Ransomware Defined in Plain Terms
Ransomware is malicious software that locks an organisation out of its own systems or data usually by encrypting files until a ransom is paid. Modern attackers also steal the data first and threaten to publish it, so the extortion works even when backups restore the files.
The word describes a crime as much as a piece of code. Behind most attacks sits an organised group running extortion at scale. The EU cyber agency ENISA called ransomware the most impactful cybercrime threat in its 2025 threat landscape and found it involved in 81.1% of cybercrime incidents targeting EU organisations.
The pressure is rising. Blockchain analysts at Chainalysis counted nearly 8,000 organisations named on criminal leak sites in 2025 about 50% more than the year before and the most active year on record for claimed victims. Only 28% of those victims paid so attackers now compensate with volume and have shifted toward smaller organisations.
Sweden has felt this directly. One attack on the HR supplier Miljödata in August 2025 disrupted services across roughly 200 of the country’s 290 municipalities. Understanding how ransomware works has become part of running an organisation.
How a Ransomware Attack Unfolds
A ransomware attack is a sequence that ends in encryption. A typical intrusion runs through five stages.
- Get in: Through a phishing email, a stolen password or an unpatched system exposed to the internet.
- Escalate: The attacker becomes an administrator, creates new accounts and switches off security tools.
- Spread: The intrusion moves from one machine to the servers that matter including the backups.
- Steal: Sensitive data leaves the network quietly ready for the leak site.
- Extort: Files are encrypted, a ransom note appears and a deadline starts.
The entry points are unglamorous. Across the intrusions ENISA analysed for its 2025 report, phishing drove about 60% and the exploitation of known software flaws another 21.3%. Stolen credentials for VPN and remote desktop services complete the picture. Finland’s National Cyber Security Centre tied a 2024 wave of Akira attacks to unpatched VPN devices that lacked multi-factor authentication.
The economics explain the volume. Ransomware as a service splits the work. A core group develops the malware and the payment infrastructure while affiliates break in and take a share of each ransom. Initial access brokers sell ready-made footholds into company networks, at an average of about 439 dollars per access in early 2026 according to figures Darkweb IQ shared with Chainalysis.
The FBI identified 63 new ransomware variants in 2025 alone. Nothing about the supply side is slowing down which is why every defence has to assume the first line will sometimes fail.
Types of Ransomware Attacks
The main types of ransomware differ in what they hold hostage and how they apply pressure. Most modern incidents combine several of these at once.
- Crypto ransomware: Encrypts files and demands payment for the decryption key. WannaCry remains the best-known example.
- Locker ransomware: Locks the whole screen or device rather than individual files. More common against consumers than organisations.
- Double extortion: Steals data before encrypting it and threatens publication on a leak site. Qilin and Akira both run this model and it is now the norm.
- Triple extortion: Adds a third lever such as DDoS attacks or direct calls to the victim’s customers and patients.
- Extortion without encryption: Skips the malware and simply steals data, betting that the threat of a leak is enough.
- Wipers in disguise: Destructive malware dressed up with a ransom note. The 2017 NotPetya outbreak looked like ransomware but was built to destroy data.
Ransomware as a service is the business model underneath most of these. The operator builds the encryptor, the leak site and the negotiation portal, then rents the kit to affiliates. Qilin affiliates reportedly keep up to 80 to 85% of each ransom according to the US Center for Internet Security, and the UK National Crime Agency identified 194 affiliates when it seized LockBit’s platform in 2024.
The 82 distinct variants ENISA observed against EU organisations in a single year come from this rental economy. Names change constantly. The playbook barely does.
The Business Impact of Ransomware
The ransom is rarely the biggest number. Downtime is. When a cyber attack halted Jaguar Land Rover’s production lines from late August 2025, the UK’s Cyber Monitoring Centre put the financial impact at an estimated £1.9 billion across more than 5,000 organisations and described it as the most economically damaging cyber event to hit the UK. Production only returned to normal levels in mid-November.
Service organisations feel the same force as weeks of manual workarounds. Restoration after the Akira attack on Tietoevry’s Swedish data centre in January 2024 stretched over weeks while universities and government agencies ran payroll on backup routines. Synnovis put the cost of the 2024 attack on its pathology services above £32 million.
The payment picture has improved for defenders without shrinking the threat. Chainalysis tracked about 820 million dollars in ransom payments in 2025, down for a second year from the 2023 record of roughly 1.25 billion dollars and only 28% of victims paid. The median payment still jumped to almost 60,000 dollars and claimed attacks rose by half.
