldn’t simply be trusted because the immediate attack appeared to have stopped.

The recovery team instead began working methodically.

What systems did Schuler Shoes absolutely need?

What connections could safely be restored?

What should come back first?

Access to point-of-sale reporting.

Email.

Vendor resources.

Shared tools.

One piece at a time, the business regained enough functionality for the administrative team to return to work.

But restoring normal operations and restoring all of the company’s data were two very different things.

Getting the Data Back Took Months

Mike estimates that the broader data recovery process took around two months.

Fortunately, Schuler Shoes recovered the majority of its information.

But even after encrypted data became available again, the company couldn’t simply put it straight back into production.

The cybersecurity consultants needed to scan it.

They needed to make sure the restored information was clean.

Compromised systems also needed to be rebuilt.

That’s one of the difficult realities of a ransomware attack.

The moment you regain access to something isn’t necessarily the moment you can trust it again.

Ransomware Is a Business

One of the stranger parts of Mike’s experience was seeing how structured the ransomware world can be.

There were negotiations.

There were experienced professionals dealing with the attackers.

There were discussions about recovering encrypted files.

The cyber insurance company remained involved throughout the process.

Mike described it as realizing that ransomware itself operates almost like a business.

Attackers can even develop reputations around whether they actually provide working decryption keys after being paid.

It’s an unsettling idea.

Retailers work hard to build reputations around serving customers honestly.

Meanwhile, criminal groups can build their own reputations around whether they reliably unlock the files they’ve illegally encrypted.

The Security Hole Was Something the Business Actually Needed

After the immediate crisis, the cybersecurity team helped Schuler Shoes understand how the attack happened.

One of the biggest vulnerabilities was a remote-access device that had been introduced during the pandemic.

At the time, it solved a real problem.

Employees needed remote access.

The company purchased technology that allowed them to work that way.

Years later, however, usage had dropped dramatically.

The security risk hadn’t.

The device was still being updated, but Mike says the cybersecurity team found that it contained significant vulnerabilities.

The recommendation was straightforward:

Get rid of it.

That introduces an important question for any established retailer:

“Do we still need this?”

Businesses accumulate technology.

Software.

Remote connections.

Vendor access.

Security cameras.

Door systems.

Third-party applications.

Tools that once solved an important problem may remain connected years after the original need has changed.

Every connection can potentially create another opening.

Password Management Became a Priority

Before the attack, Schuler Shoes didn’t have one standardized password-management system across the company.

That changed.

The company adopted 1Password.

Like any new system, adoption varies from employee to employee.

But it gives the organization a more secure and recoverable place to manage credentials.

That’s especially important if a computer eventually needs to be completely wiped.

Passwords stored only on that device or in a browser may disappear along with everything else.

A dedicated password manager provides another layer of protection and recovery.

Multi-Factor Authentication Is Worth the Extra Step

Another improvement was stronger adoption of multi-factor authentication.

We’ve all seen the prompt.

Set up MFA.

Verify your identity.

Enter the extra code.

And it’s tempting to think:

I’ll deal with that later.

Mike’s experience is a reminder that the extra few seconds aren’t there simply to make logging in annoying.

They’re another barrier between an attacker and your business.

Schuler Shoes Upgraded Its Endpoint Protection

The cybersecurity team also recommended upgrading the company’s antivirus tools to a more modern endpoint detection platform.

There wasn’t necessarily anything fundamentally wrong with what Schuler Shoes had been using before.

The threat environment had simply changed.

Malicious software changes constantly.

And with AI making it easier to create variations of attacks, security tools increasingly need to recognize suspicious behavior instead of relying only on identifying something they’ve already seen.

About six months after the ransomware incident, the investment already demonstrated its value.

An employee clicked something malicious in an email.

The new protection caught it.

That was a pretty clear reminder of why the upgrade mattered.

Your Backup Can Be Attacked Too

Backup strategy became another major learning.

Schuler Shoes had backups.

But those backups were connected to the rest of the system.

So the ransomware encrypted them too.

This is something attackers often deliberately target.

If a business has a clean backup, the attackers lose much of their leverage.

If they can destroy or encrypt the backups first, recovery becomes much harder.

Schuler Shoes began putting more effort into keeping certain backups separated or off-site.

They also invested in additional backup protection for cloud systems.

Mike isn’t particularly concerned that companies like Google or Microsoft are simply going to disappear one day.

That’s not really the point.

The additional backup provides another independent copy of important information.

If something happens to the primary environment, the business has somewhere else to recover from.

Having a Backup Isn’t Enough

This part of Mike’s story hit particularly close to home for me.

I went through my own ransomware attack back in 2018.

In my case, the attackers got into our systems through third-party access connected to someone working on our website.

They were inside for months before the ransomware demand arrived.

We were backing up our data every day.

There was just one problem.

We weren’t testing the backups.

We assumed that because the backup process was happening, those backups were usable.

They weren’t.

Our backups were compromised too.

We ultimately lost around three months of customer and transactional history from the POS environment and moved to a different point-of-sale system.

It’s an important distinction.

Don’t just ask:

Do we have backups?

Ask:

Can we actually restore them?

Cyber Insurance Changed the Financial Outcome

Mike says Schuler Shoes had been putting off buying cyber insurance for years.

Like many types of insurance, it’s easy to look at another premium and wonder whether you’ll ever use it.

They had finally purchased coverage roughly 15 months before the attack.

Then they needed it.

The ransom itself wasn’t the largest expense.

The response teams, cybersecurity experts, remediation work, rebuilding systems, and other recovery expenses created a much larger bill.

Mike estimates the total costs exceeded:

$250,000.

