Ransomware
Malware that encrypts an organisation's files or locks its systems, then demands a payment to restore access.
Definition
Ransomware is a category of malicious software that encrypts an organisation's files or locks access to its systems and then demands a ransom payment, usually in cryptocurrency, in exchange for a decryption key or restored access. Modern ransomware often combines encryption with data theft, a tactic known as double extortion, where attackers also threaten to publish or sell stolen data if the victim refuses to pay. Because so many ransomware incidents begin with a single employee clicking a malicious link or attachment, ransomware is as much a human risk problem as a technical one.
A typical ransomware attack unfolds in stages. First the attacker gains an initial foothold, most commonly through a phishing email, a stolen or weak credential, or an unpatched internet-facing system. Once inside, they move laterally across the network, escalate privileges, and quietly identify and disable backups. Only then do they deploy the encryption payload, often outside business hours, and present a ransom note with a deadline and payment instructions. The encryption itself is the final and most visible step of an intrusion that may have been underway for days or weeks.
The business impact reaches well beyond the ransom figure. Operations can halt entirely while systems are unusable, and recovery can take weeks even when backups exist. For regulated organisations in Indonesia there are added consequences: a ransomware event involving personal data can trigger breach notification duties under UU PDP (Law 27/2022) and reporting expectations from sector regulators such as OJK and BSSN. Paying a ransom offers no guarantee of clean recovery, may fund further criminal activity, and can itself create legal and reputational exposure.
Defence is layered rather than a single control. Offline, tested, immutable backups are the last line that lets an organisation refuse to pay. Prompt patching, network segmentation, least-privilege access, and endpoint detection limit how far an intruder can spread. But because the most common entry point is a person, the highest-leverage controls are often human: multi-factor authentication to blunt stolen credentials, and security awareness training plus realistic phishing simulation to reduce the chance that the first malicious email ever gets clicked.
At a glance
- Severity
- Critical
- Prevalence
- Very common
- Primary targets
- Organizations of any size, especially those with weak backups or unpatched systems
How it works
- 1
Initial access: the attacker gains a foothold, most commonly through a phishing email, a stolen or weak credential, or an unpatched internet-facing system.
- 2
Lateral movement: once inside, they move across the network and escalate privileges to reach more valuable systems.
- 3
Backup sabotage: they quietly identify and disable backups so the victim cannot simply restore from a clean copy.
- 4
Data theft: in double-extortion attacks, they exfiltrate sensitive data before encrypting anything.
- 5
Encryption and demand: the attacker deploys the encryption payload, often outside business hours, and presents a ransom note with a deadline and payment instructions.
Warning signs
- Files suddenly renamed with unfamiliar extensions or become inaccessible
- A ransom note appearing on the desktop or in affected folders
- Unusual, large-scale file access or encryption activity noticed by IT
- Backups missing, deleted, or failing unexpectedly
- Systems behaving slowly or applications failing to open
How to defend
- Maintain offline, tested, immutable backups as a last line of defense
- Patch internet-facing systems and software promptly
- Apply network segmentation and least-privilege access to limit spread
- Enable multi-factor authentication to blunt stolen credentials
- Run phishing simulations and security awareness training to reduce the chance the first malicious email gets clicked
Real-world example
An employee at an Indonesian logistics company opens what looks like a routine shipping invoice attachment. Days later, the attacker, already inside the network after disabling backups, encrypts every file server outside business hours and leaves a ransom note demanding payment in cryptocurrency, halting operations until systems can be rebuilt.
How Claro helps
Most ransomware starts with a phishing email, so the cheapest place to break the chain is before anyone clicks. Claro runs realistic phishing simulations and just-in-time training that build employee instinct for the lures that deliver ransomware, then measures that behaviour over time through risk scoring and human risk management dashboards. Instead of reporting how many people completed a course, Claro shows whether your workforce is genuinely getting harder to phish, and gives Indonesian regulated organisations the evidence trail to satisfy OJK, BSSN, and UU PDP expectations.
Frequently asked questions
What is Ransomware?
Ransomware is malicious software that encrypts a victim's files or systems and demands a payment, usually in cryptocurrency, in exchange for restoring access. Modern variants often steal the data first and threaten to publish it.
Should an organization pay a ransomware demand?
Paying offers no guarantee of clean recovery, may fund further criminal activity, and can create legal and reputational exposure. Most security guidance recommends against paying and instead relying on tested, immutable backups to restore operations.
How does ransomware usually get into an organization?
Most incidents begin with a phishing email, a stolen or weak credential, or an unpatched internet-facing system. The encryption itself is often the final and most visible step of an intrusion that may have been underway for days or weeks.
What is double extortion in ransomware attacks?
Double extortion combines file encryption with data theft. Attackers threaten to publish or sell the stolen data if the victim refuses to pay, adding pressure even for organizations that can restore from backup without paying.
Does having backups guarantee protection from ransomware?
Backups are essential but not sufficient on their own. Attackers actively search for and disable backups before encrypting, so backups must be offline or immutable to survive an attack, and recovery can still take weeks.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Credential Harvesting
Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Security Awareness Training
Security awareness training is structured education that teaches employees to recognize and respond to cyber threats such as phishing, social engineering, and unsafe data handling.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo