What Is Ransomware? How It Works, Who It Targets, and How to Stay Protected

Key Takeaways
Imagine showing up to work and finding your entire computer system locked. Every file, customer record, and financial document is encrypted and inaccessible. A message demands thousands of dollars in cryptocurrency to restore access, and threatens to publish your data if you refuse.
That's ransomware: one of the most destructive threats in the modern security landscape. And it's getting worse.
According to GuidePoint Security, claimed ransomware victims jumped ~58% in 2025, with over 7,500 organizations listed on public attacker leak sites, up from roughly 4,750 in 2024. Verizon's 2025 Data Breach Investigations Report found 44% of all data breaches that year involved ransomware.
This isn't a niche concern for large enterprises, it affects businesses of every size, schools, hospitals, and individuals. Understanding how ransomware works and how to protect yourself has never been more important.
What is ransomware?
Ransomware is malware that encrypts files on a victim's device or network, making them completely inaccessible. The attacker then demands a ransom, typically in cryptocurrency, in exchange for the decryption key.
Your data is essentially held hostage.
What started as a straightforward criminal scheme has evolved into a multi-billion-dollar industry. Modern ransomware attacks now routinely include data theft, public shame campaigns, and layered extortion tactics far beyond a simple locked screen.
A brief history: from floppy disks to global crises
The first known ransomware attack, the AIDS Trojan (PC Cyborg), dates to 1989. Distributed via floppy disks at a World Health Organization conference, it hid directory structures and demanded victims mail $189 to a P.O. box in Panama.
By 2017, WannaCry brought ransomware into global headlines, infecting 230,000 computers across 150 countries in a single day. It crippled the UK's National Health Service and caused an estimated $4-8 billion in damages, exploiting an NSA-discovered Windows vulnerability and cementing ransomware as a geopolitical issue.
Today's ransomware gangs operate like professional businesses, complete with customer support, negotiation teams, and subscription-based affiliate programs.
How does ransomware work?
Ransomware attacks follow a consistent playbook:
Step 1: Initial access
The most common entry points, per ESET and CISA, include:
- Phishing emails: malicious links or attachments that trick users into downloading malware
- RDP exploitation: attackers brute-force or use stolen credentials to access exposed remote desktop connections
- Stolen credentials: purchased from Initial Access Brokers on dark web marketplaces
- Unpatched vulnerabilities: known security flaws in outdated software
- Malvertising and infected downloads: malicious ads or pirated software that secretly install ransomware
Step 2: Persistence and lateral movement
Once inside, the malware establishes persistence and moves laterally across the network. Attackers often spend days or weeks mapping systems, escalating privileges, and identifying valuable data before triggering the ransomware.
Step 3: Data exfiltration
In modern "double extortion" attacks, attackers steal data before encrypting it, creating two forms of leverage. According to deepstrike.io, ~77% of ransomware intrusions in 2025 involved data exfiltration, up from 57% in 2024.
Step 4: Encryption
The ransomware payload encrypts files across the infected system and all mapped network drives. Victims lose access almost instantly. Modern ransomware also targets and destroys backup files, per ESET: "It is almost inevitable that attackers try to encrypt and/or destroy any backups they can find."
Step 5: The ransom demand
A ransom note demands payment in Bitcoin or Monero, with a deadline before the price doubles or data goes public. The median ransom payment in 2025 jumped to ~$59,600, up from ~$12,700 in 2024. Chainalysis reported total blockchain ransomware payments near $820 million in 2025.
Types of ransomware
Encrypting ransomware (crypto-ransomware)
The most common type, encrypts files and demands payment for the decryption key. Examples include WannaCry, Locky, and REvil.
Locker ransomware
Locks the user out of their device entirely without encrypting files. Less devastating but still highly disruptive.
Scareware
Fake warnings mimicking antivirus software or law enforcement, claiming your device is infected and demanding payment to "fix" it. The threat is largely a bluff, but convincing enough to trick many users.
Double extortion
Attackers steal data and encrypt it. Even if you restore from backups, they threaten to publish your data unless you pay. This has become the dominant tactic.
Triple and quadruple extortion
An escalation where attackers also launch DDoS attacks, contact customers or partners directly, or threaten regulatory reporting to maximize pressure.
