Ransomware attacks are malicious cyber operations where criminals infect a victim's network with malware to encrypt critical files or steal sensitive data. Attackers then demand a ransom, typically paid in cryptocurrency, to restore access or prevent the leaked publication of the stolen data. In a typical ransomware attack, a ransom note appears on the victim’s screen, threatening permanent data loss or public exposure unless the payment is made within a specific timeframe.
Ransomware attacks can target individuals, businesses, hospitals, schools, and government agencies, making them a widespread threat. Ransomware spreads through phishing emails, malicious attachments, infected websites, or exploiting vulnerabilities in software and remote access protocols. The attacker’s goal is to maximize disruption, pressure the victim into paying, and avoid detection for as long as possible.
How ransomware attacks work:
Modern attack methods include:
In this article:
Ransomware attacks can have consequences that go far beyond temporary data loss. They can disrupt daily operations, create financial strain, damage reputations, and expose sensitive information. The impact varies depending on the victim, but the risks are significant for both individuals and organizations.
Ransomware is a subset of malware, but not all malware is ransomware. Malware is a broad term that includes any software intended to cause harm or exploit devices, networks, or users. Types of malware include viruses, worms, trojans, spyware, adware, and others. Each variant has different objectives, such as stealing data, disrupting operations, or spying on users.
Ransomware’s distinct characteristic is its focus on extortion, encrypting data or locking systems to demand payment. While other malware might silently steal information or create backdoors for future exploitation, ransomware’s impact is immediate and visible. Understanding this distinction helps organizations implement targeted defenses and response strategies.
While there are many ransomware strains and the field is rapidly evolving, most ransomware attacks follow these general stages.
Attackers use various entry points to gain initial access to a target system. Common methods include phishing emails with malicious attachments or links, exploiting unpatched software vulnerabilities, or brute-forcing weak remote desktop protocol (RDP) passwords. These methods rely on human error or technical weaknesses to bypass security controls.
Once inside, attackers often deploy additional tools to maintain their presence. They may install backdoors, disable security software, or use legitimate system utilities to avoid detection. This phase sets the stage for further actions, such as privilege escalation and lateral movement within the network.
After gaining a foothold, attackers seek higher privileges to access sensitive data or systems. They may exploit misconfigurations, harvest credentials, or use privilege escalation vulnerabilities. The goal is to move from a low-level user account to an account with administrative or domain-wide access.
Lateral movement involves spreading across the network to compromise more systems and locate valuable data. Attackers use legitimate tools, such as PowerShell or PsExec, to avoid triggering security alerts. By moving laterally, they increase the impact of the ransomware deployment, affecting as many systems as possible when the attack is executed.
Modern ransomware attacks often involve data theft before encryption. Attackers exfiltrate sensitive files, such as customer records, financial documents, or intellectual property, to use as leverage for double extortion. Once data is stolen, the ransomware is triggered to encrypt files across compromised systems, rendering them inaccessible to users.
Encryption is performed using strong cryptographic algorithms, making decryption without the attacker’s key nearly impossible. Victims are presented with a ransom note demanding payment in exchange for the decryption key. The combination of data theft and encryption increases pressure on victims, as attackers can threaten to leak stolen data if the ransom is not paid.
After encrypting data and systems, attackers present a ransom demand, typically via a note displayed on infected devices. The note includes instructions for payment, often in cryptocurrency, and a deadline for compliance. Attackers may provide a sample decryption to prove they can restore access.
In recent attacks, criminals also threaten to publish stolen data or notify regulators if the ransom is not paid. Some groups run “help desks” to negotiate payments or answer questions. Regardless of whether payment is made, there is no guarantee that access will be restored or that stolen data will not be misused or sold.
The following table summarizes the main ransomware types. We explore each of these types in more detail below.
| Comparison Factor | Crypto Ransomware | Locker Ransomware | Double-Extortion Ransomware | Triple/Quadruple Extortion |
|---|---|---|---|---|
| Primary Attack Method | Encrypts files and demands payment for a decryption key | Locks users out of devices or operating systems | Encrypts files and steals sensitive data before encryption | Combines encryption and data theft with additional pressure tactics such as contacting stakeholders or launching DDoS attacks |
| Characteristics | Uses encryption to deny access to files | Blocks access to devices rather than encrypting files | Combines data theft with encryption to increase leverage | Applies multiple forms of coercion beyond encryption and data theft |
| Impact on Victim | Data becomes inaccessible and may be unrecoverable without backups | Users cannot access devices or applications, but data may remain intact | Causes operational disruption and creates risk of data exposure | Creates operational, legal, reputational, and service availability risks simultaneously |
| Examples | WannaCry, CryptoLocker, Ryuk | Reveton, WinLock | Maze, REvil | Variants using DDoS attacks and direct outreach to customers, partners, or regulators |
Crypto ransomware, also known as encrypting ransomware, is the most common form of ransomware attack. It encrypts the victim’s files using strong cryptographic algorithms, making them inaccessible without a decryption key. Victims are then presented with a ransom demand, typically with instructions for payment and a threat that the decryption key will be destroyed if the deadline is not met.
