The New IT Reality — Part 8 of 12
A series examining how technology, AI, and cyber threats are reshaping business.

Your servers have been running at 90% CPU for months. Your electricity bill has inexplicably doubled. Your employees complain about slow computers every morning. You blame Windows updates, aging hardware, perhaps even the summer heat. You are wrong. Someone is using your infrastructure to make money — and they have been doing it for longer than you think.

What Is Cryptojacking?

Cryptojacking is the unauthorised use of your computing resources to mine cryptocurrency. It is, in its simplest form, theft — not of data, not of money from your accounts, but of your electricity, your hardware capacity, and your processing power. The attacker installs mining software on your systems, and your machines do the computationally intensive work of generating cryptocurrency. The coins go to the attacker's wallet. The electricity bill goes to you.

Unlike ransomware, which announces itself dramatically and demands payment, cryptojacking is designed to be invisible. There is no ransom note, no locked files, no dramatic popup. The attacker's entire business model depends on you not noticing. The longer you remain unaware, the longer they profit.

How It Gets In

The entry points are the same vulnerabilities that every other form of malware exploits, because cryptojacking is malware — it simply has a different payload. Compromised websites can inject mining scripts into your browser sessions. Phishing emails deliver mining trojans disguised as invoices or delivery notifications. Unpatched servers — particularly those running outdated versions of content management systems, database engines, or remote access tools — are scanned and exploited automatically by botnets that deploy miners within minutes of gaining access.

Cloud environments are particularly attractive targets. A compromised set of cloud credentials can spin up mining instances across multiple regions, generating enormous compute bills before anyone notices. There have been documented cases where organisations received cloud invoices exceeding €50,000 in a single month from mining activity running on hijacked accounts.

Why You Cannot See It

Modern cryptojacking malware is engineered to stay below the detection threshold. Sophisticated variants monitor system activity and throttle their CPU usage when a user is actively working, ramping up only during idle periods — nights, weekends, lunch hours. Some variants detect when task manager or system monitoring tools are opened and temporarily suspend operations. Others distribute their workload across dozens or hundreds of machines, consuming only 10-15% of each system's capacity — enough to be profitable in aggregate, too little to trigger alarms on any individual device.

This is why traditional antivirus solutions frequently miss cryptojacking. The software is not destroying files or exfiltrating data in ways that trigger behavioural detection. It is simply performing mathematical calculations. The fact that those calculations happen to generate cryptocurrency for a criminal is invisible to most security tools.

The True Cost: More Than Electricity

The financial impact of cryptojacking operates on multiple levels. The most obvious is electricity. Cryptocurrency mining is phenomenally energy-intensive. A single compromised workstation running a mining process can consume an additional 200-400 watts continuously. Across a fleet of 50 machines, that translates to roughly €3,000-€8,000 per year in excess electricity costs, depending on local energy prices. For servers running at full load, the figures are substantially higher.

Then there is hardware degradation. CPUs and GPUs running at sustained high loads generate excessive heat. Fans run constantly, bearings wear out, thermal paste degrades, and components that should last five to seven years fail in two or three. The cost of premature hardware replacement across an organisation is significant — and it is a cost that most businesses attribute to normal wear and tear, never realising the true cause.

Employee productivity losses compound the problem. Systems running mining software in the background are measurably slower. Applications take longer to load, multitasking becomes painful, and workers develop workarounds — or simply accept that "computers are slow" as a fact of life. The aggregate productivity loss across an organisation can dwarf the electricity costs.

The Bigger Problem You Are Not Seeing

Here is the detail that should concern every business leader far more than electricity bills and hardware replacements: if an attacker has sufficient access to your systems to install and operate cryptocurrency mining software, they have sufficient access to do anything. They can read your email. They can copy your client database. They can exfiltrate your financial records. They can deploy ransomware across your entire network in minutes.

Cryptojacking is increasingly understood by security researchers as a "side hustle" for more sophisticated threat actors. The mining generates a steady revenue stream — modest but consistent — while the attacker maintains persistent access to your network for future exploitation. They are patient. The mining pays the bills while they map your infrastructure, identify your most valuable data, and wait for the optimal moment to escalate their attack.

In several documented incidents, organisations that discovered and removed cryptojacking malware were hit with ransomware attacks within weeks. The miners were the canary in the coal mine — an early indicator of a much deeper compromise that had gone undetected.

Warning Signs

Know what to look for:

  • Unexplained CPU or GPU usage spikes — particularly during off-hours when systems should be idle
  • Higher electricity bills — consistent increases without corresponding changes in operations
  • Slower system performance — widespread complaints across multiple machines simultaneously
  • Fans running constantly — hardware cooling systems working harder than they should
  • Increased network traffic to unknown IP addresses — miners must communicate with mining pools, generating detectable outbound connections
  • Overheating hardware — systems running hotter than their workload justifies
  • Unexpected cloud computing charges — sudden increases in compute resource consumption

The Greek Reality

For Greek businesses, cryptojacking carries a particularly harsh financial sting. Electricity costs in Greece remain among the highest in the European Union, meaning that the energy theft component of a cryptojacking attack is proportionally more expensive than in many other countries. A compromised server farm in Athens costs the victim more in electricity than an identical compromise in Berlin or Amsterdam.

The problem is compounded by the monitoring gap. Many small and medium-sized enterprises in Greece operate without centralised system monitoring, endpoint detection, or network traffic analysis. Without these tools, cryptojacking can persist for months or even years without detection. The symptoms — slow computers, high electricity bills — are attributed to other causes and tolerated as the cost of doing business.

Furthermore, the prevalence of older, unpatched systems and legacy hardware in the Greek business landscape creates a target-rich environment. Systems running unsupported operating systems or unpatched software are trivially exploitable by automated scanning tools, and once compromised, the lack of monitoring ensures the miners operate undisturbed.

Key Takeaway
Cryptojacking is not merely a nuisance — it is proof of compromise. Every machine running unauthorised mining software represents a system where an attacker has established persistent access, and that access can be weaponised for data theft, ransomware deployment, or complete network takeover at any moment. The electricity and hardware costs are real, but the true danger is what the attacker chooses not to do — yet.

The worst thing about cryptojacking is not the electricity they steal or the hardware they burn through. It is what it proves: someone has root access to your systems, and you did not notice. If they can mine cryptocurrency on your infrastructure, they can read your emails, copy your files, and hold your entire business for ransom. They simply have not decided to — yet.

Worried your systems might be compromised?
IWH provides infrastructure security assessments and threat detection services. Contact us for a confidential evaluation.