Cybersecurity

8 mins

Ransomware: How Attacks Work, Types, and How to Prevent Them

Last Updated
September 30, 2026

Key Takeaways

  • Ransomware is malware that encrypts or steals an organisation's data, then demands payment to restore it or keep it private.
  • Exploited vulnerabilities are now the most common way attackers break in, at 31% of known entry points in Verizon's 2026 data.
  • Clean backups restore encrypted files but cannot stop stolen data being published.
  • Microsoft 365 Business Premium includes automatic attack disruption through Defender for Business, but some ransomware protections only work once configured in Intune.
  • Most victims do not pay: 69% refused in Verizon's 2026 dataset

Ransomware now runs like a business, with developers renting their tools to affiliates and brokers selling ready-made access to company networks. This guide explains how ransomware attacks get in, the main types, what Microsoft 365 already gives you, and what to do if you are hit. The stakes keep rising: ransomware appeared in 48% of breaches in Verizon's 2026 Data Breach Investigations Report (DBIR), up from 44% the year before.

‍

What Is Ransomware?

Ransomware is malicious software that blocks access to an organisation's systems or data, usually by encrypting files, and demands payment to restore access or to stop stolen data being published. The US Cybersecurity and Infrastructure Security Agency (CISA) calls it an ever-evolving form of malware. It also warns that attackers often threaten to leak stolen data if the ransom goes unpaid.

The way ransomware reaches a business has changed. Early outbreaks like WannaCry in 2017 spread on their own, jumping between unpatched Windows machines. Today, ransomware tends to be the last step of a hands-on intrusion. An attacker gets in through stolen credentials or an unpatched system, moves through the network, copies data out, and only then deploys the encryption.

Much of this runs as Ransomware-as-a-Service (RaaS). A core group builds the malware and infrastructure, then rents it to affiliates who carry out attacks for a share of the ransom. LockBit, which the UK National Crime Agency (NCA) called the world's most harmful cybercrime group before disrupting it in February 2024, worked this way. 

For a 200-person business, the attacker is rarely a lone hacker. It is a supply chain of specialists.

Is Ransomware a Type of Malware?

Yes, ransomware is a type of malware. What sets it apart is that it wants to be noticed. Spyware, infostealers and backdoors are built to stay hidden for as long as possible. Ransomware announces itself, because the ransom demand is the whole point. By the time the note appears, the damage is done, which is why catching the earlier steps matters most.

‍

How Does a Ransomware Attack Work?

A ransomware attack moves through five stages: the attacker gets in, takes control, spreads across the network, steals and encrypts data, then demands payment. Each stage takes time, and each one is a chance to stop the attack before the ransom note appears.

  1. Initial access. Exploited vulnerabilities are now the most common way in. They accounted for 31% of initial access in breaches in the Verizon 2026 Data Breach Investigations Report (DBIR), up from 20% the year before. Stolen credentials are the other main route: only 27% of ransomware victims had no infostealer infection or credential leak in the year before the attack. Phishing and phone-based pretexting complete the list, which is why phishing protection in Microsoft 365 still matters.
  2. Establishing control. Attackers increasingly use legitimate remote monitoring and management (RMM) software instead of obvious hacking tools. Verizon recorded a 240% relative growth in this technique over the previous year. Because these tools are already approved, they sit inside the organisation's allowlists.
  3. Lateral movement. From the first foothold, the attacker scans the network, dumps passwords and works toward admin accounts that reach every system.
  4. Data theft, then encryption. Data is copied out first, so the attacker has leverage even if your backups work. Encryption comes last, often timed to cause the most disruption.
  5. Extortion. A ransom note sets a deadline and threatens to publish the stolen data on a leak site if you do not pay.

Steps 1 to 3 are where detection pays off. Once encryption starts, the job shifts from stopping an attack to recovering from one.

‍

Types of Ransomware

Ransomware types differ in two ways: what the attack does to your data, and how the operation behind it is run. The first tells you whether backups can help. The second tells you what you are up against.

By What the Attack Does

Crypto ransomware encrypts files and systems so they cannot be opened without the attacker's key. Locker ransomware locks the device or screen but leaves files untouched. Data-theft extortion copies data out and threatens to publish it, and some attacks skip encryption entirely. Double extortion combines both: the data is stolen and the systems are encrypted.

By How the Attack Is Run

Ransomware-as-a-Service (RaaS) splits the work in two. Developers build and rent the tooling, and affiliates carry out the attacks. Human-operated ransomware describes the attack itself: a person inside the network makes decisions in real time, choosing which systems to hit and when. Microsoft uses this term for the attacks its automatic defences are designed to disrupt. Stopping a live operator means correlating signals across devices, identities and email, which is the work managed XDR services do. XDR stands for extended detection and response.

