Definition · Known Vulnerabilities (CVEs)
What is Ransomware?
Ransomware began as straightforward extortion through encryption: files are made unreadable and a key is sold back. Most contemporary operations add data theft before encryption, so that a victim with good backups still faces the threat of publication — an approach usually described as double extortion. Some intrusions now skip encryption altogether and rely on the stolen data alone.
How intrusions typically begin
Initial access commonly comes from a small set of routes, most of them external:
- Exploitation of a vulnerability in an internet-facing device, particularly VPN appliances, remote access gateways, and file transfer products
- Valid credentials, whether phished, purchased, or obtained by credential stuffing
- Exposed remote access services, including RDP reachable from the internet
- Compromise of a supplier or managed service provider with access into the environment
Access is frequently obtained by one group and sold on to another that carries out the extortion, which is why exposure and extortion can be separated by weeks.
Why external exposure is the decisive factor
The routes above are almost all things an outsider can see. An unpatched edge appliance, an RDP port left open during a migration, a forgotten VPN concentrator at an acquired subsidiary — each is discoverable by the same mass scanning that attackers already run continuously. Reducing what is reachable, and knowing quickly when something new appears, addresses the majority of these entry points directly.
Practical priorities
Patch internet-facing software first, with anything in the KEV catalogue treated as urgent. Require multi-factor authentication on every remote access path. Keep offline or immutable backups and test restoration. Maintain an accurate external inventory so that an exposed service is noticed by you before it is noticed by someone else.
Related concepts
Ransomware is one outcome pursued by financially motivated threat actors, depends on an attack vector into the estate, and is the clearest argument for disciplined patch management and continuous external attack surface management.