Ransomware encrypts files and demands payment for a key. The damage is worse when there is no backup, and paying is not the fix.
How it works
Attackers use a weakness in a system or a phishing message. They encrypt sensitive files, such as personal data, financial records, or files the business needs, so the files cannot be read without a decryption key. The demand is often in cryptocurrency. Payment does not guarantee the files come back. Attackers may demand more and threaten to sell or leak the data. That is double extortion. Ransom amounts average millions of dollars per attack when there is no reliable backup and people feel forced to pay.
Why payment backfires
- No guarantee. Studies show 92 percent of victims do not fully recover the encrypted data. The attacker may not send a working key, or may demand more money.
- The payment funds the next attack.
- The attacker may keep a copy and leak or sell it later.
More than 70 percent of ransomware victims now refuse to pay.
How common it is
Experts estimate 1.7 million attacks a day, from individuals to large companies. Kits are for sale on the dark web, so a novice can launch an attack with little skill.
What helps
- Back up often, and keep copies offline. Encrypted cloud backups are a useful option.
- Use antivirus, firewalls, and endpoint protection to catch ransomware before it spreads.
- Train people to recognize phishing and the other tricks used to deliver it.
- Update the operating system, browsers, and other applications so known holes are patched.
- Turn on multi-factor authentication so a password alone is not enough.
Further reading includes CISA’s Ransomware Guide and Norton’s ransomware overview. Backups and security work protect the data more reliably than a payment does.
Back to the blog