Ransomware Explained: What It Is and How to Stay Safe

What ransomware is, how attacks unfold, whether paying the ransom ever makes sense, and the steps that actually reduce your risk.

Official CISA Stop Ransomware campaign graphic warning about Medusa ransomware
CISA Stop Ransomware awareness campaign. Image: CISA.

Ransomware is malware that encrypts the files on a computer, server, or entire network, then demands payment in exchange for the decryption key needed to restore access. It typically gets onto a device or network through a phishing email, a poorly secured remote-access connection, or an unpatched software vulnerability, and it can lock up anything from a single laptop to the systems a hospital or city government relies on to operate. Official U.S. guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) does not recommend paying the ransom: payment does not guarantee you will get your data back, and free decryption tools already exist for some ransomware variants. This explainer covers what ransomware actually is, how it differs from malware in general, how attacks typically unfold, the rise of "double extortion," whether paying ever makes sense, and the concrete steps individuals and small organizations can take to prevent an attack and respond if one happens.

Ransomware at a glance
  • What it is: Malware designed to encrypt files and systems, rendering them unusable until a ransom is paid for the decryption key.
  • How it spreads: Most commonly through phishing emails, exposed or poorly secured remote desktop (RDP) connections, and unpatched software vulnerabilities.
  • Double extortion: Many attackers also steal data before encrypting it, then threaten to leak it even if you restore from backup.
  • Should you pay? Official guidance does not recommend it; there is no guarantee you will recover your files, and a free decryptor may already exist.
  • Who to report to: CISA, your local FBI field office, or the FBI's Internet Crime Complaint Center at ic3.gov.

What Is Ransomware?

CISA defines ransomware as "an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable." In practice, that means an attacker scrambles your files with strong encryption so you can no longer open them, then leaves a message demanding payment, usually in cryptocurrency, in return for a decryption key. NIST describes the same idea in business terms: ransomware is "a type of malicious attack where attackers encrypt an organization's data and demand payment to restore access."

Ransomware is not picky about its targets. It has been used against individual consumers, small businesses, large corporations, school districts, hospitals, and municipal governments. CISA notes that a successful attack "can severely impact business processes and leave organizations without the data they need to operate and deliver mission-critical services," with effects that can linger well beyond the initial incident.

Ransomware vs. Malware: What Is the Difference?

"Malware" is the umbrella term for any software designed to damage, disrupt, or gain unauthorized access to a computer system. It covers a wide family of threats, including viruses, worms, trojans, spyware, adware, and ransomware. Ransomware is best understood as one specific, extortion-driven branch of that family: instead of quietly stealing information or spying in the background, it announces itself by locking your files and demanding payment.

So every piece of ransomware is malware, but not all malware is ransomware. Spyware tries to stay hidden and harvest data over time; a banking trojan tries to steal credentials without being noticed; ransomware does the opposite, making its presence obvious because the extortion only works if the victim knows their files are encrypted and sees a demand for payment.

How Ransomware Attacks Happen: Common Infection Vectors

Ransomware rarely exploits some exotic, unknown technique. According to CISA's joint #StopRansomware Guide, most attacks succeed through a handful of well-understood entry points that organizations and individuals can defend against:

  • Phishing emails and social engineering. A malicious attachment or link convinces someone to run malware or hand over login credentials. This remains one of the most common starting points for an attack, which is why CISA recommends ongoing cybersecurity user awareness training to help staff spot phishing emails before they click.
  • Remote access compromise. Attackers scan the internet for exposed Remote Desktop Protocol (RDP) services and other remote-access tools, then log in using stolen, weak, or reused passwords. CISA's guide specifically advises organizations to "limit the use of RDP and other remote desktop services" and lock down whatever remote access remains necessary.
  • Exploited software vulnerabilities. Attackers target known, unpatched flaws, especially in internet-facing servers and VPN appliances, to gain an initial foothold without needing to trick anyone at all. Regularly patching software and operating systems closes this door.
  • Compromised credentials. Reused or weak passwords, and accounts without multi-factor authentication, give attackers an easy way in once they have stolen a single password from a breach or phishing attempt. CISA recommends "phishing-resistant MFA for all services, particularly for email, VPNs, and accounts that access critical systems."

