Ransomware

Last Updated Sep 24, 2026

In One Sentence

Ransomware is malicious software that disrupts access to systems or data and supports demands for payment to restore access or prevent disclosure.

Definition

Ransomware is a form of malware used in extortion. It may encrypt files, lock systems, steal sensitive information, or combine these effects. Attackers often demand cryptocurrency, but cryptocurrency is a payment channel rather than the cause of the compromise. An encrypted wallet backup can become inaccessible during an incident even though the blockchain itself continues to operate normally.

How It Works

Ransomware can enter through phishing, compromised software, exposed services, or stolen access credentials. Once an organization is affected, business operations and backups may also be disrupted. Some incidents involve data theft and threatened publication even when usable backups exist. Loss of local wallet files is distinct from theft of private keys: an attacker who obtains usable keys may transfer assets regardless of whether the victim can restore the device.

Key Considerations

Maintain tested offline or appropriately isolated backups, update software, restrict unnecessary access, and use strong authentication. If an incident is suspected, isolate affected devices and seek qualified incident-response support while preserving relevant evidence. Avoid connecting clean backups to a still-compromised environment. Paying a ransom does not guarantee decryption, deletion of stolen data, or the absence of further demands. Recovery should address the underlying compromise and any exposed credentials; restoring files alone does not prove that the system is trustworthy again.