Sixwatch logo dark

What Is Ransomware? How It Works, Whether to Pay, and How to Stop It

Table of Contents

What is ransomware? Ransomware is malicious software that encrypts the files on your computers and servers so you can’t use them, then demands a payment, usually in cryptocurrency, for the decryption key. Modern ransomware groups also steal your data before encrypting it and threaten to publish it if you don’t pay, which turns an outage into a data breach. Ransomware is the most disruptive cyberattack a business can face: a successful attack means days to weeks without systems, six- or seven-figure recovery costs, regulatory notifications, and for some companies, closure. It’s also largely preventable, and recoverable without paying, if the right controls were in place beforehand.

what is ransomware attack screen demanding payment

In this guide

How ransomware works

Ransomware uses the same encryption that protects your online banking, turned against you. Once running on a machine, it generates a key, encrypts every file it can reach (documents, databases, images, backups on connected drives), and leaves a ransom note explaining how to pay. Without the key, the files are mathematically unrecoverable. The attacker holds the key and sells it back to you.

The ransom note typically includes a deadline, a payment amount in Bitcoin or Monero, a link to a “support” portal on the dark web, and a threat: pay by the deadline or the price doubles and the stolen data is published.

What has changed since the early days is scale and professionalism. Ransomware groups operate like companies, with developers, affiliates who carry out attacks, negotiators, and customer support. Ransomware-as-a-service (RaaS) lets anyone rent the tools for a cut of the proceeds.

A brief history

The concept dates to 1989 (the “AIDS Trojan,” distributed on floppy disks) and was formalized academically by Adam L. Young and Moti Yung in 1996. It became a mass threat around 2013 with CryptoLocker, exploded globally with WannaCry and NotPetya in 2017, and shifted to targeted attacks on businesses, hospitals, and governments from 2019 onward. Double extortion (steal, then encrypt) became standard around 2020. Today’s groups target backups first, move through networks for days before encrypting, and time attacks for Friday nights and holidays.

Why ransomware matters in 2026

  • The share of breached organizations reporting ransomware has climbed steadily, reaching 39% in IBM’s 2026 Cost of a Data Breach report — up from 24% three years earlier.
  • Average ransomware recovery costs for mid-size businesses run well into six figures even when no ransom is paid — Sophos’ latest State of Ransomware study put the mean recovery cost, excluding any ransom, at roughly $1.5 million — driven by downtime, incident response, rebuilding systems, legal costs, and notifications.
  • The FBI’s IC3 received thousands of ransomware complaints in its 2025 annual report, with critical manufacturing, healthcare, and government facilities among the most-hit sectors.
  • Small and mid-size businesses are targeted deliberately: they hold valuable data, can afford a ransom, and rarely have 24/7 security monitoring.

For a business without tested, isolated backups, ransomware isn’t a security incident. It’s an existential event.

Types of ransomware

Type What it does
Crypto ransomware Encrypts files; the dominant form
Locker ransomware Locks the whole device or screen without encrypting files; more common on mobile
Double extortion Steals data before encrypting, threatens publication
Triple extortion Adds a third pressure: DDoS attacks, or contacting your customers and partners directly
Ransomware-as-a-service (RaaS) The business model: developers rent the malware to affiliates who run attacks
Wiper malware disguised as ransomware Destroys data with no real intent to decrypt (NotPetya); usually state-sponsored
Data extortion only Skips encryption entirely; steals data and demands payment not to leak it

The most active groups going into late 2026 include Qilin, Akira, Cl0p, Play, and a resurgent LockBit; earlier names like ALPHV/BlackCat and RansomHub have gone dark, and names keep changing as groups are disrupted and rebrand.

How a ransomware attack unfolds

Ransomware attacks are not instant. The typical timeline from first access to encryption is days to weeks, and every stage is a chance to catch it.