What Happens During a Ransomware Attack

Once attackers get a foothold using one of the vectors above, a typical ransomware incident unfolds in stages rather than all at once. Attackers generally work to expand their access across the network, locate valuable or sensitive data, and disable or evade security tools before they ever trigger the encryption that victims notice. By the time files start becoming unreadable and a ransom note appears, demanding payment for a decryption key, the attacker has often already been inside the network for some time and may have copied data out before locking anything.

That last detail matters, because it is the basis of the extortion tactic described next, and it is also why CISA's guidance treats "detect and analyze" as the first incident-response step rather than assuming encryption is the whole story: logs need to be reviewed for the "precursor malware" that got the attacker in long before the ransomware itself ran.

Double Extortion: When Encryption Isn't the Only Threat

Encrypting files used to be the entire attack. Today, CISA notes that malicious actors "continue to adjust and evolve their ransomware tactics," and one of the biggest shifts has been the rise of double extortion: before encrypting anything, attackers quietly copy sensitive files off the network. Then, even if the victim has clean backups and can restore every encrypted file without paying a cent, the attacker still has leverage. As CISA puts it, perpetrators "threaten to sell or leak exfiltrated data or authentication information if the ransom is not paid."

This is why backups alone, while essential, are no longer a complete answer to ransomware. A good backup strategy guarantees you can recover your systems. It does not guarantee that stolen customer records, financial data, or internal documents will not end up published or sold if you decline to pay a double-extortion demand.

Should You Pay the Ransom?

Official guidance does not recommend paying. NIST frames the decision bluntly: after an attack, an organization faces a choice between paying the ransom "and hope that the attackers keep their word about restoring access," or declining to pay and restoring operations on its own. Critically, NIST notes that a ransom payment "offers no guarantee of data recovery" and can trigger state data-breach notification obligations if customer information was involved, regardless of whether the data is ultimately leaked.

CISA's #StopRansomware Guide does not instruct victims to pay either. Instead, it directs organizations to consult federal law enforcement before taking any action, in part because "security researchers may have discovered encryption flaws for some ransomware variants and released decryption or other types of tools" that can restore files for free, without funding the attacker at all. In other words, reporting the incident before paying can sometimes save the ransom entirely.

Paying also does nothing to address a double-extortion threat if attackers already have a copy of your data, and it provides financial incentive for criminal groups to keep targeting new victims. For both individuals and organizations, the safer path is to isolate the affected systems, report the incident, and explore recovery and decryption options with law enforcement and incident-response professionals before considering payment.

Infection VectorHow Attackers Use ItWhat Reduces the Risk
Phishing emailsMalicious attachment or link installs malware or harvests login credentialsSecurity awareness training, email filtering, verifying unexpected requests independently
Exposed or weak RDPAttackers log in remotely using brute-forced or stolen credentialsLimit RDP exposure, require phishing-resistant MFA, use a VPN for remote access
Unpatched software vulnerabilitiesAttackers exploit known flaws in internet-facing servers and VPN appliancesRegular patching, vulnerability scanning on internet-facing systems, prioritizing known exploited vulnerabilities
Compromised credentialsReused or weak passwords, or accounts without MFA, grant network accessUnique passwords, multi-factor authentication on every account, least-privilege access policies

How to Protect Yourself and Your Organization

CISA's #StopRansomware Guide and NIST's small-business guidance both converge on a small set of practices that meaningfully reduce ransomware risk, whether you are securing a household or a small office network:

  • Maintain offline, encrypted backups of critical data and regularly test that you can actually restore from them. A backup that has never been tested is not a reliable recovery plan.
  • Patch and update promptly. Regularly patch and update software and operating systems, prioritizing internet-facing devices and servers with known, actively exploited vulnerabilities.
  • Turn on multi-factor authentication everywhere it is offered, especially for email, VPN, and any account that can reach critical systems. Setting up a dedicated authenticator app for two-factor authentication is a stronger option than codes sent by text message.
  • Limit and lock down remote access. Restrict the use of RDP and other remote desktop services, and require strong authentication wherever remote access is genuinely needed.
  • Train people to recognize phishing. Since phishing remains one of the most common ways ransomware gets in, ongoing user awareness training measurably reduces successful clicks.
  • Apply the principle of least privilege. Restrict administrative privileges so that a single compromised account cannot reach the entire network, and disable unnecessary legacy protocols such as SMBv1.
  • Segment your network so that a ransomware infection on one machine or subnet cannot spread unchecked to every other system.
  • Enable logging and monitoring so unusual activity, like mass file renaming or unexpected administrative logins, can be caught before encryption spreads.

