What is ransomware?
Ransomware locks up your files and sells you the key. Learn how an attack really runs, why paying rarely works, and the checks that decide whether you recover in hours or weeks.
Ransomware is malicious software that scrambles the files on a computer system so nobody can read them, then demands payment for the key that unscrambles them. Most attacks now also copy the data out first, so the criminals can threaten to publish it. Offline, tested backups are the main defence.
You arrive at your shop in the morning. The lock has been changed overnight. Your key does not turn. Taped to the door is a note with a phone number and a price for the new key.
Everything you own is still inside. You just cannot reach any of it.
That is ransomware. Criminals get into a computer system, scramble the files so nobody can read them, and demand payment for the key that unscrambles them. The scrambling uses encryption, the same maths that protects your banking. Here it is turned around and used against you.
How an attack actually runs
- Get in. Usually through phishing, a stolen password, or software that was never updated.
- Look around quietly. This part can take days or weeks. The attacker learns where the valuable files live.
- Spread. They reach more machines and collect more powerful accounts.
- Break the backups. This step is deliberate.
- Copy the data out to their own servers.
- Scramble everything, usually at night or over a public holiday.
- Leave the note and start the clock.
Read step four again. The attacker goes for your backups first, because your backups are the reason you would not pay.
Notice how long the whole run takes. Weeks, in many cases. That is good news, because it means there is time to catch it. Most victims had warning signs sitting in their logs that nobody was reading.
Double extortion
Older attacks only scrambled files. If you held a good backup you restored it and ignored the note.
So the criminals added a second threat. Now they copy the data out before they scramble it. The note then says two things. Pay to get your files back, and pay so we do not publish them.
This is why a backup is no longer a complete answer. A backup restores your work. It does nothing about a copy of your customer records sitting on a criminal server somewhere else.
It is run like a business
Most attacks now come out of a supply chain. One group writes the software. Another group breaks into companies and sells the access. A third group handles the negotiation and the payment. They split the money between them.
This arrangement is called ransomware as a service. It matters for one reason. The person attacking you may have very little skill, because the skill is rented. Therefore small organisations are targets too.
Why paying is a bad idea
People do pay, and the pressure to pay is real. Understand what you are buying first.
- You may not get everything back. The tool they send is often slow, and sometimes faulty.
- You are still breached. The copy of your data does not come back.
- You may be hit again, by the same group or by another one that heard you pay.
- In some countries the payment itself can be illegal, depending on who receives it.
Police forces in most countries advise against paying. The reason is simple. Payment is what funds the next attack.
What actually stops it
Nothing stops every attack. These reduce both the chance and the damage.
- Multi-factor login everywhere, above all on remote access and on email.
- Updates applied quickly, especially to anything reachable from the internet.
- Backups kept offline, or in a form nobody can edit, and tested by restoring them.
- Least privilege, so one stolen account does not open the whole building.
- Separation inside the network, so an attack in one room does not reach the next.
- Monitoring, so somebody notices the quiet week in step two.
The design idea behind that list has a name. It is zero trust, and it means checking every request instead of trusting whatever is already inside your network.
The old rule for backups still holds. Keep three copies, on two kinds of storage, with one copy off site. People call it the 3-2-1 rule. Add one word to it now, and that word is offline.
Where it happens
Hospitals, schools, city councils, factories, transport firms and small companies of every kind. Attackers favour places where being stopped for a day is unbearable, because urgency raises the price they can ask.
Home computers get hit as well, though less often than before. Criminals worked out that a company will pay far more than a family, so the effort moved upmarket. That does not make a scrambled laptop any easier to live with.
The damage is rarely just the ransom. It is the weeks of lost work, the staff time, the legal duties that follow a data breach, and the customers who quietly go elsewhere. Our wider piece on cybersecurity shows how the other layers fit together.
What to do in the first hour
Act in this order. Disconnect the affected machines from the network. Do not switch them off, because some evidence lives only in memory. Then call for help, tell your insurer if you have one, and report it to the police or the national response team.
Do not delete anything. Do not reply to the note on your own. And keep in mind that the people you are dealing with are running a business, so they expect the call.
What to check today
Find your most important system and answer one question in writing. If it were scrambled this evening, how would you restore it, and who exactly would do the work?
If you cannot answer that, you have found your next job. Then go one step further. Restore a single file from your backup this week and time how long it takes. A BACKUP YOU HAVE NEVER RESTORED IS ONLY A GUESS.
Just Out Tech explains new research in plain language. This article was drafted with AI assistance and checked by a human against the original source.
- Ransomware encrypts your files and demands payment for the key, and modern attacks also steal a copy of the data so they can threaten to publish it.
- Attackers deliberately destroy backups before they encrypt anything, which is why a backup only helps if it is kept offline and tested by restoring it.
- Paying a ransomware demand does not undo the breach, because the stolen copy of your data stays with the criminals whatever you pay.
Questions people ask
should you pay a ransomware demand
Police forces in most countries advise against it. Payment funds the next attack, the decryption tool is often slow or faulty, and paying does nothing about the copy of your data the attackers already hold. In some countries a payment can also be illegal depending on who receives it. Treat paying as a last resort, taken with legal advice.
how does ransomware get into a company
Usually through one of three ordinary routes. Someone is tricked into clicking a link or opening a file, a password stolen elsewhere is reused, or a system facing the internet was never updated. Attackers then move quietly through the network for days or weeks before anything is encrypted.
can you remove ransomware without paying
You can remove the software, but that does not decrypt the files. Recovery normally means wiping the affected machines and restoring from a backup the attacker could not reach. A free decryption tool exists for some older strains, so it is worth checking with a national cybercrime unit before giving up.
what is ransomware as a service
It is the way most ransomware groups now work. One group writes and maintains the software, another breaks into organisations, and another handles the demand and the payment, with the proceeds split between them. It means the person attacking you may have very little technical skill of their own.