Ransomware Attack Types, 12 Tell-Tale Signs & 12 Recent Examples

What Is a Ransomware Attack?

Ransomware attacks are malicious cyber operations where criminals infect a victim's network with malware to encrypt critical files or steal sensitive data. Attackers then demand a ransom, typically paid in cryptocurrency, to restore access or prevent the leaked publication of the stolen data. In a typical ransomware attack, a ransom note appears on the victim’s screen, threatening permanent data loss or public exposure unless the payment is made within a specific timeframe.

Ransomware attacks can target individuals, businesses, hospitals, schools, and government agencies, making them a widespread threat. Ransomware spreads through phishing emails, malicious attachments, infected websites, or exploiting vulnerabilities in software and remote access protocols. The attacker’s goal is to maximize disruption, pressure the victim into paying, and avoid detection for as long as possible.

How ransomware attacks work:

  • Initial access: Attackers gain entry through phishing emails, malicious attachments, compromised websites, exposed remote access services, or unpatched software vulnerabilities.
  • Privilege escalation and lateral movement: After entering the network, attackers obtain higher privileges and move across systems to identify valuable assets and expand their reach.
  • Data theft and encryption: Sensitive data is often exfiltrated before ransomware encrypts files, creating leverage for double-extortion attacks.
  • Ransom demand: Victims receive a ransom note with payment instructions, deadlines, and threats to leak stolen data if demands are not met.

Modern attack methods include:

  • Crypto ransomware: Encrypts files and demands payment for a decryption key.
  • Locker ransomware: Locks users out of devices or systems without necessarily encrypting files.
  • Double-extortion attacks: Combine data theft with encryption and threaten public disclosure of stolen information.
  • Triple or quadruple extortion: Add pressure through tactics such as contacting customers, regulators, or launching DDoS attacks.
  • Ransomware-as-a-Service (RaaS): Developers lease ransomware tools to affiliates, enabling large-scale attacks by less-skilled criminals.

In this article:

The Impact and Dangers of Ransomware Attacks

Ransomware attacks can have consequences that go far beyond temporary data loss. They can disrupt daily operations, create financial strain, damage reputations, and expose sensitive information. The impact varies depending on the victim, but the risks are significant for both individuals and organizations.

  • Financial losses: Victims may face ransom demands, recovery costs, legal fees, regulatory fines, and expenses related to restoring systems and data.
  • Operational disruption: Critical systems can become inaccessible, causing downtime that interrupts business activities, healthcare services, education, or government operations.
  • Data loss and corruption: Even if a ransom is paid, there is no guarantee encrypted files will be fully restored or that data has not been permanently damaged.
  • Data breaches and extortion: Many ransomware groups steal sensitive data before encryption and threaten to publish it unless additional payments are made.
  • Reputational damage: Customers, partners, and stakeholders may lose trust in an organization that experiences a ransomware incident, especially if personal data is exposed.
  • Productivity decline: Employees may be unable to access applications, files, or communication tools, delaying work.
  • Legal and compliance risks: Organizations that handle regulated data may face investigations, penalties, or lawsuits if a ransomware attack results in a data breach.
  • Supply chain impact: Attacks on a single organization can affect suppliers, customers, and partners, creating disruptions across connected networks and services.

Ransomware vs. Malware

Ransomware is a subset of malware, but not all malware is ransomware. Malware is a broad term that includes any software intended to cause harm or exploit devices, networks, or users. Types of malware include viruses, worms, trojans, spyware, adware, and others. Each variant has different objectives, such as stealing data, disrupting operations, or spying on users.

Ransomware’s distinct characteristic is its focus on extortion, encrypting data or locking systems to demand payment. While other malware might silently steal information or create backdoors for future exploitation, ransomware’s impact is immediate and visible. Understanding this distinction helps organizations implement targeted defenses and response strategies.

How Does a Ransomware Attack Work?

While there are many ransomware strains and the field is rapidly evolving, most ransomware attacks follow these general stages.

1. Initial Access

Attackers use various entry points to gain initial access to a target system. Common methods include phishing emails with malicious attachments or links, exploiting unpatched software vulnerabilities, or brute-forcing weak remote desktop protocol (RDP) passwords. These methods rely on human error or technical weaknesses to bypass security controls.

