
Ransomware is a type of malicious software that prevents systems from being used or data from being accessed and demands payment or another condition to restore them. It commonly encrypts files, locks devices or disrupts essential services.
Some campaigns also extract information before blocking it and threaten to publish or sell it. When an incident consists solely of theft and a disclosure threat, without encryption or locking, it is data extortion, a related but distinct practice.
Table of contents
Ransomware operation
A ransomware incident commonly develops through these three stages:
-
Initial access: An attack begins when its operators gain the ability to execute code or access an account or system. They may use phishing, stolen credentials, exposed remote services, unpatched vulnerabilities or access provided by other malicious software.
Initial access does not by itself determine the incident’s scope. An account with limited permissions may restrict the damage, while administrative credentials or poorly segmented infrastructure may allow the attack to reach more systems and services.
-
Propagation: After gaining access, attackers may discover network resources, escalate privileges, obtain more credentials and move between systems. Some operations attempt to disable security tools, remove accessible backups or compromise administration services.
Ransomware may be executed immediately or after a preparation period. Visible encryption is commonly an advanced stage of the incident, rather than necessarily the moment when the intrusion began.
-
Impact: The program may encrypt documents, databases, servers, devices or shared repositories. It may also lock the interface or prevent the system from starting. These actions are forms of malware, combined with a ransom or extortion demand.
The damage is not limited to encrypted files. It may include operational disruption, loss of availability, data exposure, investigation and recovery costs, contractual failures and effects on customers or suppliers.
Ransomware methods
Extortion methods
The main ways of affecting systems and data are as follows:
-
Data encryption: Crypto-ransomware transforms files using keys that prevent them from being used normally. The possibility of recovering the information depends on the variant, its encryption implementation, the availability of valid backups and whether a decryption tool exists.
-
System locking: Locker ransomware restricts access to a device or particular functions without necessarily encrypting all its data. It may display a screen that prevents the system from being used and demands an action to restore access.
-
Multiple extortion: Double extortion combines encryption with a threat to publish previously extracted information. Some operations apply additional pressure by contacting customers, disrupting services or threatening third parties.
Recovering files does not by itself resolve a possible data breach. If information was extracted, confidentiality, applicable obligations and the consequences for affected people need to be assessed separately.
Ransomware as a service
Ransomware as a service, or RaaS, is a criminal operating model in which some actors develop and maintain the infrastructure while affiliates obtain access and execute attacks. Participants may share payments or contract different parts of the operation.
RaaS describes an organisational model, not a different encryption technology. The same family may use several access, extortion and distribution methods.
Use of language models
Large language models, or LLMs, are being incorporated into ransomware operations to accelerate development and preparation tasks. They can help generate or refine code, write phishing lures, adapt messages for different languages, analyse information obtained during access or automate particular actions.
Prototypes that query a model during execution have also appeared. In 2025, Google Threat Intelligence documented PROMPTLOCK, an experimental proof of concept capable of using an LLM to generate scripts for file reconnaissance, data exfiltration and encryption on Windows and Linux systems.
Using an LLM may reduce the time or expertise required for some phases, but it does not automatically make the attack autonomous. The existence of prototypes and AI-assisted tools demonstrates an emerging technical capability, not that model-controlled ransomware is already widespread.
Ransomware prevention
Risk reduction requires these three lines of action to be combined:
-
Exposure reduction: Prevention combines vulnerability management, system updates, multifactor authentication, least privilege, segmentation, email protection and control of exposed services. Firewalls can restrict particular connections but do not replace identity, device and application controls.
No single measure prevents every intrusion. Training helps people recognise deception, but technical controls are also needed to limit the effect of compromised credentials or human error.
-
Backup protection: Backups need to be separated from the systems they protect and use controlled credentials and permissions. Some versions need to remain offline or immutable so that an attacker cannot encrypt or delete them.
A backup is useful only when it contains the required information and can be restored within operational requirements. Recovery testing identifies incomplete, damaged or inaccessible copies before an emergency.
-
Operational preparedness: An organisation needs to know its assets, dependencies, privileged identities and critical services. Logs, alerts and protection tools can help detect activity such as mass file changes, unusual credential use or lateral connections.
The response plan needs to define responsibilities, alternative communication channels, escalation criteria, evidence preservation and recovery priorities. The UK National Cyber Security Centre provides current guidance on mitigating malware and ransomware.
Ransomware response
Incident management is organised into four lines of action:
-
Containment: Affected systems need to be isolated in accordance with the response procedure to limit propagation. It may also be necessary to block compromised accounts, restrict connections and protect backups that have not yet been reached.
Actions need to be coordinated so that evidence is not destroyed and disruption is not expanded. Shutting down, restarting, deleting or reinstalling systems without prior assessment may make investigation and recovery more difficult.
-
Investigation: The investigation establishes which devices, accounts, applications and data were affected. It needs to determine how access was obtained, which actions took place, whether information was extracted and which mechanisms could maintain access.
Logs and forensic images help reconstruct the sequence. The absence of a ransom note or encrypted files does not rule out unauthorised access or data theft.
-
Recovery: Recovery may require rebuilding systems from clean sources, correcting the exploited weakness, renewing credentials and restoring verified backups. Services need to be returned in a controlled sequence and monitored for residual activity.
Decryption tools exist for some variants. The No More Ransom project helps identify particular families and locate verified solutions. An unknown decryptor should not be used on original data without retaining a copy and verifying its source.
-
Communication: The response may require coordination with specialists, insurers, authorities, suppliers, customers and affected people. Notification obligations depend on the information compromised, the sector and the jurisdiction.
Payment does not guarantee a working key, deletion of stolen data or protection against another attack. It may also create legal, financial and operational risks. Any decision needs to be based on the incident investigation and specialist advice.
