Ransomware
Ransomware is a type of malicious software that locks or encrypts a victim's files, making them inaccessible until a ransom is paid to the attacker. It can target individuals, businesses, hospitals, and government agencies alike. Attackers typically demand payment in cryptocurrency, claiming they will provide a decryption key in return — though payment does not guarantee file recovery.
Modern ransomware commonly uses asymmetric encryption (such as RSA) combined with symmetric encryption (such as AES), making decryption without the attacker's private key computationally infeasible.

How Ransomware Gets In

Most ransomware infections begin with a simple mistake — clicking a link in a convincing fake email, opening an attachment disguised as an invoice or shipping notice, or visiting a website that silently exploits an unpatched browser vulnerability. These entry points are collectively known as the attack surface, and attackers work hard to make their traps look legitimate.

Phishing remains the leading delivery method. Attackers craft emails that impersonate trusted senders — an employer, a bank, a courier service — and embed malicious payloads in attached documents or linked pages. A single click can silently install the ransomware without any visible sign something has gone wrong.

Businesses face an additional risk through Remote Desktop Protocol (RDP) — software that allows employees to access work computers remotely. When RDP is left exposed to the internet with weak passwords, attackers can brute-force their way in and deploy ransomware manually across an entire network.

Supply Chain Attacks Are a Growing Vector

Attackers increasingly target software vendors and IT service providers to reach multiple victims at once — a tactic known as a supply chain attack. If a trusted software update is compromised, every organization using that software can be exposed simultaneously. This makes vendor security practices a critical consideration for businesses of all sizes.

What Ransomware Does Once Inside

After gaining access, ransomware typically runs quietly in the background before showing itself. It maps the victim's files, connects to an attacker-controlled server to retrieve encryption keys, and then begins systematically locking documents, images, databases, and backups.

Once encryption is complete, a ransom note appears — often a text file or a changed desktop wallpaper — instructing the victim to pay a specified amount, usually in Bitcoin or another cryptocurrency, within a deadline. Some modern ransomware gangs operate what security researchers call double extortion: they steal sensitive data before encrypting it and threaten to publish it publicly if the ransom isn't paid.

$1.1B+

Ransomware payments made globally in 2023

According to blockchain analytics firm Chainalysis, 2023 set a record for ransomware payments, reflecting both rising attack frequency and higher ransom demands.

72%

Organizations hit by ransomware in 2023

Sophos's State of Ransomware 2024 report found that nearly three-quarters of surveyed organizations were affected by ransomware attacks during 2023.

21 days

Average business downtime after a ransomware attack

Coveware's quarterly ransomware reports have consistently found that organizations face multi-week recovery periods even when they have cybersecurity resources in place.

The damage isn't limited to lost files. Organizations often face days or weeks of operational disruption, emergency IT costs, legal obligations around data breach notification, and lasting reputational harm.

Who Gets Targeted — and Why

Ransomware affects individuals and large institutions alike, but attackers are strategic. Organizations that hold sensitive data, operate critical services, or have limited cybersecurity resources are disproportionately targeted. Hospitals are a particularly alarming target because system outages can directly affect patient care. Schools, municipal governments, and utilities have also been hit with high frequency in recent years.

For individual consumers, the threat typically arrives through personal email or unsafe downloads. While the ransom demands in these cases tend to be smaller, the loss of personal photos, financial records, or work files can be devastating.

Reducing Your Risk and Recovering

No single measure eliminates ransomware risk entirely, but a combination of habits significantly reduces exposure. Keeping operating systems and software up to date closes the vulnerabilities attackers exploit. Being cautious with unexpected email attachments — even from familiar-looking senders — stops many infections before they start.

The most important recovery tool is a clean, offline backup. If your files are backed up to a location that isn't connected to your primary system, ransomware cannot encrypt them. Security experts recommend following the 3-2-1 rule: three copies of data, on two different types of media, with one stored offsite or offline.

If an infection does occur, avoid paying the ransom as a first step. Disconnect affected devices from the network immediately to limit spread, document what you can, and report the incident to the FBI's Internet Crime Complaint Center (IC3) or CISA. A cybersecurity professional can assess whether any decryption options are available before payment is considered.

This article is for general informational purposes only and does not constitute cybersecurity, legal, or financial advice. Consult qualified professionals for guidance specific to your situation.

Frequently Asked Questions

If you don't pay, attackers may permanently delete the decryption key, making encrypted files unrecoverable. However, victims who have clean backups can often restore their data without paying. Law enforcement agencies generally advise against paying, as it funds criminal operations and doesn't guarantee recovery.

Yes. Many modern ransomware strains are designed to move laterally through a network once inside, infecting multiple devices and servers. This is why large organizations can suffer widespread outages from a single compromised endpoint. Network segmentation and access controls help limit this spread.

The most common delivery methods are phishing emails with malicious attachments or links, drive-by downloads from compromised websites, and exploitation of unpatched software vulnerabilities. Remote Desktop Protocol (RDP) brute-force attacks are also a frequent entry point for attackers targeting businesses.

Sometimes. Security researchers and law enforcement agencies occasionally break specific ransomware variants and release free decryption tools, available through resources like the No More Ransom project. However, this is not guaranteed — many strains use strong encryption that has not been cracked.

Report the attack to the FBI's Internet Crime Complaint Center (IC3) or the Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. If you are a business, contact a cybersecurity incident response firm. Avoid making any ransom payment decisions without professional guidance.

Share

Technology Editorial Team · Contributor

Technology Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.