Financially motivated
Ransomware
Ransomware operations are criminal businesses that break into organisations to lock or steal data and demand payment. Many work as an ecosystem where different people handle access, deployment and negotiation.
Motivation: Payment, obtained by locking data, threatening to publish it, or both.
Overview
Ransomware is malware that makes data or systems unusable, usually by encrypting them, until a payment is made. The people behind it are typically financially motivated criminals, and many operate like businesses: some specialise in getting access, others in deploying the malware, others in negotiation and payment handling.
The encryption most people picture is the last step of a longer intrusion. Before that, attackers spend time inside the network finding the most valuable systems, locating backups and, increasingly, copying data out so they can threaten to publish it. That combination is often called double extortion.
Because the goal is money, targets are chosen for their ability and need to pay rather than for what they do. Organisations that cannot tolerate downtime, such as hospitals, schools, local services and manufacturers, are attractive, but any organisation with valuable data and weak defences can be hit.
The good news is that this long intrusion gives defenders many chances to notice something is wrong. Strong identity security, patching, tested offline backups and monitoring for unusual administration activity all make ransomware harder to complete and easier to recover from.
How it unfolds
- 1
Get in
Phishing, an exposed remote service or a stolen or reused login provides the first foothold.
- 2
Explore
The attackers map the network, find administrators, servers, data and backups.
- 3
Take data
Sensitive files are copied out to give the attackers extra leverage.
- 4
Disable recovery
Backups and security tools are deleted or switched off where possible.
- 5
Lock and demand
Systems are encrypted at scale and a ransom note is left.
Common techniques
Stolen credentials
Valid logins bought or phished are the most common way in, because they look like normal users.
Exposed remote access
Internet-facing remote desktop or VPN services without MFA or patches.
Abuse of administration tools
Built-in tools are used to move around and to launch encryption on many machines at once.
Backup tampering
Attackers look for and delete or encrypt backup systems before triggering encryption.
Data theft before encryption
Files are compressed and sent out, so a restored backup does not end the pressure.
Who is targeted
- Organisations that cannot afford downtime, such as healthcare, education and public services
- Businesses with valuable or regulated data
- Organisations with exposed remote access or weak identity controls
- Companies with backups that are reachable from the main network
An example
A staff member's password is captured through a fake sign-in page. Over several days, someone signs in, browses file shares and tests access to servers. On a weekend evening, many machines show a ransom note at once, and a message arrives showing samples of files taken earlier. The early access was there for days; the encryption was simply the moment it became visible.
An illustrative scenario, not a report of a specific incident.
What to look for
- Unusual administrative activity outside business hours
- Backup deletion, or security tools being disabled
- Large outbound data transfers to unfamiliar destinations
- Many files being renamed or modified in a short time
How to defend
- Use MFA everywhere, especially on email, VPN and administrator accounts
- Patch and reduce internet-facing services, and monitor remote access
- Keep offline or immutable backups and test restoring from them
- Monitor for unusual administrative activity and large outbound transfers
- Practise your incident response plan, including who decides about payment and communication
Key terms
- Double extortion
- Demanding payment both to unlock files and to keep stolen data private.
- Initial access
- The first foothold an attacker gains, such as a stolen login.
- Lateral movement
- Moving from one system to another inside a network.
- Immutable backup
- A backup that cannot be altered or deleted for a set period.
This is a general profile of a type of threat. It does not attribute any specific incident to any named group.
Go deeper on ransomware
- Attacks
Ransomware: What Really Happens When Hackers Lock Your Files
The locked-screen moment is the loud part. Understanding what happens before it is where defenders find their advantage.
2 min read - Ransomware
Double Extortion: When Locking Your Files Is Only Half the Threat
Modern ransomware often steals data first. Restoring from backup fixes the locked files, but not the threat to publish what was taken.
2 min read - AI + SOC Workflows
AI in Incident Response: How I Use It During Real Investigations
Where an AI assistant can genuinely save an analyst time during an incident, and where a human must stay in charge.
2 min read - SOC & Blue Team
EDR: The Flight Recorder on Every Laptop
Antivirus asks 'have I seen this file before?'. EDR asks 'what is this machine doing right now, and does it look wrong?'.
2 min read