Skip to main content
Book 07 · SecurityPage 31 of 50

Ransomware

Pronunciation
RAN-sum-wair
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/ransomware

In short

Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.

What is ransomware?

Attackers typically get in through phishing, stolen passwords for remote access, or unpatched internet-facing systems. They then spread quietly through the network, gain administrator rights, find and delete backups, and finally encrypt as many machines as possible at once, leaving a ransom note with payment instructions.

In double extortion, which has become the norm, attackers first copy sensitive data and then threaten to leak it if the victim refuses to pay, so even good backups don't remove the pressure. Ransomware is now run as a business: groups sell their tools to affiliates in a ransomware-as-a-service model and share the profits.

Well-known attacks show the impact. WannaCry in 2017 spread as a worm through a Windows vulnerability and disrupted hospitals in the UK's National Health Service among hundreds of thousands of computers worldwide, and the Colonial Pipeline attack in 2021 led to fuel shortages on the US East Coast. Hospitals, schools, cities and companies of every size are targeted.

A common misconception is that paying the ransom brings everything back. Decryption tools are often slow or broken, stolen data may still be sold, and payment funds further attacks. The best protection is preparation: offline or immutable backups that are tested regularly, prompt patching, multi-factor authentication for remote access, least privilege and a rehearsed incident response plan.

Key takeaways

  • Ransomware encrypts systems and demands payment for the key.
  • Double extortion adds the threat of leaking stolen data.
  • Attackers enter through phishing, stolen credentials or unpatched systems.
  • WannaCry in 2017 and Colonial Pipeline in 2021 showed its impact.
  • Tested offline backups, patching and MFA are the key defenses.

Readers ask

Should you pay a ransomware ransom?

Security agencies advise against it: payment doesn't guarantee recovery, stolen data may still be leaked, and it funds criminals. Organizations should prepare backups and a response plan so they don't face that choice.

How do you protect against ransomware?

Keep offline or immutable backups and test restoring them, patch systems quickly, require MFA for remote access and admin accounts, limit privileges, segment networks and train staff to recognize phishing.

What is ransomware as a service?

A criminal business model where developers rent their ransomware and infrastructure to affiliates who carry out attacks, splitting the ransom payments between them.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings