Ransomware
Definition
Malware that encrypts or exfiltrates data and demands payment for restoration or suppression. Modern ransomware incidents often combine an availability impact (encrypted systems) with a confidentiality impact (stolen data), triggering multiple concurrent response obligations.
- Effect
- Encrypts or exfiltrates data, demands payment
- Dual impact
- Availability loss plus confidentiality breach
- Common vector
- Phishing, exposed RDP, unpatched vulnerabilities
- Response scope
- Triggers both recovery and breach-notification obligations
Common questions
Why do modern ransomware incidents trigger multiple response obligations at once?+
Attackers now commonly steal data before encrypting it, a tactic called double extortion. That means the victim must handle both restoring encrypted systems and treating the incident as a data breach, which can carry separate legal notification duties.
What forensic evidence typically survives a ransomware attack for investigators to examine?+
Log files, network traffic captures, memory images taken before shutdown, and the ransom note or malware binary itself can all yield indicators of the intrusion vector, the ransomware family, and sometimes the attacker's infrastructure, even after files are encrypted.
Related terms
- Alert
- A notification generated when an event or pattern of events matches a detection rule. Alerts require triage to determine whether they represent...
- Data Breach
- An incident in which an unauthorised party gains access to, copies, or discloses protected data. Breaches trigger specific legal notification requirements under...
- Insider Threat
- An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
- Security Event
- Any observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast...
- Security Incident
- An event or chain of events that violates an organisation's security policy or credibly threatens the confidentiality, integrity, or availability of information...