Skip to content
Cyber Security Firms

What Is Ransomware? How It Works and How to Stop It

The ransom note is the last thing that happens, not the first. By the time it appears the attackers have usually been inside for days, taken a copy of everything worth taking, and deleted the backups. The week before the note is where this is won or lost.

Beginner16 min readUpdated
What Is Ransomware? How It Works and How to Stop It

Most people picture ransomware as a moment. The screen turns, a note appears, someone asks for cryptocurrency. That moment is real and it is the last thing that happens. By the time the note is on the screen the attackers have usually been inside the network for days, they have already taken a copy of the data they are now threatening to publish, and they have already found and deleted the backups you were planning to restore from. The week before the note is where a ransomware attack is actually won or lost, and it is the part almost nobody explains.

What Is Ransomware?

The FBI's Internet Crime Complaint Center defines it in one sentence on its ransomware page: malicious software that prevents you from accessing your computer files, systems or networks and demands you pay a ransom for their return. CISA's ransomware guidance adds the detail that matters, describing it as an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable.

In simple terms: someone gets into your systems, scrambles your files so nothing opens, and sells you the key. It is a type of malware, which puts it in the same family as viruses and infostealers, but it behaves differently from all of them in one respect. Every other kind of malware wants to stay hidden. Ransomware announces itself, because the announcement is the product.

That is the most useful thing to understand about it. Ransomware is not really a piece of software, it is a business model with software attached. The encryption is commodity. What the groups actually sell is pressure: on your operations while systems are down, on your reputation if the data is published, on your customers when they find out, and on your executives with a deadline attached. Every design choice in a modern attack, including stealing the data before encrypting it and deleting the backups first, exists to raise that pressure.

How Does Ransomware Work?

An attack is a sequence rather than an event, and the part everybody pictures sits at the end of it. Between the first step and the last there is usually a week, sometimes a month, of quiet work: mapping the network, stealing administrator credentials, finding the file servers, finding the backups, and moving the data out.

How a ransomware attack unfolds
  1. Initial accessA phishing link, a stolen password, or an unpatched system facing the internet
  2. Foothold and reconPersistence is established, then the network is mapped: file servers, domain controllers, backups
  3. Credentials and spreadAdministrator accounts are taken and remote tools are used to reach every machine that matters
  4. The detection windowDays pass here. Unusual admin activity and endpoint alerts are what catch an attack in time
  5. Data takenA copy leaves the network before anything is encrypted, which is what makes refusal expensive
  6. Backups deleted, files encryptedShadow copies and reachable backups go first, then the encryption runs, usually overnight
  7. The demandA note, a deadline, a negotiation portal, and a countdown to publication
Step four is the whole opportunity. An attack noticed at step three is an incident; the same attack noticed at step seven is an outage.

The joint FBI, CISA, HHS and MS-ISAC advisory on the Interlock ransomware group, published in July 2025, describes exactly this pattern in the field: the actors steal credentials and move laterally using ordinary remote administration tools such as RDP, AnyDesk and PuTTY before any encryption happens. That is the awkward part of detection. The tools used in stage three are frequently the same tools your own administrators use, which is why behavior matters more than file signatures.

How Ransomware Gets In

There is no exotic route. Four doors account for nearly all of it, and every one of them is closable.

  1. An unpatched system facing the internet. A VPN appliance, a file transfer product, a remote desktop gateway. Exploiting a vulnerability is now the way in for 31 percent of all breaches, ahead of stolen credentials for the first time in 19 years of the 2026 Verizon Data Breach Investigations Report.
  2. A password that already leaked. Bought from an infostealer market, reused from another breach, or simply guessed against a remote access service with no multi-factor authentication in front of it.
  3. A message. A phishing email with an attachment or a link, still the most common route into smaller organizations, and the one that scales.
  4. A download the user was persuaded to run. The Interlock advisory documents two versions: a drive-by download from a compromised legitimate website, with the payload disguised as a fake browser update or fake security software, and a fake CAPTCHA that instructs the visitor to run a PowerShell script to prove they are human.

A fifth route, less common but worth knowing, is a supplier: compromise a managed service provider or a software vendor and the ransomware arrives through a trusted channel with legitimate credentials. It is the same list that governs the threats that cause breaches generally, which is the point. Ransomware is not a special entry method, it is a particularly expensive thing to find at the end of an ordinary one.

