What is Ransomware?
Ransomware is malware that locks your files or systems and demands payment for restoration. Modern campaigns often combine encryption with data theft and public shaming. Attackers rarely start with the ransomware itself — they start with reconnaissance to find who can authorize payment and which systems will hurt most if taken offline.
How a Ransomware Attack Works
Select a high-pressure target
Public filings, news, and industry directories help attackers prioritize organizations that cannot tolerate downtime — hospitals, manufacturers, professional services.
Gain initial access
Phishing, exposed remote access, or purchased credentials get a foothold. OSINT tells them which email themes and VPN portals are most believable.
Move laterally and stage encryption
They map backups, domain admins, and critical servers before detonating — maximizing leverage.
Extort
Encryption plus stolen data plus threats to notify customers or regulators create payment pressure.
Real-World Example
A regional manufacturer was targeted after attackers found OT remote-access certificates and a plant manager's detailed LinkedIn project history. The initial email posed as a PLC vendor support bulletin. Encryption followed weeks later after backups were identified.
How AiVERSARY Detects Ransomware Risk
AiVersary shows the public intelligence an attacker would use to pick you, craft phishing, and identify high-value people — the front door to many ransomware chains — so you can harden exposure before encryption is ever in play.
Is your organization exposed to ransomware?
AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.
Get Your Threat ReportRelated Terms
Spear Phishing
Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.
Credential Stuffing
Credential stuffing is when attackers take usernames and passwords leaked from one breach and automatically try them on other services. Because most people reuse passwords, a breach at a shopping site or social network can give attackers working credentials for your corporate email, VPN, or cloud platforms. It is automated, fast, and alarmingly effective.
OSINT Reconnaissance
OSINT reconnaissance — Open Source Intelligence gathering — is the first phase of nearly every targeted cyberattack. It's the process of collecting publicly available information about an organization and its people to plan an attack. Everything from your company website and LinkedIn profiles to job postings, DNS records, and conference presentations becomes intelligence. This is exactly the same process AiVersary uses, but we do it first so you can fix what's exposed.
Supply Chain Attack
A supply chain attack reaches your organization through a third party — software updates, managed providers, or operational vendors. Instead of breaking your front door, attackers break someone you already let inside.