Ransomware

/ˈræn.sʌm.wɛr/ · Noun · Security & Infosec · Origin: 1989

Definitions

  1. Ransomware is a type of malicious software that encrypts a victim's files, databases, or entire systems and demands a ransom payment (typically in cryptocurrency) in exchange for the decryption key. Modern ransomware attacks often follow a double-extortion model, where attackers both encrypt the data and exfiltrate copies, threatening to publish sensitive information if the ransom is not paid. The attack typically begins with a phishing email, an exploited vulnerability, or compromised remote access credentials. Ransomware-as-a-Service (RaaS) operations like LockBit, BlackCat, and REvil provide ready-made ransomware tools to affiliates in exchange for a percentage of ransom payments. High-profile attacks have disrupted hospitals, fuel pipelines (Colonial Pipeline, 2021), schools, and city governments. Defenses include regular offline backups, network segmentation, endpoint detection and response (EDR), multi-factor authentication, patching, and incident response planning. Law enforcement agencies generally advise against paying ransoms, as payment funds criminal operations and does not guarantee data recovery.

    In plain English: Malicious software that locks up all your files and demands money to unlock them — like a digital kidnapper holding your data hostage.

Etymology

1989
AIDS Trojan — the first ransomware — distributed via floppy disk at a WHO conference
2013
CryptoLocker brings modern ransomware to the masses
2017
WannaCry cripples the NHS and spreads worldwide
2021
Colonial Pipeline attack triggers US executive order on cybersecurity

Related Terms

Collections Including This Term