Type What it does Do backups help? Example
Crypto Encrypts files and systems Yes, if backups are offline or immutable and tested WannaCry
Locker Locks the device, not the data Yes, a rebuild restores access Not tied to one group
Data-theft extortion Steals data and threatens to leak it No, the data is already out Not tied to one group
Double extortion Steals data, then encrypts Partly: files return, the leak threat stays LockBit
RaaS Affiliates rent tooling from developers Depends on the payload LockBit

If you are not sure which entry points are open in your own environment and want to know before choosing tools, a security assessment that maps your exposed entry points is a practical first step.

‍

Well-Known Ransomware Examples

Three cases show how ransomware has changed: WannaCry for unpatched systems, LockBit for the business model, and Akira for the threat mid-sized companies face today.

WannaCry (2017). WannaCry spread in May 2017 through a flaw in the Windows file-sharing protocol SMBv1. Microsoft had released the patch on 14 March, two months earlier, according to CISA's alert. The lesson: patching speed is a ransomware control.

LockBit (disrupted 2024). LockBit rented its tools to affiliates for four years. The UK NCA says it was behind 25% of ransomware attacks in 2023-24. More than 7,000 attacks were built on its services between June 2022 and February 2024. An NCA-led operation took control of its infrastructure in February 2024.

Akira (2023 onward). Akira primarily targets small and medium-sized businesses. Its main way in, per a joint CISA and FBI advisory updated in November 2025, is a virtual private network (VPN) without multifactor authentication (MFA). By late September 2025, it had taken approximately $244.17 million in ransom proceeds.

‍

How to Prevent Ransomware Attacks

Preventing ransomware means closing the main ways in, limiting how far an attacker can move, and keeping backups the attacker cannot reach. The list starts with the entry routes the 2026 DBIR ranks highest..

  1. Patch internet-facing systems first. Start with anything on CISA's Known Exploited Vulnerabilities (KEV) catalog. According to the DBIR, only 26% of KEV vulnerabilities were fully fixed in 2025, and the median fix took 43 days.
  2. Use phishing-resistant MFA everywhere. CISA's #StopRansomware Guide calls for it on all services, particularly email and VPNs. Treat leaked-credential alerts as urgent, not routine.
  3. Lock down remote access. Put MFA on every VPN, avoid exposing Remote Desktop Protocol (RDP) to the internet, and allow only the RMM tools your IT team actually uses.
  4. Run endpoint detection that can act on its own. Endpoint detection and response (EDR) that isolates a device automatically buys time that an alert alone cannot, especially at night.
  5. Keep backups offline and test them. CISA recommends offline, encrypted backups of critical data, restored on a schedule to prove they work.
  6. Train for phone scams as well as email. Pretexting is a growing route into ransomware attacks, so help desk staff need a firm process for verifying anyone who asks for a password reset.
  7. Monitor around the clock. Attackers do not keep office hours, and the steps before encryption are where detection works. For most 50 to 500 person companies, that means 24/7 managed SOC monitoring and response rather than an in-house night shift. SOC stands for security operations center.

No single control stops every attack. Together, they make each stage of the attack chain harder and slower, which gives your team time to respond.

‍

How Microsoft 365 Protects Against Ransomware

Microsoft 365 Business Premium already includes most of the controls that stop ransomware, through Microsoft Defender for Business and Microsoft Intune. Several of them do nothing until someone configures them.

Defender for Business provides endpoint detection with Microsoft Defender for organisations of up to 300 users. Its standout ransomware control is automatic attack disruption. When Defender detects a human-operated attack on a device, it contains that device and the user accounts on it without waiting for an analyst.

Control What it does against ransomware In Business Premium?
Automatic attack disruption Contains the device and user accounts during a human-operated attack Yes, via Defender for Business
Attack surface reduction (ASR) rules Block behaviours ransomware relies on, such as Office apps launching other programs Yes, configured in Intune
Controlled folder access Stops untrusted apps from changing files in protected folders Yes, configured in Intune
Tamper protection Stops attackers switching off Defender antivirus protections Yes, check it is on
OneDrive and SharePoint versioning, Files Restore Rolls files back to any point in the last 30 days Yes
Microsoft 365 Backup Point-in-time restore of OneDrive, SharePoint and Exchange No, pay-as-you-go add-on
Microsoft Sentinel Correlates security signals across Microsoft and non-Microsoft sources No, consumption-billed

Included Is Not the Same as Configured

ASR rules and controlled folder access have to be deployed through Microsoft Intune device management policies. A tenant can hold the Business Premium licence and still have both switched off. That gap is worth checking before buying anything new.

