Skip to content
Cybersecurity

Ransomware

Ransomware is a type of malicious software (malware) that blocks access to a computer system or encrypts data, then demands a ransom for unlocking or decryption. The name comes from the English words 'ransom' and 'software'.

What is Ransomware?

Ransomware Definition

Ransomware is a type of malicious software (malware) that blocks access to a computer system or encrypts data, then demands a ransom for unlocking or decryption. The name comes from the English words “ransom” and “software”.

How Does Ransomware Work?

Ransomware works through:

  • System Infection: Ransomware gets into the system through malicious email attachments, infected websites, security vulnerabilities, or infected USB devices.

  • Data Encryption: After installation, ransomware scans the system for files to encrypt. Files are encrypted using advanced encryption algorithms.

  • Ransom Demand: After encrypting data, ransomware displays a message demanding ransom, often in cryptocurrencies such as Bitcoin, in exchange for the decryption key.

Types of Ransomware Attacks

  • Scareware: Displays false warnings about system problems and demands payment for their repair.

  • Screen Lockers: Blocks access to the system, displaying a full-screen window with a ransom demand.

  • Encrypting Ransomware: Encrypts files on the victim’s computer, making them unreadable without the decryption key.

Most Common Ransomware Infection Methods

  • Phishing: Malicious email attachments or links.

  • Infected Websites: Drive-by downloads that automatically download and install ransomware.

  • Security Vulnerabilities: Exploitation of unpatched software vulnerabilities.

  • Infected USB Devices: Transferring ransomware on infected data media.

Consequences of a Ransomware Attack

  • Loss of Data Access: Encrypted files are inaccessible without the decryption key.

  • Financial Losses: Costs related to ransom payment, business downtime, and data recovery.

  • Reputation Damage: Loss of trust from customers and business partners.

  • Potential Privacy Breach: Possibility of public disclosure or sale of stolen data.

How to Protect Against Ransomware?

  • Regular Backup Creation: Storing backup copies in secure, isolated locations.

  • Software Updates: Regularly updating operating systems and applications to eliminate security vulnerabilities.

  • Using Antivirus Software: Installing and updating antivirus and antimalware software.

  • User Education: Training employees to recognize threats and safe online practices.

  • Implementing Security Policies: Implementing least privilege principles and network segmentation.

Procedure in Case of a Ransomware Attack

  • Disconnect the Device from the Network: To prevent further spread of ransomware, disconnect the device from the internet and local network.

  • Do Not Pay the Ransom: Paying the ransom does not guarantee data recovery and may support criminal activity.

  • Contact Experts: Report the incident to security specialists and appropriate law enforcement.

  • Visit NoMoreRansom.org: The site offers decryption tools and support for ransomware victims.

  • Restore Data from Backups: If you have backup copies, restore data from secure sources.

Most Famous Ransomware Attacks

  • WannaCry (2017): A global ransomware attack that infected hundreds of thousands of computers in over 150 countries.

  • NotPetya (2017): A ransomware attack that paralyzed many large companies and institutions worldwide.

  • Ryuk (2018): Ransomware targeting large organizations, often demanding high ransoms.

Active Ransomware Groups

GroupTacticsKnown Victims
LockBit 3.0RaaS, triple extortionCritical infrastructure, hospitals
BlackCat/ALPHVRust-based, cross-platformCasinos, airports
Cl0pSupply chain attacks, MOVEitHundreds of companies via MOVEit
PlayDouble extortionPublic sector
AkiraSMB targetingSmall and medium businesses

Evolution of Ransomware Tactics

Triple/Quadruple Extortion:

  1. Data encryption
  2. Theft and publication threat (double extortion)
  3. DDoS on victim (triple extortion)
  4. Contacting victim’s customers (quadruple extortion)

Ransomware-as-a-Service (RaaS):

  • Affiliates conduct attacks
  • Developers provide infrastructure and malware
  • Profit sharing 70/30 or 80/20
  • Lowers entry barrier for criminals

2024-2025 Statistics

  • $1.1B in paid ransoms in 2024
  • 75% of attacks use stolen credentials
  • Average ransom: $2.73M (up from $812K in 2022)
  • Average recovery time: 24 days
  • 71% of victims paying ransom experience another attack

Initial Access Brokers (IAB)

New element of ransomware ecosystem:

  • Sell access to corporate networks
  • Prices: $500 - $50,000 per access
  • Shorten time from compromise to encryption
  • Buyers: ransomware groups, APT
  • Malware - broader category of malicious software
  • Phishing - main initial infection vector
  • Backup - key protection against data loss
  • Incident Response - responding to ransomware attacks
  • Dark Web - place where stolen data is published

Explore Our Services

Want to protect your organization from ransomware? Check out:

Ransomware is one of the most serious threats in cyberspace, which can have catastrophic consequences for organizations and individual users. In 2025, ransomware groups are more organized and professional than ever. Multi-layered protection, up-to-date backups, and a prepared response plan are key to minimizing risk and the impact of potential attacks.

Frequently asked questions

+ What is ransomware in simple terms?

Ransomware is malicious software that locks your data — usually by encrypting files — and demands a payment (the 'ransom') in cryptocurrency to restore access. Modern ransomware also steals data before encryption (double extortion) and threatens to publish it on a leak site if the victim doesn't pay. The name combines 'ransom' and 'software'. Average ransom demand in 2025 is around $5.2M for enterprises (Coveware data); average total recovery cost (downtime, IR, lost business) reaches $5-10M for mid-size organisations and $50M+ for large ones.

