Ransomware
Ransomware is malware that encrypts or steals an organization's data and demands payment, most often delivered through phishing and stolen credentials.
Ransomware is malicious software that makes an organization's data or systems unusable — by encrypting files, locking machines, or exfiltrating data under threat of publication — and then demands a ransom, usually in cryptocurrency, to restore access or withhold the leak. Modern operations typically run "double extortion": data is stolen before it is encrypted, so even a victim with perfect backups can be pressured with exposure of customer records, contracts, or intellectual property.
How it works
Although the payload is technical, the entry point is usually human. The most common initial access vectors are phishing emails carrying malicious attachments or links, stolen credentials purchased or harvested through infostealers and credential stuffing, and social engineering of help desks and employees — the same playbook seen in MFA fatigue attacks. Once inside, operators move laterally for days or weeks: escalating privileges, disabling security tooling and backups, and identifying the most valuable data. Only then is the encryptor detonated, often outside business hours, accompanied by a ransom note and a deadline. Many groups operate ransomware-as-a-service, where developers lease the malware to affiliates who handle the intrusions and split the proceeds — which is why attacks against small and mid-sized organizations are just as common as headline-grabbing enterprise incidents.
How to defend against it
- Harden the human entry points. Because most intrusions start with a message or a stolen password, ongoing phishing simulation and training measurably shrink the attack surface that ransomware crews rely on.
- Contain credential damage with phishing-resistant MFA, least-privilege access, and network segmentation, so a single compromised account cannot become a domain-wide event.
- Make backups an actual recovery path: offline or immutable copies, tested restores, and backup credentials separated from the production domain — attackers routinely delete reachable backups first.
- Rehearse the incident. A ransomware tabletop exercise that includes the extortion decision — pay, negotiate, or refuse — exposes gaps in authority and communications before a real deadline does.
- Report and involve law enforcement rather than negotiating alone; agencies such as the FBI's IC3 track active groups and can occasionally provide decryptors.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo