Skip to content
lesson Cyber security fundamentals Intermediate 3 min read

How ransomware attacks work.

The three stages of a ransomware attack, how attackers get in, why they go after backups, and what to put in place before it happens.

Ransomware is malicious software that locks your devices or encrypts your files so that you cannot open them. The criminals then demand a payment, often in cryptocurrency, to restore access or to stop them leaking what they took.

The three stages of an attack

The UK’s National Cyber Security Centre describes a ransomware attack in three stages.

  1. Access. Attackers get into the network, establish control and plant the encryption software. They may also copy your data at this point.
  2. Activation. The software is switched on. Devices lock, and data across the network is encrypted.
  3. Ransom demand. A notice appears on screen with the price and how to pay, usually through an anonymous web page.

By the time anyone sees the notice, the first two stages are over. Everything that prevents an attack has to be in place before the first stage.

How attackers get in

The ransomware guide written by CISA, the FBI and the NSA in the United States groups its advice by the usual ways in:

  • unpatched or badly configured systems that face the internet, such as remote desktop
  • stolen or guessed passwords
  • phishing emails
  • other malware that is already on a device
  • a supplier or IT provider that has access to your network.

Ransomware arrives the same way as other malware, so the defences are familiar ones: updates, multi-factor authentication, and staff who know how to spot a phishing email.

Why backups are a target

The best way to recover is to restore from a backup the attack did not touch. Attackers know this. Many kinds of ransomware search for backups they can reach, then delete or encrypt them so that paying looks like the only way out.

That is why one copy should be offline or kept apart from the network, as the 3-2-1 backup rule sets out. It also has to work on the day, which is the subject of A backup you have never restored is a guess.

A backup does nothing about the second threat, which is publishing the data that was copied. The answer to that one is to limit what any single account can reach, so give each person only the access their job needs.

Should you pay?

The Australian Signals Directorate says never to pay a ransom. Paying does not guarantee that you get your files back, or that the data will not be sold or leaked anyway, and it can mark you as a target for another attack.

What to put in place now

  • Keep computers, servers and network storage up to date.
  • Turn on multi-factor authentication for email and remote access.
  • Check which services are open to the internet, such as remote desktop and file shares, and close the ones you do not need.
  • Use standard accounts for daily work and keep administrator accounts for the people who need them.
  • Keep an offline backup and restore from it on a schedule.

To see where your own gaps are, try the free Essential Eight assessment. If you would like a plan written before you need one, that is the work of our incident response service.

Sources

  1. Ransomware (Australian Signals Directorate) cyber.gov.au
  2. What you need to know about ransomware (UK National Cyber Security Centre) ncsc.gov.uk
  3. #StopRansomware Guide (CISA) cisa.gov
  4. Mitigating malware and ransomware attacks (UK National Cyber Security Centre) ncsc.gov.uk

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.