  1. Initial access. A phishing email with a malicious attachment, a stolen or reused password on a remote desktop or VPN connection without MFA, an unpatched vulnerability in a firewall or file-transfer tool, or a compromised managed service provider.
  2. Establishing a foothold. The attacker installs remote-access tools and creates new accounts so they can get back in even if the original entry is closed.
  3. Reconnaissance and privilege escalation. They map the network, find the domain controller and file servers, and work toward administrator credentials.
  4. Lateral movement. Using those credentials, they spread to every server and workstation they can reach.
  5. Finding and destroying backups. They locate backup servers and cloud backup consoles and delete or encrypt them, so you have nothing to restore from.
  6. Data exfiltration. Gigabytes of your files are uploaded to attacker-controlled storage. This is what makes it a breach.
  7. Encryption. Usually launched at night or on a weekend, across every system simultaneously. Ransom notes appear.
  8. Extortion. Negotiation through a dark web portal. Deadlines, threats, sample data published to prove the theft.

Endpoint detection, MFA, and monitoring catch attacks in stages 1 through 5. That’s why they matter more than anything you do after stage 7.

Sixwatch engineers working in the network operations center

Real examples

The remote desktop nobody used. A 60-person accounting firm had a remote desktop server from years earlier, still exposed to the internet with no MFA. An attacker used a password from an old breach to log in on a Tuesday. For nine days they mapped the network and copied client tax files. On the following Friday at 11 p.m., every server and workstation was encrypted. The backups, stored on a network share, were encrypted too. Recovery took five weeks and required notifying 2,400 clients.

The MSP that became the entry point. A ransomware group compromised a small managed service provider’s remote management tool and used it to push ransomware to dozens of client businesses at once. The clients had done nothing wrong; their provider had. (This pattern has occurred repeatedly and is why MSP security matters when choosing one.)

The one that didn’t work. A medical practice’s front desk opened a “patient referral” attachment. The endpoint detection tool flagged the process spawning encryption activity within seconds, isolated the workstation from the network automatically, and alerted the security team. One machine was rebuilt. Nothing else was touched. Total downtime: 90 minutes for one user.

Should you pay the ransom?

The FBI and CISA advise against paying, and for good reasons:

  • Payment funds the next attack, on you or someone else.
  • Many organizations that pay never get all their data back — in some studies most don’t — and decryption tools provided by attackers are often slow and buggy.
  • Paying marks you as a target that pays. Repeat attacks are common.
  • Payment to sanctioned groups can violate U.S. Treasury (OFAC) regulations.
  • Paying doesn’t undo the data theft. The stolen data exists regardless.

In practice, the decision depends on whether you have working backups. Businesses with tested, isolated backups restore and don’t pay. Businesses without them face a choice between paying and rebuilding from nothing. Cyber insurance policies typically cover ransom payments and negotiations but require the insurer to be involved from the start.

Whatever the decision, it should be made with your insurer, legal counsel, and an incident response firm, not alone at 2 a.m.

How to prevent ransomware

In priority order:

  1. Immutable, offline, tested backups. The single control that turns ransomware from catastrophe to inconvenience. Backups must be unreachable from the network (immutable cloud storage or offline copies), and you must have restored from them recently.
  2. Multi-factor authentication on all remote access, email, admin accounts, and backup consoles. Most ransomware starts with a stolen password that MFA would have stopped. See multi-factor authentication.
  3. Endpoint detection and response (EDR) with 24/7 monitoring, so the attack is caught during reconnaissance, not after encryption. See endpoint security.
  4. Patch fast, especially internet-facing systems: firewalls, VPNs, remote access tools, file transfer apps. Most exploited vulnerabilities have patches available for weeks before the attack.
  5. Remove exposed remote desktop and legacy remote access. Put it behind a VPN with MFA or a zero-trust gateway.
  6. Email security with attachment sandboxing and link scanning. See what is phishing.
  7. Least privilege. No daily-use accounts with admin rights. Separate admin accounts used only for admin tasks.
  8. Network segmentation so a compromised workstation can’t reach every server.
  9. Security awareness training with phishing simulations.
  10. An incident response plan that’s been rehearsed, with your insurer’s hotline and an incident response firm on it. See business continuity plan.
  11. Vet your MSP. Ask how they secure their own remote management tools, whether they use MFA everywhere, and whether they’ve had a SOC 2 audit.

