Ransomware
In short: A type of malware that encrypts files on a system and demands a ransom for decryption.
In more detail: Ransomware usually gains access to a system via phishing emails, infected attachments or exploited vulnerabilities, then deliberately encrypts important files (documents, databases) with a key known only to the attacker, and leaves a ransom demand. The most effective protection isn’t paying the ransom (no guarantee of success, finances further attacks), but regular backups kept separate from the system, along with promptly installing security updates.
In Depth
A typical ransomware attack sequence in a corporate network:
1. Initial access: phishing email with an infected attachment, or an
unpatched, publicly reachable security hole
2. Lateral movement: attacker spreads through the internal network,
looking for valuable targets (database servers, backup systems)
3. Encryption: encrypt as many systems as possible SIMULTANEOUSLY,
to minimise reaction time - including any reachable backups
4. Ransom demand: usually in cryptocurrency, with a deadline
5. Double extortion: data is additionally copied BEFORE encryption -
non-payment threatens publication of sensitive data, even if
backups exist
The step “encrypt backups too, deliberately” is decisive for the business model of modern ransomware groups: earlier, simpler variants could often be bypassed without trouble by restoring from backups — modern attacks therefore actively search for reachable backup systems and encrypt or delete them first, before attacking the main system. The most effective protection against this is the so-called 3-2-1 rule: at least 3 copies of the data, on 2 different types of media, at least 1 copy physically separate/offline (so-called “air-gapped” backups, which in principle can’t be reached by an ongoing attack).
Legally and practically, paying is generally discouraged: there’s no guarantee that a working decryption key will actually be delivered, the payment finances the criminal infrastructure for further attacks, and a victim known to be willing to pay becomes a more attractive target for future attacks.
Ransomware-as-a-service
A major reason for the rise in ransomware attacks is the professionalisation of the crime behind it: well-known groups (e.g. LockBit, Conti in the past) run “ransomware-as-a-service” — they develop the actual encryption software and infrastructure and rent it out to “affiliates” who carry out the actual attacks, in exchange for a share of the extorted ransom. This considerably lowers the technical barrier to entry: an attacker no longer needs to be able to develop their own encryption software, just needs initial access to a target network (e.g. purchased stolen credentials or an exploited vulnerability).
Detection and response
Early warning signs of an ongoing attack are often unusually high disk activity on multiple systems at once, files suddenly renamed with new extensions, and suspicious lateral network connections shortly before the actual encryption — modern endpoint detection systems try to recognise exactly these patterns early and automatically isolate affected systems from the network before the attack spreads further. If an attack is already underway, the first response is usually to immediately physically disconnect affected systems from the network (unplug network cables, disable Wi-Fi) to stop further spread, followed by a forensic analysis of which systems are affected, before the actual restoration process from backups begins.
Insurance against ransomware
Cyber insurance against ransomware damage has become its own market in recent years, but it’s under criticism: critics argue that easily available insurance payouts could tempt companies to pay in an actual incident (since the insurer covers it) instead of investing in prevention, which increases victims’ overall willingness to pay and thereby indirectly makes ransomware groups even more attractive as a business. Some insurers therefore now require concrete minimum technical standards (e.g. multi-factor authentication, tested offline backups) as a precondition for coverage.
See also: Malware, Encryption