Once inside, attackers often deploy additional tools to maintain their presence. They may install backdoors, disable security software, or use legitimate system utilities to avoid detection. This phase sets the stage for further actions, such as privilege escalation and lateral movement within the network.

2. Privilege Escalation and Lateral Movement

After gaining a foothold, attackers seek higher privileges to access sensitive data or systems. They may exploit misconfigurations, harvest credentials, or use privilege escalation vulnerabilities. The goal is to move from a low-level user account to an account with administrative or domain-wide access.

Lateral movement involves spreading across the network to compromise more systems and locate valuable data. Attackers use legitimate tools, such as PowerShell or PsExec, to avoid triggering security alerts. By moving laterally, they increase the impact of the ransomware deployment, affecting as many systems as possible when the attack is executed.

3. Data Theft and Encryption

Modern ransomware attacks often involve data theft before encryption. Attackers exfiltrate sensitive files, such as customer records, financial documents, or intellectual property, to use as leverage for double extortion. Once data is stolen, the ransomware is triggered to encrypt files across compromised systems, rendering them inaccessible to users.

Encryption is performed using strong cryptographic algorithms, making decryption without the attacker’s key nearly impossible. Victims are presented with a ransom note demanding payment in exchange for the decryption key. The combination of data theft and encryption increases pressure on victims, as attackers can threaten to leak stolen data if the ransom is not paid.

4. Ransom Demand

After encrypting data and systems, attackers present a ransom demand, typically via a note displayed on infected devices. The note includes instructions for payment, often in cryptocurrency, and a deadline for compliance. Attackers may provide a sample decryption to prove they can restore access.

In recent attacks, criminals also threaten to publish stolen data or notify regulators if the ransom is not paid. Some groups run “help desks” to negotiate payments or answer questions. Regardless of whether payment is made, there is no guarantee that access will be restored or that stolen data will not be misused or sold.

Common Types of Ransomware Attacks

Ransomware Types at a Glance

The following table summarizes the main ransomware types. We explore each of these types in more detail below.

Comparison Factor Crypto Ransomware Locker Ransomware Double-Extortion Ransomware Triple/Quadruple Extortion
Primary Attack Method Encrypts files and demands payment for a decryption key Locks users out of devices or operating systems Encrypts files and steals sensitive data before encryption Combines encryption and data theft with additional pressure tactics such as contacting stakeholders or launching DDoS attacks
Characteristics Uses encryption to deny access to files Blocks access to devices rather than encrypting files Combines data theft with encryption to increase leverage Applies multiple forms of coercion beyond encryption and data theft
Impact on Victim Data becomes inaccessible and may be unrecoverable without backups Users cannot access devices or applications, but data may remain intact Causes operational disruption and creates risk of data exposure Creates operational, legal, reputational, and service availability risks simultaneously
Examples WannaCry, CryptoLocker, Ryuk Reveton, WinLock Maze, REvil Variants using DDoS attacks and direct outreach to customers, partners, or regulators

Crypto Ransomware

Crypto ransomware, also known as encrypting ransomware, is the most common form of ransomware attack. It encrypts the victim’s files using strong cryptographic algorithms, making them inaccessible without a decryption key. Victims are then presented with a ransom demand, typically with instructions for payment and a threat that the decryption key will be destroyed if the deadline is not met.

The impact of crypto ransomware is severe because data recovery without backups or the attacker’s key is nearly impossible. Well-known variants include WannaCry, CryptoLocker, and Ryuk. Organizations and individuals face operational disruptions and potential data loss, underscoring the importance of preventive security measures and regular backups.

Locker Ransomware

Locker ransomware differs from crypto ransomware by locking users out of their devices rather than encrypting individual files. The operating system or applications are rendered inaccessible, and a ransom message is displayed on the locked screen. Victims are unable to use their computers or mobile devices until the ransom is paid and access is sometimes restored.

Locker ransomware is often less destructive than crypto ransomware since data may remain intact and accessible once the lock is removed. However, it can still cause disruption, especially if critical endpoints are affected. Early locker ransomware targeted consumers, but more advanced variants now target businesses and organizations.

Double-Extortion Ransomware

Double-extortion ransomware adds pressure by encrypting data and exfiltrating sensitive information before encryption. Attackers threaten to release or sell the stolen data if the ransom is not paid.

