Cyber Defence
Cyber Security

What is Ransomware? How It Works & How to Prevent It (2026)

What is ransomware? Learn how ransomware attacks work, famous examples like WannaCry and LockBit, whether you should pay, and how to prevent ransomware with backups in 2026.

What is Ransomware? How It Works & How to Prevent It (2026)
Amit Kumar
Amit KumarEthical Hacker & Founder
8 min read

Short answer: Ransomware is a type of malware that encrypts your files or locks your device, then demands a ransom, usually in cryptocurrency, to restore access. Attackers often also steal data and threaten to leak it. The best defence is prevention plus reliable offline backups; paying is strongly discouraged.

Ransomware is one of the most damaging cyber threats facing businesses, hospitals and governments worldwide, including in India. A single attack can halt operations, encrypt years of data and cost lakhs or crores in recovery. Here is how it works and how to stop it.

How a Ransomware Attack Works

Most ransomware attacks follow three stages:

StageWhat Happens
1. Infection / entryThe attacker gets in, usually through a phishing email, a malicious attachment, stolen or weak remote-desktop (RDP) credentials, or an unpatched software vulnerability.
2. Spread and encryptionThe malware moves across the network, often disables backups and security tools, then encrypts files so they cannot be opened. Modern gangs first steal (exfiltrate) sensitive data.
3. Ransom demandA ransom note appears demanding payment in cryptocurrency within a deadline, often with a threat to leak the stolen data publicly (double extortion).

This "double extortion" model, encrypt and leak, is now standard. Some groups even add a third layer (triple extortion) by launching DDoS attacks or contacting the victim's customers directly.

Ransomware-as-a-Service (RaaS)

Modern ransomware is a business. Under the ransomware-as-a-service model, skilled developers build the malware and "rent" it to affiliates, who carry out attacks and share the profits. This industrialisation is why ransomware volume has exploded: attackers no longer need advanced coding skills, only a subscription and a target. RaaS operations run help desks, negotiation portals and data-leak sites, operating almost like legitimate software companies, but criminal ones. It also means defenders face a constant stream of new variants, so relying on signatures alone is not enough; behaviour-based detection and solid backups matter more.

Types of Ransomware

  • Crypto ransomware: encrypts your files so they cannot be opened, the most common type.
  • Locker ransomware: locks you out of the entire device rather than encrypting individual files.
  • Double-extortion ransomware: steals data before encrypting and threatens to publish it.
  • Wiper malware: disguised as ransomware but destroys data permanently, with no real recovery option.

How Ransomware Spreads

  • Phishing emails with malicious attachments or links, the number-one entry method. See what is phishing.
  • Exposed or weak RDP / remote access with guessable passwords and no MFA.
  • Unpatched vulnerabilities in operating systems and software.
  • Malicious downloads, pirated software and infected USB drives.
  • Supply-chain attacks through compromised vendors or software updates.
  • Malicious ads (malvertising) and compromised websites that trigger drive-by downloads.

Ransomware is a subset of malware, so the same hygiene that stops malware also reduces ransomware risk. Importantly, most successful ransomware attacks begin with a simple human step, someone clicking a link, opening an attachment, or reusing a weak password on an exposed remote-access service. This is why awareness and basic access controls are as important as any expensive security product.

Famous Ransomware Examples

  • WannaCry (2017): A worm-like ransomware that spread to over 200,000 systems in 150+ countries within days by exploiting a Windows SMB flaw (EternalBlue). It disrupted hospitals, factories and businesses globally, including systems in India.
  • NotPetya (2017): Disguised as ransomware but designed for destruction, causing billions of dollars in global damage.
  • LockBit: One of the most prolific ransomware-as-a-service (RaaS) operations of recent years, renting its tools to affiliates who attacked thousands of organisations worldwide.
  • Ryuk, Conti, BlackCat/ALPHV, Cl0p: Well-known groups behind large enterprise attacks and mass data-leak extortion campaigns.

Ransomware Impact on Indian Businesses

India is among the most-targeted countries for ransomware. Small and medium businesses are especially vulnerable because they often lack backups, patching and trained staff. A ransomware attack can mean days of downtime, permanent data loss, regulatory scrutiny and reputational damage. Manufacturing, healthcare, education and financial services are frequent targets. For most Indian SMEs, the recovery cost, downtime, rebuilding systems, lost business, far exceeds the ransom demand itself, which is exactly why prevention matters more than reaction.

Indian organisations also face compliance obligations. Under CERT-In directions, entities are required to report cyber incidents such as ransomware within stipulated timelines, and to maintain security logs. Failing to prepare is therefore not just an operational risk but a regulatory one. Every business, from a small clinic to a large factory, should treat ransomware readiness, backups, patching, staff training and an incident-response plan, as a basic cost of doing business online, not an optional extra. The cheapest ransomware attack is the one your backups and preparation make irrelevant.

