What it is
Ransomware is malware that encrypts the files of a computer or an entire network and demands a ransom to restore them. Today it often also steals a copy of the data and threatens to publish it (double extortion).
How it works
- 1Entry comes through a phishing email, stolen credentials on remote access without multi-factor authentication, or outdated software.
- 2The attacker moves through the network, looks for important data and deletes or encrypts the backups.
- 3They copy data out and then encrypt the systems.
- 4The ransom message appears with a deadline to pay.
How to spot it
- Files that will not open or have odd extensions
- A ransom note on screen or in folders
- Very slow computers, antivirus turned off, backups gone
- Unusual out-of-hours access to systems
How to defend
- Backups kept apart from the network (offline or immutable), tested with real restores
- Regular updates and multi-factor authentication on every remote access
- Least privilege: everyone accesses only what they need
- Staff training against phishing and attachments
- A written incident response plan, with the contacts to call
If you think you have been hit
- Isolate the affected devices at once by disconnecting them from the network
- Do not pay without consulting experts: paying does not guarantee getting the data back
- Alert a security expert, report to the police and keep evidence
- If personal data is involved, assess with an advisor whether to notify the data protection authority within 72 hours of discovery
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026