The impact of crypto ransomware is severe because data recovery without backups or the attacker’s key is nearly impossible. Well-known variants include WannaCry, CryptoLocker, and Ryuk. Organizations and individuals face operational disruptions and potential data loss, underscoring the importance of preventive security measures and regular backups.
Locker ransomware differs from crypto ransomware by locking users out of their devices rather than encrypting individual files. The operating system or applications are rendered inaccessible, and a ransom message is displayed on the locked screen. Victims are unable to use their computers or mobile devices until the ransom is paid and access is sometimes restored.
Locker ransomware is often less destructive than crypto ransomware since data may remain intact and accessible once the lock is removed. However, it can still cause disruption, especially if critical endpoints are affected. Early locker ransomware targeted consumers, but more advanced variants now target businesses and organizations.
Double-extortion ransomware adds pressure by encrypting data and exfiltrating sensitive information before encryption. Attackers threaten to release or sell the stolen data if the ransom is not paid.
This approach puts organizations at risk of regulatory fines, reputational harm, and legal consequences if sensitive customer or employee data is exposed. Notable ransomware groups, such as Maze and REvil, have used double-extortion tactics. The dual threat of data loss and public exposure increases the impact of these attacks.
Triple or quadruple extortion attacks build on the double-extortion model by introducing additional layers of coercion. In triple extortion, attackers may contact customers, partners, or regulators to increase pressure on the victim. Quadruple extortion can involve distributed denial-of-service (DDoS) attacks or other disruptive actions alongside data theft and encryption.
These tactics aim to increase leverage and force payment by raising the consequences of noncompliance. Organizations must prepare for multiple simultaneous attack vectors. Incident response and communication strategies are critical to reducing the impact of such attacks.
Ransomware-as-a-service (RaaS) is a business model in which ransomware developers lease their tools to other cybercriminals for a share of the profits. This lowers the technical barrier for launching attacks, enabling less-skilled actors to participate in ransomware campaigns. RaaS operators provide infrastructure, support, and updates in exchange for a percentage of each ransom.
The spread of RaaS has led to a surge in ransomware attacks across sectors. Attack kits are sold on the dark web, and affiliate programs attract a range of participants. This model allows attackers to scale operations and increases the diversity of attacks.
Ransomware attackers often directly target specific types of companies based on the perceived value of their data and their sensitivity to operational disruption.
Healthcare organizations are frequent ransomware targets because they handle sensitive patient data and depend on connected systems for daily operations. Attacks can disrupt care delivery, expose protected information, and create pressure to restore systems quickly. Increased patient volume and more connected medical devices have also expanded the attack surface.
Impact:
Manufacturing is vulnerable because production environments depend on continuous system availability. A ransomware attack can interrupt operations, delay orders, and create expensive downtime. Network segmentation is especially important because it can help isolate infected systems before ransomware spreads across plants or production networks.
Impact:
Financial services companies are attractive targets because they store large amounts of customer and transaction data. Ransomware can lead to data loss, service disruption, regulatory exposure, and direct financial damage. Mobile banking also creates risk through fake apps and login overlays that steal credentials.
Impact:
Government agencies face ransomware risk because they provide critical public services and often manage large stores of sensitive information. Attacks can lock systems, delay services, and create major recovery costs. Training is a key weakness when employees are not prepared to recognize ransomware attempts.
Impact:
Ransomware attacks often show warning signs before, during, or immediately after encryption begins. Recognizing these indicators early can help organizations and individuals respond quickly and isolate affected systems. While not every ransomware incident follows the same pattern, the following signs are common.
Recent ransomware attacks show how cybercriminals target organizations across healthcare, retail, finance, manufacturing, and supply chain environments. These examples show how ransomware can disrupt operations, expose sensitive data, and create financial and reputational consequences.
1. DXS International
In December 2025, a technology provider serving NHS England, DXS International, reported a ransomware attack affecting its office servers. Because the company supports healthcare services, the incident shows how attackers can target smaller technology suppliers connected to critical health systems, not only hospitals themselves.
2. Asahi Group Holdings
In September 2025, Asahi Group Holdings was hit by a ransomware attack claimed by the Qilin group. The incident disrupted production and shipments in Japan, showing how ransomware can affect physical operations when manufacturing, logistics, and enterprise systems are closely connected.
6. Marquis Software Solutions
In August 2025, Marquis suffered a ransomware attack after attackers compromised a SonicWall firewall. The company later disclosed that data belonging to 672,075 people was stolen, including names, dates of birth, addresses, Social Security numbers, taxpayer IDs, and financial account information. The incident disrupted operations at 74 banks and led to lawsuits and reputational damage.
3. United Natural Foods
In June 2025, United Natural Foods detected unauthorized activity on its internal networks and took systems offline. The disruption affected order fulfillment and was expected to reduce fiscal 2025 net sales by about $350 million to $400 million. Because the company supplies major grocery retailers, including Whole Foods, the incident also showed how ransomware can create downstream supply chain problems.