This approach puts organizations at risk of regulatory fines, reputational harm, and legal consequences if sensitive customer or employee data is exposed. Notable ransomware groups, such as Maze and REvil, have used double-extortion tactics. The dual threat of data loss and public exposure increases the impact of these attacks.

Triple or Quadruple Extortion

Triple or quadruple extortion attacks build on the double-extortion model by introducing additional layers of coercion. In triple extortion, attackers may contact customers, partners, or regulators to increase pressure on the victim. Quadruple extortion can involve distributed denial-of-service (DDoS) attacks or other disruptive actions alongside data theft and encryption.

These tactics aim to increase leverage and force payment by raising the consequences of noncompliance. Organizations must prepare for multiple simultaneous attack vectors. Incident response and communication strategies are critical to reducing the impact of such attacks.

Ransomware-as-a-Service

Ransomware-as-a-service (RaaS) is a business model in which ransomware developers lease their tools to other cybercriminals for a share of the profits. This lowers the technical barrier for launching attacks, enabling less-skilled actors to participate in ransomware campaigns. RaaS operators provide infrastructure, support, and updates in exchange for a percentage of each ransom.

The spread of RaaS has led to a surge in ransomware attacks across sectors. Attack kits are sold on the dark web, and affiliate programs attract a range of participants. This model allows attackers to scale operations and increases the diversity of attacks.

How Ransomware Affects Different Industries

Ransomware attackers often directly target specific types of companies based on the perceived value of their data and their sensitivity to operational disruption.

Ransomware in Healthcare

Healthcare organizations are frequent ransomware targets because they handle sensitive patient data and depend on connected systems for daily operations. Attacks can disrupt care delivery, expose protected information, and create pressure to restore systems quickly. Increased patient volume and more connected medical devices have also expanded the attack surface.

Impact:

  • Patient records can be encrypted or stolen, creating privacy and compliance risks.
  • Connected medical devices and healthcare networks increase entry points for attackers.
  • High operational pressure can make downtime especially damaging.
  • Encryption, device security, and stronger access controls help reduce risk.

Ransomware in Manufacturing

Manufacturing is vulnerable because production environments depend on continuous system availability. A ransomware attack can interrupt operations, delay orders, and create expensive downtime. Network segmentation is especially important because it can help isolate infected systems before ransomware spreads across plants or production networks.

Impact:

  • Downtime can stop production lines and disrupt supply chains.
  • Legacy systems may be harder to patch or secure.
  • Segmentation can help quarantine affected parts of the network.
  • Offline backups help restore critical systems without paying attackers.

Ransomware in Financial Services

Financial services companies are attractive targets because they store large amounts of customer and transaction data. Ransomware can lead to data loss, service disruption, regulatory exposure, and direct financial damage. Mobile banking also creates risk through fake apps and login overlays that steal credentials.

Impact:

  • Customer data makes financial institutions high-value targets.
  • Ransom demands may be tied to stolen data or locked systems.
  • Mobile banking scams can steal credentials through fake login pages.
  • Trusted app sources, security patches, and stronger data protection reduce exposure.

Ransomware in Government and Public Sector

Government agencies face ransomware risk because they provide critical public services and often manage large stores of sensitive information. Attacks can lock systems, delay services, and create major recovery costs. Training is a key weakness when employees are not prepared to recognize ransomware attempts.

Impact:

  • Locked systems can disrupt public services and internal operations.
  • Recovery can be expensive and difficult without tested response plans.
  • Employee training helps prevent phishing-driven ransomware infections.
  • Incident response planning helps agencies contain attacks and restore services faster.

12 Tell-Tale Signs of a Ransomware Attack

Ransomware attacks often show warning signs before, during, or immediately after encryption begins. Recognizing these indicators early can help organizations and individuals respond quickly and isolate affected systems. While not every ransomware incident follows the same pattern, the following signs are common.