Types of Ransomware

TypeWhat it doesWho it targetsWhat it means for you
Encrypting ransomwareEncrypts files and sells the decryption keyOrganizations, mostlyThe classic case. Recovery is backups or the key
Locker ransomwareLocks the screen or the device without encrypting filesIndividuals, phonesUsually recoverable without paying anything
Leakware or extortion onlySteals data and threatens publication, with no encryption at allAny organization holding customer dataBackups do not help. The data is already gone
Mobile ransomwareLocks an Android device, often through an app installed outside the storeIndividualsA factory reset almost always resolves it
ScarewareFakes an infection or a legal notice to extract a paymentIndividualsNothing is encrypted. Close the browser
Wiper posing as ransomwareDestroys data and demands payment it never intends to honorTargeted organizationsPaying achieves nothing. Recovery is backups only

Ransomware as a service is why the number of groups keeps growing

Most ransomware today is rented. A development group builds and maintains the encryption software, the leak site and the negotiation portal, then recruits affiliates who carry out the intrusions and split the proceeds. This separates the skill of breaking in from the skill of building malware, which is why the population of active groups keeps expanding and why a group being taken down by law enforcement rarely reduces the total for long. The affiliates move.

The variants actually reported in 2025

Most articles on this topic still lead with CryptoLocker, WannaCry and Conti, which are historically important and no longer the problem. The ten variants most reported to the FBI in 2025, per the 2025 IC3 Annual Report, were Akira, Qilin, INC and its Lynx and Sinobi relatives, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay and Medusa. Between them they accounted for 56.8 percent of reported incidents. The FBI also identified 63 new variants during the year, an average of just over 5 a month, which tells you more about the health of this market than any single name does.

What Is Double Extortion?

Double extortion is stealing the data before encrypting it, so that refusing to pay still costs you. CISA's guidance puts it plainly: ransomware actors often target and threaten to sell or leak exfiltrated data or authentication information if the ransom is not paid. The Interlock advisory says the same thing about that group specifically, describing a double extortion model in which the actors encrypt systems after exfiltrating data, which increases pressure on victims to pay.

There are now typically four levers pulled at once:

  • Encryption, which stops you operating.
  • Publication, which turns an IT incident into a regulatory and reputational one.
  • Direct contact, with your customers, your staff or the press, so you cannot manage the disclosure quietly.
  • Regulatory pressure, including complaints filed to regulators about the victim's own breach reporting.

The logical end of this is extortion with no encryption at all, and that is now the dominant model in the largest US data leaks. If the leverage is the data rather than the downtime, the encryption step is just extra work and extra noise. A group that skips it can compromise a cloud application, take the records and issue the demand without ever deploying a payload an endpoint tool could catch.

How Do I Know If I Have Ransomware?

Once it has run, you know. Files will not open, their extensions have changed, and there is a text file or a changed desktop background telling you where to negotiate. There is no ambiguity by design.

The useful question is how you would know before that, during the days the attackers spend inside. The signs are all operational rather than visual, which is why they get missed.

For an individual, the picture is simpler and usually less severe. A full-screen browser warning demanding payment is nearly always scareware and closing the browser ends it. Genuine encrypting ransomware on a personal computer is rarer than it was, because the groups that survived learned that companies pay more.

What Happens If You Get Ransomware?

The first hour matters more than the next week. The goal in that hour is to stop the spread and preserve the evidence, in that order, and the two goals conflict less than people expect.

For an individual whose personal files have been encrypted, the sequence is shorter: disconnect the device, do not pay, check whether a free decryptor exists for the variant, and restore from a backup if you have one. Whatever was on the machine should also be treated as taken, and the follow-up for that is the same as for any leak, set out in what to do after a data breach.

Should You Pay a Ransomware Ransom?

The FBI's position is unambiguous and worth quoting exactly: it does not support paying a ransom in response to a ransomware attack, because paying does not guarantee that you or your organization will get any data back, and because it encourages perpetrators to target more victims. The Europol-backed No More Ransom project says the same thing in blunter language: paying only confirms that ransomware works, and there is no guarantee you get the decryption key in return.

That is the right default, and this page endorses it. It is also worth being honest that it is a position taken by people who will not be running your business next Monday.

Myth vs reality
What people believe
If we pay, we get our data back and the incident is over.
What actually happens
Payment buys a decryption tool, not a resolution. The tool may be slow or may fail on some files, the stolen copy remains in the attacker's hands, the same access route is still open unless it is found and closed, and organizations that pay are known to be revisited. The end of a ransomware incident is a rebuilt environment and closed access, whether or not anything was paid.

Is It Possible to Remove Ransomware?

Yes, and that is a smaller victory than it sounds, because removing ransomware and recovering files are two different problems.

Removing it is achievable. Antivirus and endpoint tools detect and delete most known families, and a full operating system reinstall removes anything. Since attackers usually leave several ways back in, a serious incident ends with rebuilding affected systems from known-good images rather than cleaning them, and with every credential in the environment rotated.

Getting the files back without paying has three routes and no others. Restore from a backup the attackers could not reach. Use a free decryptor, if one exists: No More Ransom publishes tools for a limited set of variants, usually the ones whose keys were seized in a law enforcement operation or whose encryption was implemented badly, and it is explicit that not every type of ransomware has a solution. Or accept the loss. There is no fourth option, and any product promising to decrypt arbitrary ransomware is selling you something that does not exist.

