All malware guidance

Explainer

Ransomware

Extortion malware that encrypts systems, and increasingly steals data first, to force a payment after attackers have already gained access.

In this section

What it is

Ransomware is malicious software that encrypts files and the systems that depend on them, then demands payment for a decryption key. CISA's #StopRansomware guide notes that most operations now add a second lever, known as double extortion: they copy data before encrypting it and threaten to publish it. Some crews skip encryption entirely and extort on stolen data alone.

How it gets in

Ransomware is usually the last stage of an intrusion, not the first. CISA lists the common entry points as vulnerable internet-facing systems and misconfigurations, stolen credentials, phishing, precursor malware such as loaders, social engineering, and compromised third parties or managed service providers. Attackers typically spend time inside the network escalating privileges, disabling defences and finding backups before they launch the encryptor.

What it does

Once deployed, the payload encrypts file shares, servers and often virtualisation hosts, halting operations. Stolen data is posted to a leak site if the victim does not pay. Most brands run as ransomware-as-a-service: a core team maintains the malware and leak site, and affiliates carry out the intrusions in exchange for a share of the ransom.

Notable groups in 2025-2026

According to Comparitech, Qilin was the most prolific group in the first half of 2026 with 641 claimed victims, followed by The Gentlemen (464) and Akira (317). In August 2026, Comparitech recorded a monthly record of 997 attacks, led again by Qilin and The Gentlemen. Cl0p followed a different model: SecurityWeek reported that by August it had named more than 40 organisations it claimed to have breached through a flaw in PTC Windchill software, stealing data without relying on encryption.

Claims versus confirmed attacks

Headline counts come mostly from leak-site posts, which are extortion claims. Comparitech's figures show the gap: of 997 attacks it tracked in August 2026, just 77 had been confirmed by the victim at the time of publication.

How it is used downstream

The payoff is extortion: a ransom for decryption, for deleting stolen data, or both. Comparitech put the median ransom demand in confirmed first-half 2026 cases at $150,000. Beyond the ransom, victims face outage costs, regulatory notifications and the risk that leaked data fuels fraud against their customers.

Detect and contain

Detection signals

  • Mass file renames or high-entropy writes across file shares
  • Shadow-copy and backup deletion commands, or backup agents being stopped
  • New services or scheduled tasks pushed domain-wide, and large outbound transfers to unfamiliar cloud storage

Reduce the blast radius

  • Keep offline or immutable backups and regularly test restores
  • Patch internet-facing systems first, prioritising known exploited vulnerabilities
  • Use phishing-resistant MFA and tiered admin accounts; segment hypervisors from user networks

Questions people ask

Is ransomware a virus?

Not in the strict sense. A virus is malware that copies itself into other files to spread, while ransomware is defined by what it does: encrypt or steal data for extortion. Most ransomware is deployed deliberately by human operators after they break into a network, rather than spreading on its own, although both are types of malware.

Should you pay a ransomware demand?

Payment does not guarantee working decryption or that stolen data will be deleted, and it funds further attacks. Government guidance such as CISA's focuses on preparation and recovery from backups, and advises contacting law enforcement early, partly because free decryptors exist for some variants. Organisations should also check sanctions rules before any payment.

How does ransomware get into a network?

The most common routes are unpatched internet-facing systems, stolen or weak credentials for remote access, phishing emails, loader malware that installs further tools, and compromised suppliers or IT service providers. Attackers usually move through the network for days before encrypting anything, which gives defenders a window to detect them.

What is double extortion ransomware?

Double extortion means attackers steal a copy of the victim's data before encrypting systems, then threaten to publish it on a leak site if the ransom is not paid. Even an organisation that restores from backups can still face pressure over the stolen data. Some groups now skip encryption and rely on data theft alone.

Further reading