  1. Unusual file encryption: Files suddenly become inaccessible, display unfamiliar extensions, or generate errors when opened.
  2. Appearance of a ransom note: A message appears on the screen, desktop, or in affected folders demanding payment in exchange for a decryption key.
  3. Unexpected system slowdowns: Devices may become unusually slow as ransomware encrypts large numbers of files and consumes system resources.
  4. Disabled security tools: Antivirus software, endpoint protection tools, backups, or system recovery features may be disabled or modified.
  5. Suspicious network activity: Large amounts of data may be transferred to external servers before encryption occurs.
  6. Unauthorized account activity: New administrator accounts, unusual login attempts, or unexpected privilege changes can indicate unauthorized access.
  7. Missing or deleted backups: Attackers often target backup systems before launching ransomware.
  8. Locked systems or applications: Users may suddenly lose access to computers, servers, databases, or business applications.
  9. Unusual pop-ups or error messages: Frequent system warnings, failed application launches, or unexpected error messages can signal malicious activity.
  10. Mass file modifications: A large number of files are renamed, modified, or created within a short period.
  11. Unexpected shutdowns or reboots: Systems may restart unexpectedly as attackers deploy ransomware or execute malicious scripts.
  12. Reports from multiple users: Multiple employees or users reporting inaccessible files or locked devices at the same time can indicate a ransomware attack spreading across the network.

12 Recent Ransomware Attack Examples

Recent ransomware attacks show how cybercriminals target organizations across healthcare, retail, finance, manufacturing, and supply chain environments. These examples show how ransomware can disrupt operations, expose sensitive data, and create financial and reputational consequences.

1. DXS International

In December 2025, a technology provider serving NHS England, DXS International, reported a ransomware attack affecting its office servers. Because the company supports healthcare services, the incident shows how attackers can target smaller technology suppliers connected to critical health systems, not only hospitals themselves.

2. Asahi Group Holdings

In September 2025, Asahi Group Holdings was hit by a ransomware attack claimed by the Qilin group. The incident disrupted production and shipments in Japan, showing how ransomware can affect physical operations when manufacturing, logistics, and enterprise systems are closely connected.

6. Marquis Software Solutions

In August 2025, Marquis suffered a ransomware attack after attackers compromised a SonicWall firewall. The company later disclosed that data belonging to 672,075 people was stolen, including names, dates of birth, addresses, Social Security numbers, taxpayer IDs, and financial account information. The incident disrupted operations at 74 banks and led to lawsuits and reputational damage.

3. United Natural Foods

In June 2025, United Natural Foods detected unauthorized activity on its internal networks and took systems offline. The disruption affected order fulfillment and was expected to reduce fiscal 2025 net sales by about $350 million to $400 million. Because the company supplies major grocery retailers, including Whole Foods, the incident also showed how ransomware can create downstream supply chain problems.

4. Kettering Health

In May 2025, Kettering Health confirmed that the Interlock ransomware group breached its network and stole data. The attack affected 14 medical centers and more than 120 outpatient facilities, forcing staff to use pen and paper when computerized charting was unavailable. Elective procedures were canceled, call centers were disrupted, and the attackers claimed to have stolen 941 GB of files.

5. Marks & Spencer

In April 2025, Marks & Spencer suffered a major cyberattack linked in reports to Scattered Spider and DragonForce ransomware. Online orders were paused, some store services were affected, and the incident wiped more than £500 million from the company’s market value within a week. The attack showed how ransomware can damage retail sales, customer service, and investor confidence at the same time.

7. Change Healthcare

In 2024, Change Healthcare was hit by a ransomware attack that disrupted claims processing, payments, and pharmacy operations across the United States. The attack showed how one healthcare technology provider can create nationwide disruption when it sits between providers, insurers, pharmacies, and patients.

8. CDK Global

In 2024, CDK Global suffered a ransomware incident that disrupted software used by thousands of car dealerships. Many dealerships had to process sales, financing, repairs, and customer records manually, showing how ransomware can affect business operations even when the victim is a software vendor rather than the end customer.

9. MGM Resorts

In 2023, MGM Resorts experienced a ransomware-related cyberattack that disrupted hotel check-ins, slot machines, digital room keys, payment systems, and internal operations. The incident showed how attacks on identity and access systems can quickly spread into customer-facing services.

10. Royal Mail

In 2023, Royal Mail was hit by a ransomware attack that disrupted international shipping services. The attack affected the ability to process overseas parcels and letters, showing how ransomware can interrupt logistics networks and delay services beyond the victim organization.

11. Costa Rica Government

In 2022, Costa Rica faced ransomware attacks against government systems, including finance and public administration services. The disruption became severe enough that the country declared a national emergency, showing how ransomware can affect public services at a national scale.

