WorkNest

Blog

What is ransomware - a quick guide with videos

Find out what ransomware is, how attacks work & types of attack to help you get started with keeping ransomware out of your business.

Background Image
  • Threat actors will use an attack method such as phishing which relies on users downloading and opening a link or attachment. Plugging in malware infected devices or visiting websites that execute drive by downloads can also introduce ransomware to a system.

  • Ransomware is a type of malware that unlike those used in stealth attacks, makes itself known by spreading rapidly throughout the network, encrypting endpoint user access, and bringing business activities to a halt.

  • Users will be notified via the ransomware itself which displays a message on the screen informing users that their data has been encrypted and demanding payment in return for a decryption key needed to restore files.

  • If the user decides to pay the ransomware to recover their data, they should be provided with a decryption key for unlocking their files. However, they may not receive the key even after payment, or their data may be sold or stolen by attackers to demand further payments.

Most ransomware works by encrypting files and locking users out of systems, but sometimes hackers may bluff an attack with scareware, which flags up warning signs that a system has been hacked and tries to sell fake security software to fix non-existent problems. Another way hackers deploy ransomware is by stealing confidential business files and information and threatening to leak them on the dark web, known as doxing. Doxware also encrypts files and can lead to double or triple extortion attacks where hackers demand multiple payments to keep stolen data from being leaked in the future.

Ransomware often gains notoriety for proliferating throughout networks and infecting multiple businesses. Some notable attacks include WannaCry, an attack which infected thousands of computers worldwide in 2017, and more recently the MOVEit attack of 2023, which used an existing vulnerability in widely used software to launch a zero-day attack against over 600 businesses, including high profile companies Shell, British Airways, and the US Department of Energy.

Talk to an expert

Share your challenge with us and we’ll help you find the right level of support for your business.

Your certified partner

Proven standards, trusted expertise, complete peace of mind

Award logo 1
Award logo 2
Award logo 3
Award logo 4
Award logo 5
Award logo 6
Award logo 7
Worknest logo
© 2020-2026 WorkNest. All rights reserved. (888) 243-3110