Ransomware

/ˈræn.sʌm.wɛr/ · Noun · Security & Infosec · Origin: 1989

Definitions

  1. Ransomware is a type of malicious software that encrypts a victim's files, databases, or entire systems and demands a ransom payment (typically in cryptocurrency) in exchange for the decryption key. Modern ransomware attacks often follow a double-extortion model, where attackers both encrypt the data and exfiltrate copies, threatening to publish sensitive information if the ransom is not paid. The attack typically begins with a phishing email, an exploited vulnerability, or compromised remote access credentials. Ransomware-as-a-Service (RaaS) operations like LockBit, BlackCat, and REvil provide ready-made ransomware tools to affiliates in exchange for a percentage of ransom payments. High-profile attacks have disrupted hospitals, fuel pipelines (Colonial Pipeline, 2021), schools, and city governments. Defenses include regular offline backups, network segmentation, endpoint detection and response (EDR), multi-factor authentication, patching, and incident response planning. Law enforcement agencies generally advise against paying ransoms, as payment funds criminal operations and does not guarantee data recovery.

    In plain English: Malicious software that locks up all your files and demands money to unlock them — like a digital kidnapper holding your data hostage.

Etymology

1989
AIDS Trojan — the first ransomware — distributed via floppy disk at a WHO conference
2013
CryptoLocker brings modern ransomware to the masses
2017
WannaCry cripples the NHS and spreads worldwide
2021
Colonial Pipeline attack triggers US executive order on cybersecurity

Related Terms