12. Colonial Pipeline

In 2021, Colonial Pipeline shut down pipeline operations after a ransomware attack affected business systems. The shutdown caused fuel supply disruption across parts of the eastern United States, showing how ransomware in IT environments can still force decisions that affect critical infrastructure.

How to Prevent Ransomware Attacks

1. Use Application Control to Stop Unknown and Untrusted Code

Application control helps prevent ransomware from executing by allowing only approved applications, scripts, and binaries to run on endpoints and servers. Instead of relying only on signature-based detection, application control uses allowlists to block unauthorized software, including newly developed ransomware that may not yet be recognized by security tools.

A key benefit of application control is that it can monitor and block scripts, malicious macros, and legitimate administrative tools to execute code and move throughout a network. Attackers frequently abuse tools such as PowerShell, Windows Management Instrumentation (WMI), PsExec, and command-line utilities because they are already present on most systems.

By restricting execution to trusted applications and verified publishers, organizations reduce the likelihood that malicious code delivered through phishing emails, compromised websites, or infected downloads will run.

2. Maintain Offline, Immutable, and Tested Backups

Regular backups provide a way to restore systems without paying a ransom. However, backups must be protected from attackers who often attempt to locate and encrypt backup repositories during an attack. Offline and immutable backups help ensure that recovery data remains available even if production systems are compromised.

Organizations should follow a backup strategy that includes multiple copies of critical data stored in separate locations. Backup recovery procedures should be tested regularly to verify that data can be restored quickly and completely.

3. Enforce Multi-Factor Authentication

Multi-factor authentication (MFA) adds a layer of security by requiring users to provide more than one form of verification before gaining access to systems or applications. Even if attackers obtain valid usernames and passwords through phishing, credential theft, or password reuse, MFA makes unauthorized access more difficult.

MFA should be enforced for remote access services, privileged accounts, cloud applications, email platforms, and administrative interfaces. Strong authentication controls help prevent many ransomware attacks that begin with compromised credentials.

4. Limit Privileged Access

Excessive privileges increase the damage attackers can cause after gaining access to a network. Users should be granted only the permissions necessary to perform their job functions, following the principle of least privilege. Restricting administrative rights reduces the ability of ransomware to spread, disable security controls, or access sensitive systems.

Organizations should regularly review user accounts, remove unnecessary privileges, and separate administrative accounts from standard user accounts. Privileged access management solutions can further strengthen security by controlling, monitoring, and auditing the use of elevated permissions across the environment.

5. Segment the Network

Network segmentation limits the ability of attackers and ransomware to move laterally across an environment. By dividing networks into smaller, isolated segments, organizations can contain infections and prevent a compromise in one area from affecting systems elsewhere.

Segmentation is especially important for protecting high-value assets such as domain controllers, backup systems, databases, industrial control systems, and business applications. Firewalls, access control lists, and zero-trust network principles can help enforce segmentation and reduce the potential impact of a ransomware incident.

How to Prevent Ransomware Attacks with Airlock Digital

Most ransomware succeeds because it is allowed to execute in the first place. Airlock Digital takes a proactive, prevention-first approach that stops malicious software before it can run. By enforcing a Deny by Default security model, Airlock Digital ensures that only trusted applications, scripts, and processes are permitted to execute, significantly reducing the attack surface and mitigating the risk of ransomware and other file-based threats across both IT and OT environments.

Key capabilities of Airlock Digital:

  • Deny by Default model: Automatically blocks all untrusted and unauthorized applications, ensuring that only approved software is allowed to execute on your endpoints.
  • Granular application control: Define trusted applications and processes at the file, path, publisher, or process level for precise control over what runs in your environment.
  • Integrated file-level intelligence: Leverage industry-leading VirusTotal intelligence to understand the context and history of unknown files before making trust decisions.
  • Precision blocklisting: Block specific files using a range of launch conditions, including path, product name, publisher, version, user, command line, and operating system.
  • Offline mode protection: Secure endpoints even in air-gapped and other non-internet-connected environments, ensuring continuous protection against threats.

Take control of your endpoint security with Airlock Digital's prevention-focused approach to ransomware defense. Learn how Airlock Digital prevents malware and ransomware.