How to Prevent a Ransomware Attack

Prevention is unglamorous and well documented. The joint #StopRansomware Guide from CISA, MS-ISAC, the NSA and the FBI is the reference, and the FBI repeats the core of it in its annual report: offline, encrypted, immutable backups, no default credentials, least privilege on administrative accounts, multi-factor authentication everywhere, endpoint detection that can see lateral movement, network segmentation, and prioritized patching of internet-facing systems.

Where a ransomware attack gets stopped
Internet edgePatch fast, inventory what is exposed, and put MFA in front of every remote entry point
Email and webFiltering and DNS controls remove most delivery attempts before anyone sees them
IdentityPhishing-resistant MFA and least privilege cap how far one stolen account can travel
NetworkSegmentation, so one compromised machine is not the whole estate
EndpointDetection and response, watching behavior, which is what catches stage three
BackupsOffline, encrypted, immutable, and restore-tested rather than merely running
Your data
A short stack of external drives on a plain surface with the top one unplugged

Ransomware Attacks on Businesses

Ransomware is a business risk before it is a technical one, because the cost is measured in downtime and disclosure rather than in cleanup.

The sector pattern is worth knowing if you are deciding how much of this applies to you. The FBI's top ten variants most affected critical manufacturing, healthcare and government facilities. Outside the critical infrastructure sectors, the FBI received more than 1,400 ransomware complaints, and the two industries leading that list were legal services at 18 percent and contracting services at 17 percent. Those are small firms holding valuable data with no security team, which is the profile these groups now optimize for.

Key takeaways

  • Ransomware is malware that encrypts your files and sells the key back, but it is really a business model built on pressure.
  • An attack is five stages over days or weeks. The ransom note is stage five, and stages two through four are where it is catchable.
  • Double extortion means the data is stolen before it is encrypted, so refusing to pay still leaks it. Extortion with no encryption at all is now the dominant model in the largest data leaks.
  • Four doors: unpatched internet-facing systems, leaked passwords, phishing, and a download the user was persuaded to run.
  • The FBI does not support paying, because payment guarantees neither recovery nor silence and funds the next attack.
  • Removing ransomware and recovering files are separate problems. Backups, a free decryptor if one exists, or accepting the loss are the only routes back without paying.
  • Offline immutable backups you have actually restored from, MFA on remote access, and fast patching of exposed systems close most of it.

Common questions

What is ransomware in simple terms?

Software that gets into your computer or your company's network, scrambles your files so nothing opens, and demands money for the key that unscrambles them. Most attacks now also copy the files first and threaten to publish them if you do not pay.

What happens if you get ransomware?

Files stop opening, their names change, and a note appears with a deadline and a way to contact the attackers. Behind that, a copy of your data has usually already left the network and any backups the attackers could reach have been deleted. For a business it becomes an outage, a disclosure obligation and a negotiation at the same time.

How do I know if I have ransomware?

After it runs, it announces itself. Before it runs, the signs are operational: a new administrator account nobody created, remote access software appearing on a server, security logging switched off on a few machines, backup jobs failing, and large amounts of data leaving the network overnight.

Is it possible to remove ransomware?

Yes. Endpoint security tools remove most known families and a full reinstall removes anything. Removing it does not decrypt your files, and it does not undo the theft, so a serious incident ends with rebuilt systems and rotated credentials rather than a cleanup.

Should I pay the ransom?

The FBI says no, because payment does not guarantee you get your data back and it funds more attacks. That is the right default. The narrow real-world exception is an organization with no viable backup facing closure, and even then payment does not reliably prevent publication and can create legal exposure if the group is under sanctions, so counsel and law enforcement are involved before any money moves.

Can I get my files back without paying?

Three ways: restore from a backup the attackers could not reach, use a free decryption tool if one exists for that specific variant, or accept the loss. The No More Ransom project publishes free decryptors for a limited list of families and is clear that most have no solution.

How does ransomware get on a computer?

Through an unpatched system exposed to the internet, a password that leaked or was reused, a phishing message with a link or an attachment, or a download the user was persuaded to run, including fake browser updates and fake CAPTCHA pages that ask you to run a command.

Does antivirus stop ransomware?

Sometimes, and it is worth having, but it is aimed at the last step. By the time the encryption runs, the attackers have administrator credentials and can often disable the tool. What catches the earlier stages is behavioral endpoint detection plus someone reading the alerts.

Can ransomware infect a phone?

Android phones can get locker ransomware, usually from an app installed outside the Play Store, and a factory reset almost always clears it. iPhones effectively do not, and a full-screen web page demanding payment is a scam page rather than an infection. Close the browser tab.

How long does a ransomware attack take?

Initial access to encryption is typically days, sometimes weeks, and occasionally hours when the group is in a hurry. That gap is the detection window, and it is the reason speed of response matters more than any single preventive product.

On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →