Ransomware
- In Turkish
- Fidye Yazılımı
- Pronunciation
- RAN-sum-wair
In short
Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
What is ransomware?
Attackers typically get in through phishing, stolen passwords for remote access, or unpatched internet-facing systems. They then spread quietly through the network, gain administrator rights, find and delete backups, and finally encrypt as many machines as possible at once, leaving a ransom note with payment instructions.
In double extortion, which has become the norm, attackers first copy sensitive data and then threaten to leak it if the victim refuses to pay, so even good backups don't remove the pressure. Ransomware is now run as a business: groups sell their tools to affiliates in a ransomware-as-a-service model and share the profits.
Well-known attacks show the impact. WannaCry in 2017 spread as a worm through a Windows vulnerability and disrupted hospitals in the UK's National Health Service among hundreds of thousands of computers worldwide, and the Colonial Pipeline attack in 2021 led to fuel shortages on the US East Coast. Hospitals, schools, cities and companies of every size are targeted.
A common misconception is that paying the ransom brings everything back. Decryption tools are often slow or broken, stolen data may still be sold, and payment funds further attacks. The best protection is preparation: offline or immutable backups that are tested regularly, prompt patching, multi-factor authentication for remote access, least privilege and a rehearsed incident response plan.
Key takeaways
- Ransomware encrypts systems and demands payment for the key.
- Double extortion adds the threat of leaking stolen data.
- Attackers enter through phishing, stolen credentials or unpatched systems.
- WannaCry in 2017 and Colonial Pipeline in 2021 showed its impact.
- Tested offline backups, patching and MFA are the key defenses.
Readers ask
Should you pay a ransomware ransom?
Security agencies advise against it: payment doesn't guarantee recovery, stolen data may still be leaked, and it funds criminals. Organizations should prepare backups and a response plan so they don't face that choice.
How do you protect against ransomware?
Keep offline or immutable backups and test restoring them, patch systems quickly, require MFA for remote access and admin accounts, limit privileges, segment networks and train staff to recognize phishing.
What is ransomware as a service?
A criminal business model where developers rent their ransomware and infrastructure to affiliates who carry out attacks, splitting the ransom payments between them.
See also
- MalwareSecurity, p. 20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- PhishingSecurity, p. 27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Social EngineeringSecurity, p. 39Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- PostmortemDevOps & Cloud, p. 42A postmortem is a written review after an incident that explains what happened, why it happened, and what the team will change so it doesn't happen again.
Spotted a mistake or something missing on this page?Suggest an edit