Ransomware was involved in 48% of all the data breaches Verizon analyzed for its 2026 report, up from 44% the year before. That makes it the most common way an attack ends, and for many organizations the most disruptive thing that will ever happen to them. Yet most people still picture it as a computer virus you catch by clicking the wrong link.
That picture is mostly wrong, and the gap between the picture and reality is what makes ransomware hard to defend against. This guide explains what ransomware actually is, how an attack unfolds from the first break-in to the ransom note, why backups alone no longer solve the problem, what to do in the first hours if you are hit, and which defenses matter most. No technical background required.
2. Why it is everywhere
3. The assumption that leaves people exposed
4. Anatomy of an attack
5. Double extortion: why backups are not enough
6. What to do if you are hit
7. Should you pay?
8. What actually reduces your risk
9. Frequently asked questions
1. What ransomware actually is
Ransomware is malicious software that locks you out of your own files or systems and demands payment to give them back. The US Cybersecurity and Infrastructure Security Agency (CISA) describes it as malware designed to encrypt files on a device, leaving those files and the systems that depend on them unusable until the attackers are paid for the decryption key.
Encryption is the same technology that protects your online banking. In ransomware it is turned against you: the attacker scrambles your data with a key only they hold. Without that key the data is effectively unreadable, no matter how powerful your computers are. The ransom note, usually a text file or a message on the screen, tells you how much to pay, how, and by when.
What has changed is who gets hit and how often. Early ransomware targeted individuals and demanded a few hundred dollars. Today the focus is on organizations: hospitals, schools, manufacturers, law firms, city governments, small businesses. They have the most to lose from downtime and the most data worth stealing. The rest of this guide is mostly about that kind of attack, because the same lessons protect a home user too.
2. Why it is everywhere
Ransomware keeps growing because it has become a business, not a hacking hobby. Blockchain analysis cited in industry reporting put ransomware revenue at roughly $529 million in the first quarter of 2026 alone, up about 39% from a year earlier. That kind of money supports specialization.
Instead of one skilled attacker doing everything, the work is split among specialists. Initial access brokers break into networks and sell that access, typically for somewhere between $500 and $5,000 depending on the victim. Ransomware-as-a-service operators build and maintain the malware and rent it out. The renters, called affiliates, run the attacks and usually keep 70 to 90 percent of whatever the victim pays. A person with limited technical skill can now rent almost every tool they need.
3. The assumption that leaves people exposed
The common belief is that ransomware is something you catch: one person opens a bad attachment, the files lock, and the damage happens right then. If that were true, the defense would be simple. Train people not to click, run antivirus, and you are done.
Encryption is not the attack. It is the final step of an attack that started earlier. By the time your screen shows the ransom note, the attackers have usually already been inside, looking around, for a while.
This matters because it changes where you should look. CISA notes that a ransomware incident can be a sign of an earlier, unresolved compromise, and that malware used to get a foothold often arrives before the ransomware does. The note on the screen is not the beginning of the story. It is the moment the attackers decided you should find out.
It also explains why the entry point is rarely a careless click. In the 2026 Verizon data, exploiting a vulnerability, usually in a system facing the internet, became the most common way breaches begin, at 31%. Stolen credentials followed at 13%. CISA lists the same families of entry points: exposed services and unpatched software, compromised credentials, phishing, earlier malware infections, and weak security at a third-party vendor. Most of these have nothing to do with whether an employee is paying attention.
4. Anatomy of an attack
Attacks vary, but most modern ransomware intrusions follow the same sequence. Seeing it laid out is the quickest way to understand where defenses can interrupt it.
Getting in. The attackers need one foothold. That might be an unpatched VPN or remote access system, a password bought from an access broker, or a phishing email. Any one of these is enough. The technique matters less than the fact that it works once.
Gaining control and moving around. A basic foothold usually has limited rights. The attackers then look for ways to obtain administrator-level access, often by harvesting stored passwords or abusing legitimate tools already on the network. CISA points out that attackers frequently use tools that normally belong to administrators, which makes their activity blend in. They then explore: which servers matter, where the sensitive data lives, where the backups are kept.
Stealing and preparing. Before encrypting anything, many groups copy sensitive files out of the network. They also go after backups, because working backups are the one thing that lets a victim refuse to pay. Only after this preparation do they run the encryption, typically across many systems at once and often at a moment chosen to cause maximum disruption, such as a weekend or a holiday.
One well-known example is the 2021 attack on Colonial Pipeline, which carried fuel across the eastern United States. The attackers, a group called DarkSide, got in through a compromised account for a remote access system that was not protected by multi-factor authentication. The company shut down pipeline operations as a precaution and paid about $4.4 million in bitcoin; US authorities later announced they had recovered a portion of it. One weak entry point, in a system that did not need to be that exposed, led to a national fuel disruption.
5. Double extortion: why backups are not enough
For years the standard advice was simple: keep good backups, and if ransomware hits, restore and move on. That advice was right, and it worked well enough that many victims stopped paying. Attackers responded by changing the threat.
In a double extortion attack, the criminals steal your data first, then encrypt your systems. Now they hold two threats. Pay, or stay locked out. Pay, or we publish your customer records, employee files, or contracts on a leak site. Restoring from backup solves the first problem and does nothing about the second.
Why this changes the mathA backup protects your ability to operate. It does not protect your data from being exposed. Those are two different risks, and modern attacks target both.
This shows up in the payment numbers. According to the Q2 2026 report from the ransomware negotiation firm Coveware, the share of victims who paid fell to a record low. For attacks where criminals only stole data without encrypting, just 15% of victims paid. When all you are buying is a promise to delete stolen files, there is no way to check that the promise is kept, and there is evidence it often is not. After a law enforcement takedown of one of the largest ransomware groups in 2024, investigators found that the group had kept victim data it had promised to delete.
