Security Glossary

What is Ransomware?

Ransomware is malware that locks your files or systems and demands payment for restoration. Modern campaigns often combine encryption with data theft and public shaming. Attackers rarely start with the ransomware itself — they start with reconnaissance to find who can authorize payment and which systems will hurt most if taken offline.

How a Ransomware Attack Works

1

Select a high-pressure target

Public filings, news, and industry directories help attackers prioritize organizations that cannot tolerate downtime — hospitals, manufacturers, professional services.

2

Gain initial access

Phishing, exposed remote access, or purchased credentials get a foothold. OSINT tells them which email themes and VPN portals are most believable.

3

Move laterally and stage encryption

They map backups, domain admins, and critical servers before detonating — maximizing leverage.

4

Extort

Encryption plus stolen data plus threats to notify customers or regulators create payment pressure.

Real-World Example

A regional manufacturer was targeted after attackers found OT remote-access certificates and a plant manager's detailed LinkedIn project history. The initial email posed as a PLC vendor support bulletin. Encryption followed weeks later after backups were identified.

How AiVERSARY Detects Ransomware Risk

AiVersary shows the public intelligence an attacker would use to pick you, craft phishing, and identify high-value people — the front door to many ransomware chains — so you can harden exposure before encryption is ever in play.

Is your organization exposed to ransomware?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report