Ransomware

term

security

An intrusion that ends in encrypting the victim's data for payment - and, in its modern form, in copying that data out first so the threat to publish survives any recovery.

The operational detail that matters for defence is the order: capable operators locate and destroy backups before encrypting production, because the recovery path is what determines whether anyone pays. So backup design became an adversarial problem rather than an availability one. The double form splits the incident into two decisions - restore, which good backups answer completely, and disclosure, which they do not answer at all and which runs on regulatory clocks of its own.

Also known as: double extortion, encryption attack, ransomware-as-a-service, leak site

All glossary entries