Most of that was covered by their cyber insurance policy, minus the deductible.

Without the policy, Mike says the company probably wouldn’t have hired the same level of outside expertise.

They might have simply accepted some lost data, rebuilt what they could, and moved forward.

But that would have created costs of its own through lost productivity, duplicated work, and a slower recovery.

Cyber Insurance Is Becoming Harder to Get

There’s another side to the insurance conversation.

Carriers increasingly want businesses to demonstrate that they’re taking reasonable cybersecurity precautions before providing coverage.

That may mean having things like:

  • Multi-factor authentication
  • Modern endpoint protection
  • Secure backups
  • Password policies
  • Employee training
  • Documented security procedures

Cyber insurance shouldn’t replace cybersecurity.

The two increasingly work together.

What Customer Data Are You Holding?

Schuler Shoes was fortunate in another important way.

The company ultimately didn’t need to make the type of public disclosure that can come with a major personal-data breach.

The investigation determined that the incident hadn’t resulted in the kind of exposed personally identifiable information that would trigger those requirements in their situation.

That isn’t always what happens.

And for retailers, it’s worth thinking about how much customer information moves between systems and outside partners.

Are you downloading customer lists?

Sending files to agencies?

Emailing spreadsheets?

Giving vendors access to systems?

Collecting health-related information?

For footwear retailers with pedorthic services or other medically related areas of the business, the sensitivity of that information may be even greater.

The more valuable the data, the more important it becomes to understand where it’s going and how it’s being protected.

Train Employees Before They Click the Real Thing

Schuler Shoes has also introduced routine phishing tests for employees.

The company sends realistic-looking test emails based on the kinds of scams employees might actually receive.

Maybe it’s a payroll update.

Maybe it’s a link asking someone to log in.

Maybe it appears to come from someone inside the business.

Sometimes employees click them.

That’s part of the point.

The goal isn’t to embarrass someone.

It’s much better to click a fake malicious link during a training exercise than a real one during an attack.

And these scams are becoming more convincing.

AI makes it easier to generate professional-looking emails, mimic communication styles, and create messages that don’t contain the obvious spelling mistakes and awkward language people once associated with phishing attempts.

Your employees are part of your cybersecurity system.

Create a Response Plan Before You Need It

One of Mike’s most practical recommendations doesn’t require expensive software.

Talk about what happens if something goes wrong.

Who needs to be on the first call?

Who contacts IT?

Who contacts the insurance company?

Who communicates with employees?

Which systems can be shut down immediately?

Which ones absolutely need to stay operating?

How will stores accept payments?

How will leadership communicate if email and phones aren’t available?

You don’t need to predict every possible scenario.

The problem doesn’t even have to be ransomware.

It could be a fire.

A flood.

A major internet outage.

A server failure.

A natural disaster.

The important thing is knowing who makes the call and what happens first.

That alone can save valuable time during the first chaotic hour of an emergency.

Communication Matters During a Crisis

Another lesson Mike took away from the experience was the importance of communication.

During the attack and recovery, he sent multiple company-wide updates explaining what was happening.

To him, those messages sometimes felt repetitive.

To employees hearing bits and pieces from different people, they were valuable.

Without clear communication, rumors fill the gap.

And Mike heard some pretty creative ones.

Leadership doesn’t need to pretend everything is fine.

Sometimes the most useful communication is simply:

“Here’s where we’re at. We’re working on it. I’ll update you again tomorrow.”

As we discussed during the episode:

Clarity brings confidence.

Cybersecurity Is a Leadership Issue

That’s really where this conversation lands.

Cybersecurity isn’t only about computers.

It’s about protecting the business you’ve spent years building.

Retailers now depend on connected technology for nearly everything:

  • Payments
  • Inventory
  • Customer information
  • Accounting
  • Email
  • Phones
  • Vendor communication
  • Marketing
  • Security systems
  • Employee information

You don’t need to become a cybersecurity expert.

But you do need to be willing to ask uncomfortable questions.

Are we sure this system is secure?

Do we still need this remote connection?

Are employees using multi-factor authentication?

Where are our passwords stored?

Can we restore our backups?

What customer information are we holding?

What happens if our network disappears tomorrow?

Who do we call?

My Takeaway

One of the easiest cybersecurity mistakes to make is assuming that because everything worked yesterday, everything must be fine today.

Technology accumulates quietly inside a business.

A tool gets added.

A vendor needs access.

An employee starts working remotely.

A new system gets connected.

A backup runs automatically.

Years pass.

And eventually, nobody remembers exactly why some of those connections are still there.

Mike’s experience is a good reminder to occasionally stop and look at the systems around your business with fresh eyes.

You don’t need perfect cybersecurity.

You need to keep asking whether the protections you have still match the business you’re running today.

Start with some basic questions:

  • Do we have cyber insurance?
  • Are we using multi-factor authentication?
  • Do employees have a secure password manager?
  • Are our backups separated from our primary systems?
  • Have we actually tested a backup?
  • Are old remote-access tools still connected?
  • Do employees know how to recognize suspicious emails?
  • Do we know who to call first if something happens?

Because the worst time to figure out your ransomware response plan is after the files have already started disappearing.

Protect the systems. Protect the data. Protect the people. And ultimately, protect the business.

Listen to my full conversation with Mike Schuler to hear what happened inside Schuler Shoes, how the company responded to the ransomware attack, what the recovery really looked like, and the cybersecurity changes Mike believes other independent footwear retailers should consider before they’re forced to learn the same lessons firsthand.


Scan to listen to Episode 29 of The Footwear Retailer Podcast with Mike Schuler

You May Also Like…

0 Comments