How it happens
- Email or stolen login
- Quiet preparation
- Files encrypted
- Ransom demand
The entry point is almost always ordinary: an email attachment, a fake login page, or a weak password for remote access. Exotic vulnerabilities are less common than someone opening the wrong thing.
Then comes the least noticeable part. The program looks around, finds data copies, and deletes them first, because they are exactly what would make everything that follows pointless. At this stage, you notice nothing.
Only then are the files encrypted and a ransom note appears. Today, this usually comes with a second threat: the attackers promise to publish a copy of the data, even if recovery succeeds.
What determines the outcome
- Keep a separate copy of your data: on a drive that is not always connected, or in a service with version history
- Test the copy by restoring it, not just by checking that it exists: an untested copy is hope, not a backup
- Disconnect the infected device from the network immediately to stop the spread
- Update the system and turn on two-factor authentication
- Keep your only copy on the same computer or on a constantly connected drive
- Open attachments you were not expecting, even from a familiar address
- Treat payment as a solution: the key is not always provided, and paying marks you as a target
- Try to “cure” work data yourself without a specialist
Payment is the worst option partly because it guarantees nothing. Decryption sometimes works only partially, sometimes not at all, and the mere fact that you paid makes you an easy target for another break-in.
For a home user, the takeaway is simple: the biggest losses are photos and documents that exist nowhere else. A copy on an external drive or in the cloud covers almost all the risk.
For a small organization, you also need a plan for a day without technology. Who calls whom, what gets disconnected, where the contacts and contracts are kept: if you work this out during the incident, the losses grow many times over.
Finish reading in the Miqo app
1 more minute, then a quiz at the end. Find it under “Crime → Cybercrime”
Point your phone camera here to open the App Store or Google Play.
Sources
- The main ways ransomware gets in are phishing attachments, compromised credentials, and exposed remote access. Deleting backups and shadow copies before encryption, as well as threatening to publish stolen data, are described as typical tactics. Cybersecurity agencies do not recommend paying the ransom: data recovery is not guaranteed