Computer Security

What Is Ransomware?

Ransomware is malware that encrypts a victim’s files or locks a device and demands a ransom payment to restore access. It pairs strong encryption with extortion, holding data hostage until the victim pays or rebuilds from a clean backup. The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) rank it among the most damaging malware categories, and in 2026 nearly every major attack also steals data to threaten a leak.

In shortRansomware locks your files (or your whole device) and demands payment, usually in cryptocurrency, to unlock them. Most 2026 attacks use double extortion – they encrypt and steal data, then threaten to leak it – and the surest fix is restoring from an offline backup, not paying. The FBI and CISA advise against paying: it does not guarantee recovery.
$1M
Avg ransom paid (2025)
$5.08M
Avg total breach cost
~88%
Attacks that also steal data
7,500+
Orgs leaked in 2025

What Is Ransomware?

Ransomware is malware that encrypts a victim’s files or locks a device and demands a ransom payment in exchange for restoring access. It targets availability – making data unusable until payment – rather than quietly stealing in the background. Its defining traits are:

  • Encryption or locking makes files or the whole device inaccessible to the owner.
  • A ransom demand requests payment, usually in cryptocurrency, to restore access.
  • A deadline pressures the victim, often threatening to delete or publish the data.
  • Extortion is what defines ransomware, separating it from malware that only steals or destroys.

Ransomware is one category within the broader set of malicious software covered in the overview of malware. Because it attacks availability, the most reliable recovery is restoring from a backup made before the infection.

How Does a Ransomware Attack Unfold?

A ransomware attack runs from initial access to encryption to extortion, often over days while the attacker spreads quietly first. The typical stages are:

  • Initial access. The attacker gets in through a phishing email, an exposed remote-access service, or an unpatched flaw.
  • Spread and steal. They move laterally across the network and, in most 2026 attacks, copy (exfiltrate) sensitive data first.
  • Encryption. Files are scrambled with strong cryptography so they cannot open without the attacker’s key.
  • Ransom note. A note appears on screen demanding payment and giving instructions and a deadline.
  • Double extortion. If you have backups, they threaten to leak the stolen data unless you pay anyway.

Modern ransomware uses encryption that cannot be reversed without the attacker’s key, according to CISA – which is why prevention and offline backups matter far more than any hope of decryption.

What Are the Types of Ransomware?

The main types of ransomware are crypto, locker, double extortion, and ransomware-as-a-service. A type is defined by how it restricts access and how the operation is run:

What Are the Types of Ransomware? - What Is Ransomware?

Crypto ransomware

Encrypts your files so they cannot open without the key. The most common type.

Locker ransomware

Locks the entire device or screen, blocking the whole system rather than single files.

Double extortion

Steals data before encrypting, then threatens to publish it – now the default tactic.

Ransomware-as-a-Service

Operators rent the malware to affiliates for a cut, lowering the barrier to entry.

Crypto ransomware is the most common, while ransomware-as-a-service (RaaS) has industrialised the threat, per CISA and Kaspersky. Double extortion grew because backups defeat encryption alone, so attackers added the threat of leaking stolen data – in 2026 roughly 88 percent of attacks both encrypt and steal.

How Does Ransomware Get In?

Ransomware most often gets in through phishing email, exposed remote access (RDP/VPN), and unpatched vulnerabilities. The entry vector is the path it uses to reach the network:

  • Phishing email delivers ransomware through a malicious attachment or link – the most common initial access.
  • Exposed remote access lets attackers scan for open RDP, then brute-force weak or reused passwords (about 70% of cloud systems leave RDP open).
  • Unpatched vulnerabilities in operating systems, browsers, and VPN appliances can be exploited with no user action.
  • Malicious downloads and trojan loaders hide the payload, and a worm component spreads it across the network.

Phishing email and exposed remote access are the leading entry points, according to the FBI. A trojan often delivers ransomware as its payload, the deception covered in the guide to the trojan horse, while a worm element spreads it, as in the guide to computer worms.

