Is it common practice to have the servers running your production (not in the manufacturing sense) cloud services join the AD domain that has your office staff in it? Why? That doesn't even make any sense from a convenience PoV.
It just seems like an unfathomable level of incompetence required to go from compromising some random Windows workstation all across the hardware that runs your app services. And lest we forget: a ransomware attack is always also a massive data loss attack. Garmin better get to work complying with the law and notifying impacted customers (all of them?).
If there's one thing I've learned in the computer industry, it's that there is no such thing as an unfathomable level of incompetence. All levels of incompetence are not only fathomable, but repeatedly demonstrated. It's amazing that anything works at all.
It just seems like an unfathomable level of incompetence required to go from compromising some random Windows workstation all across the hardware that runs your app services. And lest we forget: a ransomware attack is always also a massive data loss attack. Garmin better get to work complying with the law and notifying impacted customers (all of them?).