Ransomware is malware that encrypts files or whole systems and demands a ransom, usually in cryptocurrency, for the decryption key – and often also for not publishing stolen data.
How ransomware works
Modern ransomware attacks are run by people, not just by code. Attackers get in through phishing, stolen VPN or RDP credentials, or an exploited vulnerability; spend days or weeks on privilege escalation and lateral movement; delete backups; copy data out; and then launch encryption across the network at once, often at night or on a holiday.
Since the Maze group introduced it in 2019, double extortion has become standard: pay, or the stolen data is published on a leak site on the dark web. Some gangs add DDoS attacks or contact customers of the victim directly. Most operations run as ransomware as a service.
Why ransomware matters for security
Ransomware is one of the most damaging threats for companies and public institutions. WannaCry hit around 200,000 computers in 150 countries in 2017; the 2021 attack on Colonial Pipeline led to fuel shortages on the US East Coast. Hospitals, schools, municipalities and manufacturers are frequent victims, and downtime usually costs far more than the ransom itself. Paying does not guarantee recovery or deletion of stolen data.
How to defend
- Keep offline or immutable backups (3-2-1 rule) and regularly test restores.
- Patch internet-facing systems quickly and protect remote access with MFA.
- Segment the network, restrict admin rights, and deploy EDR with 24/7 monitoring.
- Prepare and rehearse an incident response plan, including communication and legal steps.