+ How does a ransomware attack work?

Most attacks follow four stages: (1) **Initial access** — phishing email, exposed RDP, vulnerable VPN gateway, software supply chain (the most common entry point in 2025-2026), (2) **Persistence and lateral movement** — establish multiple footholds, harvest credentials, escalate to domain admin (the 'breakout time' between initial compromise and lateral movement is now ~62 minutes for top groups, per CrowdStrike 2025 Threat Report), (3) **Data exfiltration** — copy sensitive data to attacker infrastructure for double-extortion leverage, (4) **Encryption and ransom note** — disable backups, encrypt files across endpoints/servers/cloud, drop ransom note demanding payment in Bitcoin or Monero. Modern groups also delete shadow copies, kill anti-malware, and recruit insiders.

+ What are the main ransomware groups in 2026?

Top active ransomware-as-a-service (RaaS) operators: (1) **LockBit** — historically the most prolific, partially disrupted by Operation Cronos (Feb 2024) but rebranded and continuing, (2) **Cl0p** — known for mass-exploitation campaigns (MOVEit 2023, GoAnywhere 2023, Cleo 2024), (3) **BlackCat / ALPHV** — disrupted in Dec 2023 but technique heirs continue (RansomHub, Akira), (4) **Akira** — fast-growing, targets mid-market via VPN exploits, (5) **Play / PlayCrypt** — heavy in Europe, exploiting Citrix and Fortinet vulnerabilities, (6) **8base, Medusa, Hunters International, Qilin, RansomHub** — emerging tier. Many groups operate as RaaS franchises with affiliates handling intrusion. Russian, North Korean and Iranian state-backed groups occasionally use ransomware as cover.

+ How to protect against ransomware?

Defence in depth — no single control is sufficient: (1) **MFA on every account** (especially VPN, RDP, admin) — 80%+ of intrusions could be stopped by MFA alone, (2) **Aggressive patching** — most ransomware exploits known CVEs, especially edge devices (Fortinet, Citrix, Ivanti, Palo Alto), (3) **EDR/XDR** with behaviour-based detection (CrowdStrike, SentinelOne, Defender for Endpoint), (4) **Email security** (Defender for Office 365, Proofpoint) with sandbox detonation and phishing-resistant MFA, (5) **Network segmentation** — slow lateral movement, isolate backup infrastructure, (6) **Immutable, offline backups** with 3-2-1 rule and tested restore procedure (median restore time after ransomware is 21 days), (7) **24/7 SOC monitoring** to detect intrusion in the first hour, not the third week, (8) **User awareness training** with phishing simulations, (9) **Incident response plan** with tabletop exercises, retainer with IR firm, ready-to-call lawyer/PR/insurer.

+ Should you pay the ransom?

FBI, Europol, CISA and most national CSIRTs strongly advise against paying. Reasons: (1) No guarantee of decryption — Sophos 2025 State of Ransomware shows only 4% of paying victims recovered all data; many decryption tools are buggy, slow or fail, (2) Marks the organisation as a paying target — repeat-attack rate within 12 months for paying victims is ~40%, (3) Funds further criminal/terrorist/nation-state activity, (4) Sanctions risk — paying OFAC-sanctioned groups (e.g., LockBit affiliates linked to Russia, North Korean groups) is a US federal offence, with similar regimes in UK and EU, (5) Often disclosed publicly — paying does not always prevent leak. Better path: invoke incident response, restore from backups, hire negotiator only as a last resort, report to law enforcement and your CSIRT.

+ What are famous ransomware attacks?

Five high-impact attacks: (1) **WannaCry (2017)** — exploited EternalBlue NSA leak, hit UK NHS, $4B+ damages, (2) **NotPetya (2017)** — destructive wiper masquerading as ransomware, $10B damages, the most expensive cyberattack in history (Maersk, Merck, FedEx), (3) **Colonial Pipeline (2021)** — DarkSide group, fuel pipeline shutdown across US East Coast, $4.4M ransom paid (mostly recovered by FBI), (4) **Kaseya VSA (2021)** — REvil supply chain attack hitting 1500+ MSPs and downstream customers, (5) **Change Healthcare (2024)** — BlackCat/ALPHV, $872M total impact on UnitedHealth, paralysed US healthcare claims processing. Lesson: even well-resourced organisations fall to ransomware; the only reliable defence is layered prevention + tested recovery.

+ How long does it take to recover from a ransomware attack?

Median recovery times (Sophos State of Ransomware 2025): organisations with mature backup/IR programmes — 7-10 days; average organisation — 21 days; severely affected (no backups, paid ransom) — 30-60+ days. Full recovery often takes 6-12 months including remediation, audit, regulatory reporting, customer trust rebuild and litigation. Cost breakdown for typical attack: detection and IR ($300K-2M), forensics and notification ($100K-500K), system restoration ($500K-3M), legal and regulatory ($200K-1M), reputational and business loss (often the largest, $5M-50M+). Cyber insurance covers some but premiums have risen 50-200% and many insurers now require demonstrated controls (MFA, EDR, immutable backups) to qualify.

Tags:

ransomware malware cyberattack encryption cybersecurity

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist