Know
What is Ransomware?
Modern ransomware operations may combine data theft, encryption, service disruption, public-leak threats, and pressure against customers or partners. Some incidents involve an affiliate ecosystem in which access brokers, ransomware operators, and other specialists participate in the same campaign.
Why it matters
Ransomware can halt core operations, expose sensitive data, disrupt customers, and create major recovery and legal costs even when an organization refuses to pay.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Qakbot infected more than 700,000 computers and enabled ransomware operations
The Justice Department and FBI disrupted Qakbot infrastructure after identifying more than 700,000 infected computers worldwide. Qakbot was used to deliver additional malware and ransomware.
This provides direct law-enforcement validation of malware as a delivery and access mechanism used in broader criminal ecosystems.
ALPHV/BlackCat ransomware activity documented through FBI investigations
A joint advisory publishes indicators and tactics associated with ALPHV/BlackCat ransomware based on FBI investigations and notes that healthcare was the most commonly victimized sector among recent leaked victims.
The advisory connects ransomware terminology to observed campaigns, indicators, tactics, victim impact, and recommended defensive actions.
Understand the mechanics
How it works
- 1
Gain initial access through credentials, phishing, exposed services, or vulnerabilities.
- 2
Establish persistence and expand privileges.
- 3
Discover systems, backups, identities, and valuable data.
- 4
Move laterally and often exfiltrate data.
- 5
Encrypt, disrupt, or otherwise deny access.
- 6
Demand payment and apply extortion pressure.
Practice
What to watch for
- Unusual administrative activity
- Mass file changes
- Security tools being disabled
- Unexpected lateral movement
- Backup deletion attempts
- Ransom notes or inaccessible files
Perform
What to do
- 1
Activate the incident response plan.
- 2
Isolate affected systems without destroying evidence.
- 3
Protect unaffected backups and privileged identities.
- 4
Determine scope and initial access.
- 5
Engage legal, insurance, law enforcement, and response specialists as appropriate.
How to reduce the risk
- Phishing-resistant MFA
- Patching and exposure management
- Endpoint detection and response
- Network segmentation
- Least privilege
- Immutable/offline backups
- Incident-response exercises
Business impact
- Business interruption
- Data theft
- Recovery cost
- Extortion
- Regulatory obligations
- Customer impact
What different roles should do
Employee
- Report suspicious activity quickly
- Do not attempt improvised remediation
Security
- Contain affected assets and identities
- Preserve evidence
- Prioritize restoration from trusted systems
Executive
- Use the established crisis and legal decision process
- Separate operational recovery from ransom-pressure decisions
Framework & standards context
- MITRE ATT&CK T1486 — Data Encrypted for Impact
Source transparency
Authoritative sources
Last reviewed: 2026-09-02