Related Articles

What Are the Notable Ransomware Groups and Examples?

Notable ransomware includes the historic WannaCry, Ryuk, and REvil, plus the active 2026 groups LockBit, Qilin, and Akira. Each shows how the category operates in real incidents:

WannaCry (2017)

A worm that hit 200,000+ systems across 150 countries via a Windows SMB flaw – the classic spreading example.

LockBit

The most prolific RaaS in history; disrupted in 2024 but resurged as LockBit 5.0 and still active in 2026.

Qilin

The top ransomware brand by volume since 2025, outpacing the bottom 50 groups combined in early 2026.

Ryuk and REvil

Big-game hunters; REvil pioneered double extortion – encrypt, steal, then threaten to leak.

After law-enforcement takedowns of LockBit and ALPHV/BlackCat in 2024, the ecosystem splintered into 124 active groups in 2025 (up 46% year over year) rather than shrinking. New affiliate programs such as The Gentlemen and Hyflock surfaced through 2025 and 2026.

Should You Pay the Ransom?

No – the FBI and CISA advise against paying, because payment does not guarantee recovery and only funds more attacks. Paying carries risk even when the data is critical:

  • No guarantee the attacker hands over a working decryption key, or a complete one, after payment.
  • Funding crime finances the next wave of ransomware and future victims.
  • Repeat targeting marks a paying victim as likely to pay again.
  • Legal exposure can arise if the payment goes to a sanctioned group.
Do not pay if you can avoid itA ransom buys a promise, not your data – decryptors are often slow, partial, or broken, and with double extortion the criminals keep the stolen copy regardless. A tested offline backup lets you restore without paying or trusting the attacker. Report the incident to CISA or the FBI.

How Do You Prevent Ransomware?

Prevent ransomware with offline backups, prompt patching, multi-factor authentication, locked-down remote access, and email caution. Each measure cuts either the chance of infection or the damage it causes:

  • Offline or immutable backups keep copies ransomware cannot reach, enabling recovery without payment.
  • Prompt patching closes the vulnerabilities attackers and worms exploit.
  • Multi-factor authentication stops stolen passwords from unlocking remote access.
  • Restricted remote access limits exposed RDP and VPN services to what is needed.
  • Email caution and antivirus block the phishing and payloads that deliver ransomware (see removing malware from a PC).
Follow the 3-2-1 backup ruleKeep 3 copies of your data on 2 different media with 1 stored offsite, and make at least one copy offline or immutable so ransomware cannot encrypt it. CISA, the NSA, and the FBI call an immutable backup the last line of defense – it is what lets you recover clean data without paying.

Tested offline backups are the single most effective defense, since they allow recovery without paying, per CISA. The procedure for reliable copies is in the guide to backing up a computer.

How Do You Recover From Ransomware?

Recover from ransomware by isolating the device, reporting it, removing the malware, and restoring from a clean backup – not by paying. The steps in order are:

  1. Isolate the infected device from the network to stop the ransomware spreading.
  2. Report the incident to authorities such as CISA or the FBI.
  3. Remove the ransomware with antivirus software or a full system reinstall.
  4. Restore data from a clean backup made before the infection.
  5. Patch the vulnerability that allowed the infection to prevent recurrence.

A clean backup makes recovery possible without paying, which is why offline copies are the foundation of ransomware defense, per CISA. The full backup procedure is in the guide to backing up a computer, and broader cleanup is in the steps to remove malware from a PC.

Who Does Ransomware Target?

Ransomware targets hospitals, schools, government agencies, businesses, and individuals – favoring anyone who cannot tolerate downtime. A target is chosen by the value of its data and its pressure to restore service fast:

Who Does Ransomware Target? - What Is Ransomware?
  • Healthcare organizations are hit because patient care cannot pause during an outage.
  • Schools and universities hold large data sets on limited security budgets.
  • Government agencies run critical services that pressure quick restoration.
  • Businesses face encryption of operational data that halts revenue.
  • Individuals face encryption of personal files such as photos and documents.