Recovery has limits too. Files Restore reaches back 30 days and only covers OneDrive and SharePoint. File servers and anything outside Microsoft 365 need a separate backup. Microsoft itself recommends evaluating Microsoft 365 Backup on top of the built-in features.

‍

What to Do If You're Hit by Ransomware

If ransomware hits, isolate affected systems, keep evidence, reset compromised credentials, call in incident response, and restore only from clean backups. The order matters, because a rushed restore can let the attacker straight back in.

  1. Isolate affected systems. Disconnect them from the network rather than switching them off. CISA notes that powering down destroys evidence held in memory, so treat it as a last resort.
  2. Preserve evidence. Keep logs, alerts and the ransom note for investigators and insurers.
  3. Reset credentials and revoke sessions. Assume every account the attacker touched is compromised, starting with admin accounts.
  4. Call in incident response and your insurer. Check what cyber insurance covers before you need it, not during the incident.
  5. Report the incident. In the UK, the government's Where to Report a Cyber Incident service points you to the right agency. In the US, CISA recommends reporting to CISA or the FBI.
  6. Restore from clean backups. Close the original entry point first, then restore and reconnect in stages.

The incident response life cycle covers each phase in more depth.

Should You Pay the Ransom?

Most organisations do not. In the Verizon 2026 DBIR, 69% of ransomware victims did not pay, and the median ransom paid fell to $139,875.

Paying also carries legal risk. The US Treasury's Office of Foreign Assets Control (OFAC) strongly discourages payment and warns that paying a sanctioned group can breach sanctions law. In July 2025, the UK government confirmed plans to legislate a ban on ransom payments by public sector bodies and critical national infrastructure operators.

Whether to pay is a decision for the organisation, its insurer and its legal counsel. The UK National Cyber Security Centre (NCSC) publishes guidance for organisations weighing that choice.

‍

Final Thoughts

Ransomware defence for most 50 to 500 person businesses comes down to two questions. Are the Microsoft 365 protections you already pay for actually switched on? And is anyone watching when an attacker moves overnight?

If either answer is no, see how CyberQuell's 24/7 managed SOC monitoring and response covers the hours your team cannot. You can also book a call with Cyberquell to review your Microsoft 365 set-up.

Last Updated:
September 30, 2026

FAQs

Find answers to commonly asked questions about our cybersecurity solutions and services.

What is ransomware in simple terms?

Ransomware is malicious software that locks or encrypts an organisation's files and demands payment to unlock them. Many attackers also steal data first and threaten to publish it if the ransom goes unpaid.

‍

What is Ransomware-as-a-Service (RaaS)?

Ransomware-as-a-Service (RaaS) is a business model in which ransomware developers rent their tools to affiliates, who carry out the attacks and share the ransom. LockBit worked this way until an operation led by the UK National Crime Agency disrupted it in February 2024.

‍

How does ransomware get into a company's network?

The most common way in is an exploited vulnerability in an internet-facing system. It accounted for 31% of initial access in breaches in the Verizon 2026 Data Breach Investigations Report. Stolen credentials, phishing and phone-based pretexting are the other main routes. Patching exposed systems and using phishing-resistant multifactor authentication (MFA) address all of them.

‍

Can you recover files after a ransomware attack without paying?

Yes, if you have clean backups the attacker could not reach. Microsoft 365 can also roll OneDrive and SharePoint files back to any point in the last 30 days with Files Restore. Backups do not help when the attacker has stolen data and threatens to publish it.

‍

Should you pay a ransomware demand?

Most organisations do not: 69% of ransomware victims in the Verizon 2026 Data Breach Investigations Report did not pay. The US Treasury's Office of Foreign Assets Control (OFAC) strongly discourages payment and warns it can breach sanctions law. The decision belongs to the organisation, its insurer and its legal counsel.

‍

Can antivirus stop ransomware?

Antivirus alone is not enough, because modern attacks often use stolen credentials and legitimate admin tools that look like normal activity. Endpoint detection and response (EDR) watches behaviour and can contain a device automatically. In Microsoft 365 Business Premium, Defender for Business adds automatic attack disruption for human-operated attacks.

‍

Protect Your Business from Cyber Threats

Get in touch with our cybersecurity experts to discuss your security needs and solutions.