What to Do If You've Been Hit by Ransomware

CISA's guidance for active incidents centers on containment first, recovery second:

  1. Isolate affected systems immediately. Determine which systems were impacted and disconnect them from the network right away. If isolating individual machines is not feasible, CISA advises taking "the network offline at the switch level." For cloud-based resources, take a snapshot of volumes to preserve a point-in-time copy for forensic review.
  2. Don't assume encryption is the only step you need to investigate. Examine available logs for precursor malware or earlier unauthorized access, since the ransomware itself is often only the final stage of an intrusion that started earlier.
  3. Report the incident before deciding anything about payment. Contact CISA, your local FBI field office, the FBI's Internet Crime Complaint Center (IC3), or your local U.S. Secret Service field office. Consult federal law enforcement about possible decryptors "even if mitigation actions are possible," since a free tool may already exist for the variant that hit you.
  4. Restore from clean, offline backups once systems are contained, prioritizing the services that are most critical to get back online first.
  5. Document what happened and feed the lessons learned back into your security practices, since the vectors that let the attacker in rarely close themselves.

Reporting Ransomware: Who to Contact

Whether you are an individual, a small business, or a larger organization, U.S. federal guidance is consistent: report ransomware promptly rather than handling it in isolation. The main channels are:

  • CISA — for technical assistance and incident reporting, especially for organizations, via cisa.gov/stopransomware.
  • Your local FBI field office — for direct law enforcement engagement.
  • The FBI's Internet Crime Complaint Center (IC3) — the central portal at ic3.gov for reporting ransomware and other cybercrime, used by both individuals and organizations.
  • Your local U.S. Secret Service field office — another federal law enforcement option, particularly relevant when financial fraud is involved.

Reporting is not just a formality. It connects victims to investigators who track ransomware infrastructure across many cases, and as noted above, it can surface free decryption tools before anyone pays a cent.

Bottom Line: What to Do Next

Ransomware is malware built around extortion: it encrypts your files, and increasingly also steals them, then demands payment to undo the damage. The entry points are well known, phishing, exposed remote access, unpatched vulnerabilities, and weak credentials, which means the defenses are well known too: offline encrypted backups you actually test, prompt patching, multi-factor authentication, limited remote access, and basic staff awareness of what a phishing attempt looks like. If you are ever hit, isolate affected systems immediately, report to CISA, your local FBI field office, or IC3 before making any decision about payment, and restore from backup once the incident is contained. Official guidance does not recommend paying a ransom, since it offers no guarantee of recovery and does nothing to undo a data leak that has already occurred.

Frequently asked questions

What is ransomware in simple terms?

Ransomware is malware that encrypts the files on a computer or network, then demands payment for the decryption key needed to restore access. It can affect anything from a single laptop to an entire organization's systems.

What is the difference between ransomware and malware?

Malware is the broad category for any malicious software, including viruses, spyware, and trojans. Ransomware is one specific type of malware that encrypts files and extorts the victim for payment, rather than quietly stealing data in the background.

Should I pay a ransomware demand?

Official guidance from CISA and NIST does not recommend paying. Payment offers no guarantee you will recover your files, may trigger data-breach notification requirements, and free decryption tools already exist for some ransomware variants.

How does ransomware usually get onto a computer or network?

The most common entry points are phishing emails, exposed or poorly secured remote desktop (RDP) connections, unpatched software vulnerabilities, and compromised or weak credentials.

What is double extortion ransomware?

Double extortion is when attackers steal a copy of your data before encrypting it, then threaten to sell or leak that data even if you restore your systems from backup without paying.

Who do I report a ransomware attack to?

Report it to CISA, your local FBI field office, or the FBI's Internet Crime Complaint Center at ic3.gov. Reporting before deciding whether to pay can also reveal whether a free decryptor already exists for the ransomware variant involved.

Sources

More on Ransomware →ransomwaremalwarecybersecuritydata backupsphishingincident response
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all