Operators favor organizations under pressure to restore service, since that pressure raises the chance of payment, according to the FBI. Critical-infrastructure and healthcare attacks drew heavy federal attention after major incidents disrupted essential services.

How Does Ransomware Differ From Other Malware?

Ransomware announces itself and demands payment, while most malware stays hidden to steal data or maintain access. The difference is visibility and goal:

  • Ransomware reveals itself with a ransom note and targets availability by locking data.
  • Spyware stays hidden and targets confidentiality by stealing information.
  • A trojan hides its payload, which may include ransomware as the delivered malware.
  • A botnet conceals control of a device to use it in coordinated attacks.

Ransomware is unusual because it must be visible to demand payment, unlike covert spyware that steals data silently. See the full list of malware types for how the categories relate.

Ransomware Readiness CheckRate your three core defenses to see how ready you are for a ransomware attack and which gap to fix first

Last Thoughts on Ransomware

Ransomware encrypts your files or locks your device and demands payment for access, and in 2026 it almost always steals data too, so it can threaten a leak even when you hold backups. It gets in mainly through phishing, exposed remote access, and unpatched flaws, and the most reliable defense remains an offline or immutable backup that the attack cannot reach.

The decision is simple: do not pay if you can avoid it, restore from a clean backup, and report the incident. Continue with the overview of malware, the complete list of malware types, the guide to backing up a computer, or the overview of cybersecurity.

Key Takeaways:

  • Ransomware encrypts files or locks a device and demands payment for access.
  • Double extortion is standard: most 2026 attacks also steal data and threaten to leak it.
  • It gets in mainly via phishing email, exposed RDP/VPN, and unpatched vulnerabilities.
  • Examples span historic WannaCry, Ryuk, and REvil and active groups LockBit, Qilin, and Akira.
  • Prevention relies on offline or immutable backups, patching, MFA, and email caution.
  • Recovery uses clean backups, and the FBI and CISA discourage paying the ransom.

Frequently Asked Questions (FAQs)

What is ransomware in simple terms?

Ransomware is malware that encrypts a victim’s files or locks a device and demands a ransom payment to restore access. It holds data hostage until the victim pays or recovers from a backup.

How does ransomware work?

Ransomware infects a device, encrypts files with a key held by the attacker, and displays a ransom note demanding payment for the decryption key. Strong encryption cannot be reversed without that key.

What are examples of ransomware?

Major ransomware examples include WannaCry, Ryuk, LockBit, and REvil. WannaCry spread as a worm in 2017, while LockBit operated as ransomware-as-a-service rented to affiliates.

Should you pay the ransom?

Authorities such as the FBI and CISA discourage paying. Payment does not guarantee recovery, funds further attacks, and marks the victim as willing to pay again. Restoring from backup is recommended.

How do you prevent ransomware?

Prevent ransomware with offline backups, regular updates, email caution, antivirus software, and restricted remote access. Tested offline backups are the single most effective defense.

Can you recover files after ransomware?

Yes, by restoring from a clean backup made before the infection. Without a backup, encrypted files usually cannot be recovered, because the encryption cannot be reversed without the attacker’s key.

Nizam Ud Deen

Muhammad Nizam Ud Deen Usman is the founder of theCoreiTech and the author of The Local SEO Cosmos. Nizam works as an SEO consultant and content strategy expert with more than a decade of experience in digital marketing and IT, and he also founded ORM Digital Solutions, a digital agency serving medium and large businesses. He holds a degree from the University of Education, Lahore (Multan Campus), and was listed among the top 20 SEO experts in Pakistan in 2024. Nizam started theCoreiTech in 2012 to make computers easier to understand and use for everyone. Connect with Nizam on LinkedIn (seoobserver), X (@SEO_Observer), or at nizamuddeen.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button