Should You Pay the Ransom?

Security experts and law enforcement strongly advise against paying. Here is why:

  • Payment does not guarantee you get a working decryptor, many victims never recover all their data.
  • It funds and encourages more attacks, marking you as a soft target for repeat extortion.
  • Even after paying, stolen data may still be leaked or sold.
  • Paying may raise legal and compliance issues.

Instead, isolate infected systems, report the incident, and restore from clean backups. Check whether a free decryptor exists (for example via the No More Ransom project) before considering any other option.

Early Warning Signs of a Ransomware Attack

Ransomware rarely strikes instantly, attackers often lurk for days or weeks. Spotting these signs early can let you stop an attack before encryption begins:

  • Antivirus or security tools being unexpectedly disabled or uninstalled.
  • New, unknown admin accounts or unusual login activity, especially at odd hours.
  • Unexpected use of remote-access or network-scanning tools.
  • Backups failing, being deleted, or suddenly disconnected.
  • Large numbers of files being renamed, moved or accessed rapidly.
  • Test encryption of a small folder before the full attack.

If you notice these, treat it as an emergency: isolate the affected systems and involve your security team or an incident-response expert immediately.

How to Prevent Ransomware

  • Maintain offline, tested backups using the 3-2-1 rule: three copies, on two types of media, one kept offline/off-site. This is your single most important defence.
  • Patch promptly. Keep operating systems and software up to date to close known vulnerabilities.
  • Enable MFA on email, VPNs and remote access; disable or lock down exposed RDP.
  • Train staff to spot phishing, the entry point for most attacks.
  • Use endpoint protection (EDR) and network segmentation to limit spread.
  • Apply least-privilege access so a single compromised account cannot reach everything.
  • Have an incident-response plan and rehearse recovery so you are not improvising during a crisis.

What To Do During a Ransomware Attack

  • Disconnect affected devices from the network immediately to stop spread.
  • Do not pay right away; preserve evidence and the ransom note.
  • Identify the strain and check for a free decryptor.
  • Report the incident, in India, call helpline 1930 and file at cybercrime.gov.in. See how to report cyber crime in India.
  • Rebuild from clean backups and reset all credentials.

The 3-2-1 Backup Rule Explained

Because reliable backups are the ultimate ransomware defence, it is worth understanding the widely recommended 3-2-1 approach:

  • 3 copies of your important data (the original plus two backups).
  • 2 different storage types (for example an external drive and cloud storage).
  • 1 copy kept offline or off-site, disconnected from the network so ransomware cannot reach it.

Crucially, test your backups regularly. Many organisations discover, too late, that their backups were incomplete, corrupted, or also encrypted because they were left connected. A backup you have never restored from is only a hope, not a plan.

Ransomware Recovery: Realistic Expectations

Even with good preparation, recovery takes time. You must isolate infected systems, identify how the attacker got in, rebuild machines from clean images, restore data, reset every credential, and verify the threat is fully removed before reconnecting. Rushing back online without closing the original entry point often leads to re-infection. This is why having a documented, rehearsed incident-response plan, and knowing whom to call, makes the difference between a controlled recovery and a prolonged crisis.

Defending against ransomware is a core skill in modern cyber security. At Cyber Defence in Hisar, learners practise incident response, backup strategy and threat hunting in real lab environments, the capabilities organisations need most today.

FAQ

What is ransomware in simple words?

Ransomware is malicious software that locks or encrypts your files and demands payment to restore access, often while also threatening to leak stolen data.

How does ransomware infect a computer?

Most often through phishing emails, weak or exposed remote access, unpatched software vulnerabilities, and malicious downloads or USB drives.

Should I pay the ransom?

No. Experts and law enforcement advise against paying because it does not guarantee recovery, funds further crime, and may not stop your data from being leaked. Restore from backups instead.

What is the best protection against ransomware?

Reliable, tested, offline backups combined with prompt patching, MFA, phishing awareness and endpoint protection. Backups let you recover without paying.

What were WannaCry and LockBit?

WannaCry was a 2017 worm-like ransomware that infected over 200,000 systems worldwide. LockBit was a major ransomware-as-a-service operation that powered thousands of attacks by affiliates.

How can I learn to defend against ransomware?

Take a hands-on cyber security or ethical hacking course covering incident response, backups and threat detection. Cyber Defence in Hisar trains students under CEH-certified instructors.

Want to build the skills to stop ransomware and launch a cyber security career? Explore our courses, a cyber security course (approx. 3-4 months, around Rs.15,000) and an ethical hacking course (around 6 months, approx. Rs.60,000), led by founder Amit Kumar (CEH, CRTA). Cyber Defence is an ISO-certified, GeM-registered institute in Hisar, Haryana. Call +91-75175-72000 to enrol.

Talk to a Cyber Defence Expert

Get a free consultation on cybersecurity, training and certifications. Our team responds within 10 minutes during business hours.