A Hospital Goes Dark in 90 Seconds

In 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by the ALPHV/BlackCat ransomware group. The attack disrupted pharmacy operations, delayed patient care, and exposed the protected health information of roughly 100 million individuals. UnitedHealth Group, Change Healthcare's parent company, reported the incident cost over $870 million in the first quarter alone.

If you're asking what is ransomware, that incident is your answer in human terms: systems locked, operations frozen, and real people harmed. But let me break it down more precisely so you understand the mechanics, the money, and what actually stops these attacks.

What Is Ransomware, Exactly?

Ransomware is a type of malicious software that encrypts your files or locks you out of your systems entirely. The threat actor then demands a ransom payment — usually in cryptocurrency — in exchange for a decryption key. Sometimes you pay and get your data back. Sometimes you pay and get nothing.

Modern ransomware goes further. Most groups now practice "double extortion." They steal your data before encrypting it, then threaten to publish it on leak sites if you don't pay. Some have moved to triple extortion, adding DDoS attacks or contacting your customers directly to pressure you.

According to IBM's 2024 Cost of a Data Breach Report, the average cost of a data breach reached $4.88 million globally. Ransomware-specific breaches consistently land above that average. The FBI's Internet Crime Complaint Center (IC3) received thousands of ransomware complaints annually, with adjusted losses climbing every year.

How Ransomware Actually Gets Into Your Network

I've investigated dozens of ransomware incidents. In my experience, the initial access almost always falls into one of three categories.

Phishing Emails: Still the #1 Entry Point

The Verizon 2024 Data Breach Investigations Report found that the human element was involved in 68% of breaches. Phishing and social engineering remain the most reliable way for attackers to get a foothold. One employee clicks a malicious link, enters credentials on a spoofed login page, and the attacker is inside your network.

This is why phishing awareness training for organizations isn't optional — it's a frontline defense. Phishing simulation exercises teach your employees to recognize credential theft attempts before they become full-blown incidents.

Exploiting Unpatched Vulnerabilities

Ransomware groups actively scan for known vulnerabilities in internet-facing systems. VPN appliances, remote desktop services, and outdated web servers are prime targets. The Clop ransomware group exploited a zero-day vulnerability in MOVEit Transfer software in 2023, compromising hundreds of organizations in weeks.

If your patching cadence is measured in months, you're leaving the front door open.

Stolen or Weak Credentials

Credential theft through infostealer malware and dark web marketplaces gives attackers valid usernames and passwords. Without multi-factor authentication, those credentials provide direct access — no phishing required.

The Anatomy of a Ransomware Attack

Understanding what is ransomware means understanding the kill chain. Here's what I typically see when reconstructing an attack timeline:

  • Initial Access (Day 1): Attacker gets in via phishing email, exposed RDP, or a vulnerable appliance.
  • Persistence & Reconnaissance (Days 2-7): The attacker installs backdoors, maps Active Directory, identifies backup systems, and escalates privileges.
  • Data Exfiltration (Days 5-14): Sensitive data is copied to attacker-controlled infrastructure for double extortion leverage.
  • Encryption & Ransom Note (Day 14+): The ransomware payload deploys across the network, often during off-hours. Systems go dark. A ransom note appears on every machine.

The dwell time — the period between initial access and encryption — averages days to weeks. That window is your best chance to detect and stop the attack. Most organizations miss it entirely because they lack the monitoring to catch lateral movement.

The $4.88M Lesson Most Organizations Learn Too Late

Here's what actually happens after encryption. Your IT team discovers locked systems, usually on a Monday morning. Email is down. Business applications are offline. Backups may or may not be intact — attackers increasingly target backup infrastructure first.

Then comes the ransom demand. It might be $50,000 for a small business. It might be $20 million for a hospital system. You contact your cyber insurance carrier, your legal team, and potentially law enforcement. The CISA StopRansomware initiative provides incident response resources, but by this point, you're already in crisis mode.

The real cost isn't just the ransom. It's the business interruption, the forensic investigation, the legal liability, the regulatory fines, and the reputational damage that follows you for years.

Should You Pay the Ransom?

The FBI's official position is clear: don't pay. Payment funds criminal operations and provides no guarantee of data recovery. In my experience, about half the organizations that pay still face data leaks or incomplete decryption.

That said, I've seen situations where a hospital with lives on the line or a manufacturer facing millions in daily losses makes the difficult decision to pay. There's no judgment-proof answer. But if your strategy depends on paying ransoms, you don't have a strategy — you have a prayer.

Seven Defenses That Actually Work Against Ransomware

Forget the vendor pitches. These are the controls I've seen make a measurable difference in real environments.

1. Security Awareness Training

Your employees are your largest attack surface and your most effective sensor network. Regular cybersecurity awareness training teaches them to spot social engineering tactics, suspicious attachments, and credential theft attempts. Training should be continuous, not annual.

2. Multi-Factor Authentication Everywhere

MFA stops the vast majority of credential-based attacks. Deploy it on email, VPN, remote desktop, cloud services, and admin consoles. Prioritize phishing-resistant methods like FIDO2 keys over SMS-based codes.

3. Immutable, Tested Backups

Your backups must be air-gapped or immutable — meaning attackers can't encrypt or delete them. Test your restoration process quarterly. A backup you've never tested is a backup that doesn't exist.

4. Network Segmentation

Flat networks let ransomware spread from a single compromised workstation to every server in minutes. Segment your network so that a breach in one zone doesn't become an enterprise-wide catastrophe. This aligns with NIST Cybersecurity Framework principles and zero trust architecture.

5. Endpoint Detection and Response (EDR)

Traditional antivirus won't catch modern ransomware. EDR solutions monitor for behavioral indicators — unusual file encryption patterns, credential dumping, lateral movement — and can isolate compromised endpoints automatically.

6. Aggressive Patch Management

Patch critical vulnerabilities within 48 hours. Prioritize internet-facing systems and anything in CISA's Known Exploited Vulnerabilities catalog. If you can't patch, mitigate or isolate.

7. Incident Response Plan

Have a written, practiced incident response plan. Run tabletop exercises at least twice a year. When ransomware hits, the worst time to figure out your plan is in the middle of the crisis.

Ransomware in 2026: What's Changed

Ransomware groups now operate like businesses. They have affiliate programs, customer service portals, and negotiation teams. Ransomware-as-a-Service (RaaS) platforms let low-skilled threat actors launch sophisticated attacks using toolkits built by experienced developers.

AI-generated phishing emails are making social engineering harder to detect. Deepfake voice calls impersonating executives have been used to authorize wire transfers and disable security controls. The barrier to entry keeps dropping while the potential payoff keeps climbing.

Your defense has to evolve at least as fast as the threat.

Your Next Step Isn't Optional

Now you know what is ransomware, how it works, and what stops it. The gap between knowing and doing is where most organizations get burned. Start with the basics: train your people, enforce MFA, test your backups, and build an incident response plan you've actually rehearsed.

If you're looking for a starting point, explore the cybersecurity awareness training program at computersecurity.us and launch phishing simulations for your team. The organizations that survive ransomware aren't the ones with the biggest budgets — they're the ones that prepared before the ransom note appeared on their screens.