Resources > Security Terms Glossary > What is Ransomware

What is Ransomware?

What is ransomware?

Ransomware is a type of malicious software, or malware, that steals data, encrypts it, and holds it for ransom, usually demanded in cryptocurrency. Ransomware attacks most often deny victims access to their data unless the ransom is paid and there is typically a timeframe in which to pay it before the data is gone forever. Payment for a decryption key can cost anywhere from hundreds of dollars to hundreds of thousands, or even millions, in rare cases.

In the past, ransomware attacks that locked down a user’s computer or files could be easily reversed by a trained professional. But in recent years, ransomware attacks have become more sophisticated and, in many cases, have left the victims with little choice but to pay the ransom or lose their data forever. 

A recent and notable change in many ransomware family variants is the addition of a data exfiltration feature. This new feature allows cybercriminals to exfiltrate sensitive data from victim organizations before encrypting the data. This exfiltrated data is like an insurance policy for attackers: even if the victims have good backups, they’ll likely pay the ransom to avoid having their data exposed.

In a July 2020 attack, a ransomware gang was able to infiltrate the network of a large U.S. company, perform surveillance, move around the network, and unleash their ransomware payload onto 30,000 computers. Before encrypting those 30,000 systems, they exfiltrated more than 2 terabytes of sensitive information and threatened to publish it online. Ultimately, the company paid $4.5 million. It was an unusually large payout, but the tactics used in the attack are increasingly common.

The history of ransomware and an increase in attacks

Though cybercriminals have been using ransomware attacks for more than 30 years, there has been a significant uptick in recent years. According to the FBI, ransomware attacks started picking up in 2012, and show no sign of slowing. 

A 2020 ThreatLabZ report showed an increase of more than 500 percent in ransomware delivered in encrypted channels between March and September. It is estimated that during the year 2020 alone, ransomware will have inflicted damages of more than $20 billion worldwide.

The most common targets for ransomware attacks in recent years have been municipal governments and academic institutions, but since the start of the COVID-19 pandemic, hospitals and remote workers have become a new focus for ransomware gangs. Furthermore, in the last year, reports of ransomware delivered through encrypted traffic have increased significantly. Due to the capacity limitations of legacy security technologies, such as next-generation firewalls, most organizations do not have the ability to inspect all encrypted traffic. Attackers know this, so they are increasingly using encryption to hide their malicious links and attachments.

The best way to avoid being exposed to ransomware—or any type of malware—is to be a cautious and conscientious computer user. Malware distributors have gotten increasingly savvy, and you need to be careful about what you download and click on.

U.S. Federal Bureau of Investigation (FBI)

How ransomware works

Ransomware is most commonly spread by phishing emails and ads with infected links or a planted website embedded with malware. Phishing emails often appear as though they have been sent from a legitimate organization or someone known to the victim (in targeted attacks),  tricking the user into clicking on a malicious link or opening a malicious attachment. 

In ransomware attacks on an individual, documents, photos, and financial information are most commonly locked and held hostage. While individuals might be an easier target, corporations—especially larger organizations—are far more attractive. If attackers can get just one employee to download the malware, it can then spread from that user’s device onto the network, where the stakes are much higher. Not only can an attack disrupt business, but the threat of data loss or exposure could be devastating and costly in dollars and in company reputation.

While some organizations are investing in cybersecurity insurance to help cover costs in the event of a cyberattack or data breach, the best course of action when it comes to ransomware is prevention. 

To protect your organization from ransomware, CISA, the Cybersecurity & Infrastructure Security Agency and the FBI recommend the following:

  • Back up computers, so you can restore your system to its previous state using your backups.  
  • Store backups separately, such as on an external hard drive or in the cloud, so they cannot be accessed from a network.
  • Update and patch computers, so that vulnerable applications and operating systems don’t become targets.
  • Train employees with ongoing, mandatory cybersecurity awareness sessions to ensure they are aware of current threats and security best practices. Be sure they are cautious with email—even from senders they know, verifying the sender’s legitimacy before opening any attachments or clicking links.
  • Create a continuity plan in case your organization becomes the victim of a ransomware attack.

Ransomware can be devastating to an individual or an organization. Anyone with important data stored on their computer or network is at risk, including government or law enforcement agencies and healthcare systems or other critical infrastructure entities.

U.S. Cybersecurity & Infrastructure Security Agency

Ransomware is less about technological sophistication and more about exploitation of the human element. Simply, it is a digital spin on a centuries-old criminal tactic.

Institute for Critical Infrastructure Technology

Preventing ransomware attacks

Modern ransomware defense technology is not only highly effective but also easy to deploy. Sufficient ransomware prevention begins with adopting a security posture that’s natively built in the cloud to protect users, applications, and sensitive data from these attacks, regardless of where users connect or what devices they’re using.

To keep up with today’s most common ransomware threats, a prevention strategy must incorporate the following principles and tools to prevent these attacks from exposing your data, disrupting your business, or costing your organization time and money:

  • Use an AI-driven sandbox quarantine to hold and inspect suspicious content before allowing it to pass through to the recipient
  • Inspect all SSL/TLS-encrypted traffic to ensure there are no hidden threats
  • Implement always-on protection for users on and off the network 

No company, large or small, is safe from ransomware without a dedicated security defense. Avoid becoming the next victim of ransomware, or the next organization in the news as a result of an attack. Learn more about Zscaler Advanced Cloud Sandbox and Ransomware Prevention.

Ransomware is everywhere. Stay informed to learn how to protect your company

Read the blogs
security research blogs

ThreatLabZ Research: 2020 State of Encrypted Attacks

Read the report
ThreatLabZ Research: 2020 State of Encrypted Attacks

As ransomware becomes more sophisticated, you’ll need to bolster your defenses.

Discover ransomware protection
Zscaler Ransomware Protection