Ransomware
Malware that encrypts the victim's data and demands payment to release it. It now adds the threat of publishing what was stolen if no payment is made.
Full definition
Ransomware is malware that encrypts the victim's files and systems and demands a payment, almost always in cryptocurrency, in exchange for the decryption key. It can paralyze a company's entire operation in hours.
The model evolved into double extortion: before encrypting, the attacker steals the data and threatens to publish it if no payment arrives, which cancels the defense of having backups. It also operates as an industry: developers rent the ransomware to affiliates who execute the attacks, and initial access is often bought from brokers who obtained it through phishing or leaked credentials.
Preparation combines tested and isolated backups, network segmentation, patching and a rehearsed response plan, together with the work on the human factor that closes the most used way in.
Related terms
Malware
Any software designed to damage, spy on or take control of a system without authorization. It almost always needs a person to let it in.
Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Leaked credentials
Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.
Data exfiltration
Unauthorized transfer of information from the victim's systems to the attacker. It is the end goal of most intrusions.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.