Definition

Ransomware is malicious software that encrypts data or locks systems and demands a ransom to release them. Modern campaigns additionally threaten to publish data they exfiltrated beforehand.

At a glance

The way in is usually phishing or an unpatched remote access point.

Double extortion: copy first, then encrypt.

Offline backups are the only copy an attacker cannot encrypt along with the rest.

Ransomware is no longer a lone operator’s tool but a division-of-labour business, with access brokers, developers and negotiators.

Double extortion

Data is copied before it is encrypted. Even an organisation that can restore cleanly is then under pressure, because publication is threatened. Backups alone no longer solve the problem.

Real-world examples

  • One click on an attachment encrypts the whole department’s file share overnight.
  • An unpatched VPN appliance opens the network without anyone having to click anything.

Common misconception

Myth “We have backups, so we are protected against ransomware.”

Reality Backups help against encryption, not against publication of copied data. And a backup reachable online gets encrypted along with everything else.

Frequently asked questions

Should you pay the ransom?

Authorities advise against it: paying funds the business model and guarantees nothing. CISA StopRansomware collects practical guidance.

Is a ransomware incident reportable?

Entities in scope of the NIS2 Directive face short reporting deadlines. Whether your organisation is in scope is a question for legal.