Ransomware
/ˈræn.sʌm.wɛr/ · Noun · Security & Infosec · Origin: 1989
Definitions
Ransomware is a type of malicious software that encrypts a victim's files, databases, or entire systems and demands a ransom payment (typically in cryptocurrency) in exchange for the decryption key. Modern ransomware attacks often follow a double-extortion model, where attackers both encrypt the data and exfiltrate copies, threatening to publish sensitive information if the ransom is not paid. The attack typically begins with a phishing email, an exploited vulnerability, or compromised remote access credentials. Ransomware-as-a-Service (RaaS) operations like LockBit, BlackCat, and REvil provide ready-made ransomware tools to affiliates in exchange for a percentage of ransom payments. High-profile attacks have disrupted hospitals, fuel pipelines (Colonial Pipeline, 2021), schools, and city governments. Defenses include regular offline backups, network segmentation, endpoint detection and response (EDR), multi-factor authentication, patching, and incident response planning. Law enforcement agencies generally advise against paying ransoms, as payment funds criminal operations and does not guarantee data recovery.
In plain English: Malicious software that locks up all your files and demands money to unlock them — like a digital kidnapper holding your data hostage.
Etymology
- 1989
- AIDS Trojan — the first ransomware — distributed via floppy disk at a WHO conference
- 2013
- CryptoLocker brings modern ransomware to the masses
- 2017
- WannaCry cripples the NHS and spreads worldwide
- 2021
- Colonial Pipeline attack triggers US executive order on cybersecurity