How to recover from ransomware

  1. Isolate. Disconnect affected systems from the network and internet. Don’t power them off; memory holds evidence.
  2. Activate the plan. Notify your managed security provider or incident response firm, your cyber insurer (before anything else is done; policies require it), and legal counsel.
  3. Identify the strain. The ransom note and encrypted file extensions identify the group. Check NoMoreRansom.org for free decryptors; some older strains have them.
  4. Determine scope. What’s encrypted, what’s not, what data was stolen. Preserve logs.
  5. Contain and eradicate. Find the attacker’s access points and persistence mechanisms and remove them. Restoring without doing this means getting re-encrypted.
  6. Restore from clean backups, prioritizing by the business continuity plan’s recovery order. Verify backups are clean before restoring.
  7. Rebuild what can’t be restored. Fresh operating systems, not cleaned ones.
  8. Reset every credential in the environment.
  9. Notify as required: regulators (HIPAA, state breach laws), affected individuals, clients, and law enforcement (ic3.gov).
  10. Post-incident review. How they got in, what worked, what didn’t, and what changes.

Recovery for a mid-size business with good backups: 1 to 5 days. Without: 2 to 8 weeks, if ever.

Ransomware protection tools compared

Control What it prevents Typical cost
Immutable cloud backup Losing your only copy $50 – $500 / mo depending on data volume
EDR / MDR Execution and lateral movement $8 – $25 / device / mo
MFA (phishing-resistant) Credential-based entry $0 – $6 / user / mo
Email security Malicious attachments and links $3 – $8 / user / mo
Patch management Exploited vulnerabilities Included in managed IT
Zero-trust remote access Exposed RDP/VPN entry $5 – $15 / user / mo
Network segmentation Spread Project cost; firewall dependent
Security awareness training The click $2 – $6 / user / mo
Cyber insurance Financial impact Varies; controls above reduce premiums
Managed cybersecurity service All of the above, run by a team $50 – $150 / user / mo

Sixwatch team planning an IT roadmap

Common mistakes

  • Backups on the same network. The attackers find and encrypt them. Immutable or offline only.
  • Backups never tested. The restore fails when you need it most.
  • “We have antivirus.” Antivirus catches yesterday’s malware; ransomware groups test against it before deploying.
  • Remote desktop exposed to the internet. Still the top entry point for small businesses.
  • No MFA on the VPN or backup console. One stolen password is enough.
  • Powering off encrypted machines. Destroys evidence and can corrupt partially encrypted files.
  • Restoring before removing the attacker. Leads to re-encryption within days.
  • Not calling the insurer first. Policies require it; skipping it can void coverage.

How Sixwatch protects against ransomware

Every Sixwatch managed cybersecurity plan is built around the controls that stop ransomware: immutable backups tested quarterly, phishing-resistant MFA, endpoint detection and response with 24/7 monitoring, aggressive patching of internet-facing systems, email security with sandboxing, and network segmentation, for businesses across Tampa Bay and Cincinnati.

When something gets through, our 30-minute emergency remote response isolates it before it spreads, and same-day onsite support handles the rebuild. Founder John Owens has 25+ years of experience, and our 5.0 Google rating includes clients whose ransomware attack ended as a one-workstation incident instead of a company-wide outage.

The best IT service, security, and support in Tampa. Thank you for the quick response and guidance with our network issues.

Kat

Book a 15-minute call to review your ransomware readiness, or request a proposal.

Frequently asked questions

What is ransomware in simple terms? Malicious software that locks your files with encryption and demands payment for the key. Modern versions also steal your data and threaten to publish it.

How does ransomware get into a business? Most commonly through phishing emails, stolen passwords on remote access without MFA, unpatched internet-facing systems, or a compromised IT provider.

Can ransomware be removed? The malware can be removed, but removing it doesn’t decrypt the files. Recovery requires backups, a free decryptor (rare), or the attacker’s key.

Should I pay a ransomware demand? The FBI and CISA advise against it. Payment doesn’t guarantee recovery, funds future attacks, and may violate sanctions. Businesses with tested backups don’t need to. Make the decision with your insurer and counsel.

How long does ransomware recovery take? One to five days with tested, isolated backups and a rehearsed plan. Two to eight weeks or more without them.

Does cyber insurance cover ransomware? Most policies cover incident response, recovery costs, business interruption, and ransom payments, provided the controls listed in your application (MFA, backups, EDR) were actually in place.

What is double extortion ransomware? An attack where data is stolen before encryption, so the attacker can demand payment both for the decryption key and for not publishing the data.

Can antivirus stop ransomware? Traditional antivirus rarely does. Ransomware groups test their tools against common antivirus products. Endpoint detection and response, which watches behavior rather than signatures, is the current minimum.

