What is Ransomware?
Ransomware encrypts your files and demands payment — now combined with data theft so attackers can threaten publication even if you restore from backups.
Ransomware is malware that encrypts your data and demands payment for the decryption key — now combined with data theft for double extortion.
Ransomware is a category of malicious software that encrypts an organization's files and systems, rendering them inaccessible, and demands payment (typically in cryptocurrency) in exchange for the decryption key. Modern ransomware operations are run by professional criminal enterprises — with negotiators, support desks, affiliate programs, and even customer satisfaction surveys — and represent the most financially devastating threat facing small and mid-sized businesses today.
The average ransom payment reached $2.73 million in 2025 (Sophos). The average total recovery cost — including downtime, IT restoration, legal fees, regulatory fines, and reputational damage — is often multiples of the ransom itself, even when no ransom is paid.
How ransomware works
- Initial access via phishing, exposed RDP, compromised VPN credentials, or software vulnerabilities
- Persistence established using native OS tools to survive reboots and evade detection
- Lateral movement across the network to reach high-value systems
- Data exfiltration — files stolen before encryption for double extortion leverage
- Backup destruction — identifying and deleting or encrypting backup systems first
- Mass encryption — simultaneous deployment across all reachable systems
Ransomware-as-a-Service (RaaS)
Modern ransomware operations frequently operate as franchises. The ransomware developer creates and maintains the encryption software and negotiation infrastructure. Affiliates — criminal operators who don't have the technical skill to build their own ransomware — pay a percentage of collected ransoms to use the platform. This has dramatically lowered the barrier to conducting ransomware attacks and contributed to the explosion in attack volume.
Notable ransomware groups active in 2025 include LockBit, Rhysida (which specifically targets healthcare), BlackCat/ALPHV, and Play. Each has distinct targeting preferences, negotiation tactics, and technical capabilities.
Ransomware is technically malware — malicious software — but not a virus in the traditional sense. It doesn't self-replicate like a virus. It's typically deployed deliberately by attackers who have already gained access to a network, though some variants do spread automatically once inside.
Occasionally — law enforcement agencies have seized decryption keys from some ransomware operations, and security researchers have published decryptors for specific variants. However, for most active ransomware families, decryption without the key is not feasible. Prevention and offline backups are the reliable defenses.