← Glossary

Ransomware

Ransomware encrypts your data (and increasingly steals it first) to extort payment. Most attacks start with a phishing email or a stolen credential, days before encryption.

Updated

Ransomware is malware that encrypts an organization''s data (and increasingly steals it first) to extort a payment for restoring access and withholding a leak. It is among the most disruptive cyberattacks, but its defining lesson is that the encryption is the last step: the attack almost always begins somewhere cheaper to stop, usually a phishing email or a stolen credential.

Key facts

  • Most ransomware intrusions begin with phishing, stolen credentials or exploited vulnerabilities, days or weeks before any file is encrypted.
  • Double extortion is now standard: data is stolen before encryption, so backups alone do not remove the leak threat.
  • The ransomware-as-a-service model industrialized it, letting non-experts run attacks.

The attack chain

Initial access (phishing, stolen credentials, unpatched systems), then reconnaissance and lateral movement, privilege escalation, data theft, and finally encryption and the ransom demand. The long middle is the point: defenders have many days to detect and disrupt before encryption, and the earliest, cheapest interception is at initial access, overwhelmingly email. See also zero-day attacks and account takeover for the two other main entry routes.

How to defend

Prioritize the entry points: email security against the phishing that starts most chains, phishing-resistant MFA so stolen credentials are not enough, and fast patching. Then limit blast radius: network segmentation, least privilege, and monitoring for the lateral movement and account-takeover behavior that precede encryption. Finally, resilience: offline, tested backups and a rehearsed incident plan, because the worst case must be survivable without paying.

How Sentaro helps

Sentaro guards the most common front door: the phishing and credential-theft emails that begin most ransomware intrusions, and the account-takeover behavior that follows. Stopping the initial-access email is the cheapest possible place to break the chain, weeks before encryption would occur.

Questions we get asked.

What is ransomware in simple terms?

Malware that locks your data by encrypting it, and often steals a copy first, then demands payment to restore access and not leak the stolen data.

How does ransomware get in?

Most commonly through phishing emails, stolen or reused credentials, and unpatched internet-facing systems. The encryption happens later, after the attacker has moved through the network.

Should we pay the ransom?

Law enforcement generally advises against it: payment funds the ecosystem, guarantees nothing, and may raise legal issues. Tested backups and an incident plan are the reliable alternative.

What is double extortion?

Stealing data before encrypting it, so attackers can threaten to leak it even if you restore from backups, adding pressure to pay.

How do we prevent ransomware?

Stop the entry points first: email security, phishing-resistant MFA and patching, then segmentation, least privilege, monitoring, and tested offline backups for resilience.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.