Ransomware-as-a-service (RaaS)
Criminal groups offer ransomware tools, infrastructure, and support as a subscription service to "affiliates," taking a cut of profits. RaaS has industrialized ransomware, making it accessible to low-skill attackers and dramatically increasing attack volume.
Who does ransomware target?
The short answer: everyone. But some groups face significantly higher risk.
Small and mid-sized businesses
Despite media focus on large enterprises, ESET reports 65% of publicly reported ransomware victims in 2025 had 1-200 employees. Verizon's DBIR found ransomware present in 88% of breaches involving small organizations, versus 39% for large enterprises. Smaller organizations have fewer security resources, less mature defenses, and are less likely to have incident response plans.
Healthcare
Hospitals are high-value targets because downtime can cost lives, creating enormous pressure to pay quickly. The PowerSchool breach in late 2024 exposed data on 62 million students and 9.5 million teachers across North America, illustrating how far-reaching healthcare-adjacent attacks can be.
Education
Schools and universities run aging infrastructure on limited budgets, making them attractive targets. The 2024-2025 school year saw a notable spike in attacks against K-12 and higher education institutions.
Manufacturing and industrial
Downtime interrupts production lines and can cost millions per hour. Attackers price ransoms accordingly. Legacy systems common in industrial environments are also harder to patch.
Finance and professional services
Sensitive financial data and regulatory exposure make these firms attractive extortion targets, the threat of a data leak adds leverage beyond the ransom itself.
Individuals
Everyday users are targeted through malvertising, infected downloads, and phishing. Attackers count on individuals being less equipped to respond and more emotionally distressed by the threat of losing personal files and photos.
Notable ransomware attacks: real-world examples
WannaCry (2017)
Exploiting a leaked NSA vulnerability, WannaCry infected 230,000+ systems across 150 countries in one day, crippled the UK's NHS, and caused an estimated $4-8 billion in damages. It was later attributed to North Korea's Lazarus Group.
Colonial Pipeline (2021)
The DarkSide attack on the US's largest fuel pipeline caused East Coast fuel shortages and a $4.4 million ransom payment (partially recovered by the FBI), demonstrating ransomware's ability to threaten critical national infrastructure.
Change Healthcare (2024)
A ransomware attack on UnitedHealth Group's Change Healthcare subsidiary disrupted insurance claims processing across the US healthcare system for weeks, affecting hospitals and pharmacies nationwide. It is considered one of the most impactful healthcare cyberattacks in US history.
PowerSchool (2024-2025)
Criminals breached K-12 software provider PowerSchool in late 2024, exposing records for 62 million students and 9.5 million teachers across North America, highlighting the vulnerability of ed-tech supply chains.
How to protect yourself from ransomware
Prevention is far cheaper than recovery. The average ransomware breach costs ~$5 million including remediation, downtime, legal exposure, and lost business, far exceeding the ransom itself. Here's what CISA, ESET, and the FBI recommend:
1. Maintain offline, encrypted backups
CISA's #StopRansomware Guide lists offline backups as the single most important preventive measure. Store at least one copy offline (air-gapped from your network), ransomware can't encrypt what it can't reach. Test backups regularly; a backup that fails when needed is no backup at all.
2. Use multi-factor authentication (MFA) everywhere
Compromised credentials are a top ransomware entry path. MFA means stolen passwords alone can't unlock your systems. Enable it on email, VPNs, cloud services, and remote access tools.
3. Keep systems and software patched
Unpatched vulnerabilities are a gold mine for attackers. WannaCry infected 230,000 machines because organizations hadn't applied a patch Microsoft released weeks earlier. Enable automatic updates and maintain a regular patch cadence.
4. Train employees to recognize phishing
Phishing is the #1 initial access vector. Regular security awareness training, including simulated phishing exercises, significantly reduces the risk of someone clicking a malicious link.
5. Limit RDP exposure
If your organization doesn't need Remote Desktop Protocol, disable it. If you do, place it behind a VPN, require MFA, and monitor for unusual access. Exposed RDP ports are consistently among the top ransomware entry points.
6. Implement endpoint detection and response (EDR)
EDR tools use behavioral analysis to detect ransomware-like activity, such as rapid file encryption, before it causes full damage, and can automatically isolate infected endpoints.
7. Apply the principle of least privilege
Limit user and system access to only what's necessary. Segment your network so a compromised segment can't easily spread to everything else.
8. Have an incident response plan
Before an attack, document who to notify, how to isolate compromised systems, when to involve law enforcement, and how to communicate with customers. Organizations with a tested IR plan recover faster and at lower cost.
9. Consider cyber insurance
Cyber insurance can provide financial support for ransom negotiation, incident response, legal costs, and business interruption. Review policy terms carefully, some insurers have clauses that affect ransomware payouts.
For individuals: quick wins
- Keep your OS and apps updated
- Use reputable security software with real-time protection
- Avoid clicking suspicious email links or attachments
- Don't download software from unofficial sources
- Back up important files to an external drive or secure cloud storage
- Be skeptical of pop-up warnings demanding payment or threatening legal action
Should you pay the ransom?
The FBI and CISA both advise against paying ransoms. Paying:
- Doesn't guarantee you'll get your data back, some victims pay and receive no working decryption key
- Funds criminal operations, enabling future attacks
- Marks you as a "payer", potentially making you a target again
- May violate sanctions laws if the ransomware group is on a government sanctions list
Organizations are increasingly refusing to pay. According to Verizon's 2025 DBIR, 64% of victim organizations did not pay a ransom, up from 50% just two years earlier, though this partly explains why attackers have shifted toward harder extortion tactics to force compliance.
Conclusion
Ransomware is no longer a theoretical risk for "someone else." It's a pervasive, evolving threat that hits businesses of all sizes, public institutions, and individuals alike. In 2025 alone, over 7,500 organizations were publicly named as victims, and that's only those who refused to pay quietly.
The good news: ransomware is also one of the most preventable cyberattacks when organizations invest in the right defenses, offline backups, MFA, patching, employee training, and a solid incident response plan.
You don't need to be a security expert to protect yourself. You just need to take it seriously before an attack happens.
FAQs
What is ransomware in simple terms?
Ransomware is malicious software that locks or encrypts your files and demands payment (usually cryptocurrency) before the attacker will restore your access. Think of it as a digital hostage situation: your data is held until you pay.
How does ransomware get onto your computer?
The most common entry points are phishing emails with malicious links or attachments, exploited vulnerabilities in unpatched software, stolen login credentials used to access remote systems, and infected downloads or malicious ads. Phishing remains the single most frequent method.
Should you pay a ransomware demand?
The FBI and CISA advise against paying. Paying doesn't guarantee you'll get your data back, funds future criminal operations, and can make you a repeat target. In 2025, 64% of victim organizations chose not to pay, according to Verizon's DBIR.
Can ransomware be removed without paying?
Sometimes. If you have clean, offline backups, you can restore your systems without paying. Free decryption tools exist for some older ransomware strains at NoMoreRansom.org. For newer variants, decryption without the attacker's key is typically not possible, which is why prevention and backups are so critical.
What industries are most targeted by ransomware?
Healthcare, education, manufacturing, and financial services are among the most frequently targeted sectors. Small and mid-sized businesses account for the majority of victims: 65% of publicly reported ransomware victims in 2025 had fewer than 200 employees, according to ESET.
What is Ransomware-as-a-Service (RaaS)?
RaaS is a criminal business model where ransomware developers rent out their tools, infrastructure, and support to other attackers (called affiliates) in exchange for a percentage of ransom payments. It has dramatically lowered the technical barrier to carrying out ransomware attacks.
What is double extortion ransomware?
Double extortion is when attackers steal your data before encrypting it. They then threaten two things: they won't decrypt your files unless you pay, and they'll publicly release your stolen data if you don't. About 77% of ransomware attacks in 2025 involved data exfiltration, according to GuidePoint Security.
How can individuals protect themselves from ransomware?
Keep your operating system and software updated, use real-time security protection, avoid clicking suspicious links or downloading files from unofficial sources, back up important files to an external drive or secure cloud storage, and be skeptical of pop-up warnings that demand payment.