Glossary

  • Affiliate: A criminal who rents ransomware from a developer and carries out attacks.
  • Decryptor: A tool that reverses the encryption; provided by the attacker after payment, or occasionally released free by researchers.
  • Double extortion: Data theft plus encryption.
  • Exfiltration: Copying data out of the victim’s network.
  • Immutable backup: A backup copy that cannot be altered or deleted for a set period, even by an administrator.
  • Initial access broker: A criminal who sells network access to ransomware groups.
  • Lateral movement: Spreading from the first compromised machine to others.
  • Persistence: Methods attackers use to keep access after a reboot or password change.
  • RaaS: Ransomware-as-a-service.
  • RDP: Remote Desktop Protocol; a common entry point when exposed to the internet.

Would your backups survive a ransomware attack? Book a 15-minute call · Request a proposal

Cybersecurity Services in Port Charlotte, FL

October 7, 2026

Managed IT Services Pricing: What Businesses Actually Pay in 2026

October 6, 2026

Managed IT Services in Port Charlotte, FL

October 5, 2026

What Is Phishing? How Attacks Work and How to Stop Them

October 1, 2026

Cloud Services in Bradenton, FL

September 30, 2026

What Is a Managed Service Provider (MSP)?

September 29, 2026

IT Outsourcing in Bradenton, FL

September 28, 2026

IT Consulting in Bradenton, FL

September 25, 2026

What Is Cybersecurity? A Plain-English Guide for Business Owners

September 24, 2026

Cybersecurity Services in Bradenton, FL

September 23, 2026

Managed IT Services: What They Are, What’s Included, and What They Cost

September 22, 2026

Managed IT Services in Bradenton, FL

September 16, 2026

Cloud Services in Fort Myers, FL

September 11, 2026

IT Outsourcing in Fort Myers, FL

September 9, 2026

IT Consulting in Fort Myers, FL

September 7, 2026

Cybersecurity Services in Fort Myers, FL

September 4, 2026

Managed IT Services in Fort Myers, FL

September 2, 2026

Cloud Services in Sarasota, FL

August 28, 2026

IT Outsourcing in Sarasota, FL

August 26, 2026

IT Consulting in Sarasota, FL

August 24, 2026

Cybersecurity Services in Sarasota, FL

August 21, 2026

Managed IT Services in Sarasota, FL

August 19, 2026

IT Support in Sarasota, FL

August 17, 2026

Cloud Services in Naples, FL

August 14, 2026

IT Outsourcing in Naples, FL

August 12, 2026

IT Consulting in Naples, FL

August 10, 2026

Cybersecurity Services in Naples, FL

August 7, 2026

Managed IT Services in Naples, FL

August 5, 2026

Cloud Services in St. Petersburg, FL

July 31, 2026

IT Outsourcing in St. Petersburg, FL

July 29, 2026

IT Consulting in St. Petersburg, FL

July 27, 2026

Cybersecurity Services in St. Petersburg, FL

July 24, 2026

Managed IT Services in St. Petersburg, FL

July 22, 2026

Cloud Services in Clearwater, FL

July 17, 2026

IT Outsourcing in Clearwater, FL

July 15, 2026

IT Consulting in Clearwater, FL

July 13, 2026

Best Cybersecurity Services in Clearwater, FL | Sixwatch

July 10, 2026

Managed IT Services in Clearwater, FL

July 8, 2026

Best Cloud Services in Cincinnati | Sixwatch

July 3, 2026

IT Outsourcing in Cincinnati | Sixwatch

July 1, 2026

Cybersecurity Services in Cincinnati | Sixwatch

June 29, 2026

IT Consulting in Cincinnati | Sixwatch

June 29, 2026

Managed IT Services in Cincinnati | Sixwatch

June 24, 2026

IT Support in Cincinnati | Sixwatch

June 22, 2026

Cloud Services in Tampa, FL | Sixwatch

June 19, 2026

IT Outsourcing in Tampa, FL | Sixwatch

June 17, 2026

IT Consulting in Tampa, FL | Sixwatch

June 15, 2026

Cybersecurity Services in Tampa, FL | Sixwatch

June 12, 2026

Managed IT Services Tampa, FL | Sixwatch

June 10, 2026