6. What to do if you are hit
If you see a ransom note or suddenly cannot open files, the first hour matters. The steps below follow guidance from CISA. If you are part of an organization, your incident response plan and your security or IT team come first, and the steps here are what they will be doing.
Isolate the affected systems immediately. Disconnect them from the network to stop the spread. If many systems are affected, CISA advises taking the network segment offline at the switch level. Pull the network cable or disable Wi-Fi on an individual device.
Do not power machines off unless you cannot disconnect them. It feels natural to switch off an infected computer, but doing so erases information held in memory that investigators may need. Disconnect first, and shut down only if there is no other way to contain it.
Communicate through a channel the attackers cannot see. If they are inside your email or chat systems, they may be reading your response plans. Use phone calls or another out-of-band method to coordinate.
Preserve evidence and find the way in. Keep logs, take snapshots of cloud systems, and record what you see. Closing the original entry point is part of recovery. If you restore systems without fixing the weakness, the attackers can simply return.
Report it. In the US, CISA, the FBI, and the Internet Crime Complaint Center accept ransomware reports. Many countries have equivalent bodies, and some jurisdictions now require organizations to report incidents or ransom payments.
Recover from clean, offline backups, and rebuild carefully. Restore the most important systems first and avoid reintroducing the attackers. Reset passwords, especially for administrator accounts, since the attackers may have captured them. Our guide to what actually happens during a security incident walks through how this process looks from the inside.
For individuals, the same logic applies in a smaller form: disconnect the device from the internet, do not pay in a panic, and check whether a free decryption tool exists for the specific strain. The No More Ransom project, a collaboration between Europol and security companies, offers free decryptors for some ransomware families. It does not cover everything, but it is worth checking before anything else.
7. Should you pay?
Law enforcement agencies generally advise against paying, and the data suggests most victims follow that advice: the Verizon report found that 69% of ransomware victims did not pay. The reasons are practical as well as ethical. Payment does not guarantee you get a working decryption key. It does not verify that stolen data is deleted. And it can mark you as willing to pay: in one industry survey of 1,100 security leaders, 83% of organizations that paid a ransom were attacked again.
There are also legal considerations. In the United States, sanctions rules can make a payment illegal if the group is on a sanctions list, even if the victim did not know who they were dealing with. Some countries, including Australia, require certain businesses to report ransom payments within a short deadline. Anyone facing this decision should involve legal counsel and experienced incident responders early.
The most useful point is a timing one. Whether you can afford to say no is decided long before an attack. An organization with tested backups, clear authority, and a rehearsed plan has a real choice. One without them often does not.
8. What actually reduces your risk
No single control stops ransomware, but a short list of basics blocks most of the common routes. They are not glamorous, and they are the ones most often skipped.
Patch internet-facing systems quickly. Since exploited vulnerabilities are now the top way breaches begin, this is the highest-value habit. The same report found that only 26% of critical known-exploited vulnerabilities were fully fixed, and the median time to full remediation was 43 days. Attackers move faster than that.
Protect remote access with strong multi-factor authentication. Remote desktop and VPN systems should not be exposed carelessly, and every login to them should require more than a password. CISA recommends phishing-resistant multi-factor authentication where possible. Our guide on how passwords actually get stolen explains why a password alone is a weak lock.
Keep backups that an attacker cannot reach, and test them. Backups stored where the main network can reach them can be deleted along with everything else. Keep at least one copy offline or otherwise isolated, and practice restoring from it. A backup you have never tested is a hope, not a plan.
Limit how far an intruder can travel. Segmenting the network and giving accounts only the access they need means a single compromised login does not open every door. A firewall is one piece of that, but segmentation and least privilege do more of the work once someone is inside.
Manage vendor and contractor access. Third parties are part of your attack surface, appearing in 48% of breaches in the Verizon data. Give outside parties the narrowest access that works and remove it when the job ends.
Prepare the people side. Phishing and impersonation still start many intrusions, and attackers are skilled at creating urgency. Our article on social engineering covers the habits that help, above all verifying unexpected requests through a separate channel.
Finally, write the incident plan before you need it. Decide who has authority to make decisions, who to call, and how to communicate if email is compromised. Under pressure, people follow the plan they have rehearsed, not the one they intended to write.
9. Frequently asked questions
What is ransomware in simple terms?
Ransomware is malware that locks your files or systems with encryption and demands payment for the key to unlock them. Many attackers also steal your data and threaten to publish it, which is why it is often called double extortion.
How does ransomware spread?
The most common entry points are unpatched internet-facing systems, stolen or weak credentials, phishing emails, earlier malware infections, and weak security at a third-party vendor. Once inside, attackers move through the network before encrypting anything.
Can you recover from ransomware without paying?
Often, yes. Clean, offline backups are the most reliable route, and free decryption tools exist for some ransomware families through projects such as No More Ransom. Recovery can still take days or weeks, and backups do not protect against stolen data being leaked.
Does antivirus software stop ransomware?
It helps, but it is not enough alone. Many attacks use legitimate administrator tools and stolen logins that look like normal activity. Patching, strong multi-factor authentication, segmented networks, and tested backups do more to limit the damage.
What should I do first if I see a ransom note?
Disconnect the affected device or network segment from the internet, avoid powering it off if you can, and notify your IT or security team. Preserve evidence, communicate through a channel the attackers cannot see, and report the incident to the relevant authorities.
Security, Decoded.
If this changed how you think about ransomware, you’ll like the newsletter. One security idea, decoded clearly, every week, free.
Subscribe to SKB Decoded →→ What Actually Happens During a Security Incident?
→ What Is Social Engineering? (And Why Smart People Fall For It)