4. Kettering Health
In May 2025, Kettering Health confirmed that the Interlock ransomware group breached its network and stole data. The attack affected 14 medical centers and more than 120 outpatient facilities, forcing staff to use pen and paper when computerized charting was unavailable. Elective procedures were canceled, call centers were disrupted, and the attackers claimed to have stolen 941 GB of files.
5. Marks & Spencer
In April 2025, Marks & Spencer suffered a major cyberattack linked in reports to Scattered Spider and DragonForce ransomware. Online orders were paused, some store services were affected, and the incident wiped more than £500 million from the company’s market value within a week. The attack showed how ransomware can damage retail sales, customer service, and investor confidence at the same time.
7. Change Healthcare
In 2024, Change Healthcare was hit by a ransomware attack that disrupted claims processing, payments, and pharmacy operations across the United States. The attack showed how one healthcare technology provider can create nationwide disruption when it sits between providers, insurers, pharmacies, and patients.
8. CDK Global
In 2024, CDK Global suffered a ransomware incident that disrupted software used by thousands of car dealerships. Many dealerships had to process sales, financing, repairs, and customer records manually, showing how ransomware can affect business operations even when the victim is a software vendor rather than the end customer.
9. MGM Resorts
In 2023, MGM Resorts experienced a ransomware-related cyberattack that disrupted hotel check-ins, slot machines, digital room keys, payment systems, and internal operations. The incident showed how attacks on identity and access systems can quickly spread into customer-facing services.
10. Royal Mail
In 2023, Royal Mail was hit by a ransomware attack that disrupted international shipping services. The attack affected the ability to process overseas parcels and letters, showing how ransomware can interrupt logistics networks and delay services beyond the victim organization.
11. Costa Rica Government
In 2022, Costa Rica faced ransomware attacks against government systems, including finance and public administration services. The disruption became severe enough that the country declared a national emergency, showing how ransomware can affect public services at a national scale.
12. Colonial Pipeline
In 2021, Colonial Pipeline shut down pipeline operations after a ransomware attack affected business systems. The shutdown caused fuel supply disruption across parts of the eastern United States, showing how ransomware in IT environments can still force decisions that affect critical infrastructure.
Application control helps prevent ransomware from executing by allowing only approved applications, scripts, and binaries to run on endpoints and servers. Instead of relying only on signature-based detection, application control uses allowlists to block unauthorized software, including newly developed ransomware that may not yet be recognized by security tools.
A key benefit of application control is that it can monitor and block scripts, malicious macros, and legitimate administrative tools to execute code and move throughout a network. Attackers frequently abuse tools such as PowerShell, Windows Management Instrumentation (WMI), PsExec, and command-line utilities because they are already present on most systems.
By restricting execution to trusted applications and verified publishers, organizations reduce the likelihood that malicious code delivered through phishing emails, compromised websites, or infected downloads will run.
Regular backups provide a way to restore systems without paying a ransom. However, backups must be protected from attackers who often attempt to locate and encrypt backup repositories during an attack. Offline and immutable backups help ensure that recovery data remains available even if production systems are compromised.
Organizations should follow a backup strategy that includes multiple copies of critical data stored in separate locations. Backup recovery procedures should be tested regularly to verify that data can be restored quickly and completely.
Multi-factor authentication (MFA) adds a layer of security by requiring users to provide more than one form of verification before gaining access to systems or applications. Even if attackers obtain valid usernames and passwords through phishing, credential theft, or password reuse, MFA makes unauthorized access more difficult.
MFA should be enforced for remote access services, privileged accounts, cloud applications, email platforms, and administrative interfaces. Strong authentication controls help prevent many ransomware attacks that begin with compromised credentials.
Excessive privileges increase the damage attackers can cause after gaining access to a network. Users should be granted only the permissions necessary to perform their job functions, following the principle of least privilege. Restricting administrative rights reduces the ability of ransomware to spread, disable security controls, or access sensitive systems.
Organizations should regularly review user accounts, remove unnecessary privileges, and separate administrative accounts from standard user accounts. Privileged access management solutions can further strengthen security by controlling, monitoring, and auditing the use of elevated permissions across the environment.
Network segmentation limits the ability of attackers and ransomware to move laterally across an environment. By dividing networks into smaller, isolated segments, organizations can contain infections and prevent a compromise in one area from affecting systems elsewhere.
Segmentation is especially important for protecting high-value assets such as domain controllers, backup systems, databases, industrial control systems, and business applications. Firewalls, access control lists, and zero-trust network principles can help enforce segmentation and reduce the potential impact of a ransomware incident.
Most ransomware succeeds because it is allowed to execute in the first place. Airlock Digital takes a proactive, prevention-first approach that stops malicious software before it can run. By enforcing a Deny by Default security model, Airlock Digital ensures that only trusted applications, scripts, and processes are permitted to execute, significantly reducing the attack surface and mitigating the risk of ransomware and other file-based threats across both IT and OT environments.
Key capabilities of Airlock Digital:
Take control of your endpoint security with Airlock Digital's prevention-focused approach to ransomware defense. Learn how Airlock Digital prevents malware and ransomware.