How Ransomware works
Three-step view of how it operates in practice.
- Intrusion. Attackers get in, usually through phishing, stolen credentials, or an unpatched internet-facing system. They often spend days moving laterally.
- Exfiltration. Before encryption, modern ransomware gangs copy sensitive data out. This is leverage for double extortion.
- Encryption & demand. Files are encrypted, backups deleted where possible, and a ransom note appears. Downtime begins.
Why Ransomware matters
For a midsize organization, ransomware compounds every cost at once, weeks of downtime, recovery labor, legal exposure from stolen data, and reputational repair, and global breach costs now average several million dollars in IBM's annual research. The affiliate economy targets smaller businesses precisely because defenses are lighter, so the preparation that matters, protected backups, hardened access, a rehearsed response, has to happen before the note appears.
Encryption-only vs double extortion vs RaaS
- Encryption-only. The classic model: files are locked and payment buys the key. Reliable backups largely defeat it — which is precisely why the criminals evolved.
- Double extortion. Data is stolen before it's encrypted, and the ransom threatens publication as well as lockout. Restoring from backup no longer ends the threat — now it's a data-breach problem too.
- Triple extortion. Pressure widens further: your customers or partners are contacted directly, or attacks on your services pile on until payment. The blast radius extends beyond your own walls.
- Ransomware-as-a-Service. Developers rent their platform to affiliates who run the intrusions and split proceeds. This franchise model is why sophisticated attacks reach small organizations that once flew beneath the threat.
Common Ransomware mistakes
- Believing backups end the story. Against double extortion, a perfect restore still leaves stolen client data in criminal hands and notification laws in play. Backups remain essential — but pair them with controls that keep data from leaving in the first place.
- Engaging attackers alone. Paying without counsel risks sanctions violations if the gang is on a prohibited list, and paid-for decryptors are frequently slow or defective. Involve your insurer and experienced legal counsel before any contact with the attackers.
- Restoring before evicting. Rebuilding systems while the attacker's accounts and backdoors survive invites re-encryption weeks later, a well-documented pattern. Eradicate persistence, reset credentials, and verify clean before recovery begins.