Two costs sit outside every spreadsheet. A breach of personal data brings regulatory exposure as the Miljödata leak that affected more than 1.5 million people shows. When hospitals are hit, the price is measured in patient harm.
The FBI notes that the 32 million dollars of ransomware losses reported to it in 2025 exclude downtime, lost business and recovery costs, so official loss figures understate the damage.
Real-World Ransomware Cases
Five incidents show how the same crime plays out in different settings. Each ended with a clear lesson.
WannaCry, the Worm That Hit 150 Countries
On 12 May 2017 WannaCry ransomware spread itself through a Windows file-sharing flaw using the leaked EternalBlue exploit. Europol called the outbreak unprecedented and estimated around 200,000 infected computers across 150 countries within days.
The UK’s NHS was among the worst hit. About a third of hospital trusts and some 595 GP practices were disrupted, roughly 19,000 appointments were cancelled and the Department of Health and Social Care later estimated the cost at £92 million. No NHS organisation paid the ransom and a researcher’s kill-switch domain stopped the spread the same day.
Microsoft had patched the flaw two months earlier so every infected machine was running software that could have been updated in March. The US and UK later attributed the attack to North Korea, but the operational lesson stands regardless of the attacker. Patch fast especially anything reachable from the internet.
Kaseya and Coop Sweden, the Supply Chain Attack
On 2 July 2021 the REvil gang pushed ransomware through a vulnerability in Kaseya VSA, an IT management tool, reaching up to 1,500 businesses in at least 17 countries. The gang demanded 70 million dollars for a universal decryptor.
In Sweden the visible victim was Coop. Most of its roughly 800 supermarkets closed for several days because the supplier running its point-of-sale systems, Visma Esscom, was caught in the attack and the tills stopped working.
Coop was never the target and its own network was not breached. The stores closed anyway which is why supplier contingency plans belong in every continuity exercise.
Tietoevry and Akira, Weeks of Disruption in Sweden
During the night of 19 to 20 January 2024 the Akira group encrypted virtualisation and management servers in one of Tietoevry’s Swedish data centres. The blast radius was national. The Primula payroll service used by a majority of Swedish universities and around 30 government authorities went down. So did Filmstaden’s ticketing, the retailers Rusta and Granngården and healthcare systems in Uppsala County.
Restoration stretched over weeks with affected organisations falling back on manual routines. Tietoevry never disclosed the exact entry route. Finland’s National Cyber Security Centre had warned that month that the ongoing Akira wave was breaking in through unpatched Cisco VPN devices that lacked multi-factor authentication, a flaw patched in autumn 2023.
Two controls close that door. Patch internet-facing VPN devices as a priority and require multi-factor authentication on every remote login without exception.
Synnovis and Qilin, Ransomware in the Hospital Lab
On 3 June 2024 the Qilin ransomware group attacked Synnovis, the pathology provider for NHS hospitals in southeast London. Blood testing slowed to manual pace across major hospitals. More than 10,000 appointments were disrupted and 1,710 operations postponed at King’s College Hospital and Guy’s and St Thomas’ trusts.
No ransom was paid and roughly 400GB of stolen data, including patient information, was published. In June 2025 King’s College Hospital NHS Foundation Trust confirmed that one patient died unexpectedly during the incident and that a long wait for a blood test result caused by the attack was a contributing factor. Synnovis has put its own costs above £32 million.
The entry route has never been publicly confirmed, so honesty matters more than a neat moral here. What the incident proves is the value of limiting blast radius. Segmented systems and rehearsed manual fallbacks decide whether a supplier outage is an inconvenience or a clinical emergency.
Miljödata, One Supplier and 200 Municipalities
On Saturday 23 August 2025 Miljödata, an HR systems supplier used by about 80% of Swedish municipalities detected an intrusion. The attackers demanded 1.5 bitcoin. Systems for handling medical certificates, rehabilitation cases and workplace injuries went down across roughly 200 of Sweden’s 290 municipalities plus regions and universities.
In mid-September the stolen data appeared on the dark web and the Swedish Prosecution Authority confirmed that more than 1.5 million people were affected. A group calling itself Datacarry claimed the attack and the leak ranks among the largest known personal data exposures in Swedish history.
For every organisation that outsources HR, payroll or IT, the questions write themselves. What data does the supplier hold, does the contract require security measures you can verify and what is the plan for the week their systems are gone?
Ransomware and Compliance
For organisations in scope of NIS2, ransomware readiness is now written into Swedish law. Cybersäkerhetslagen (SFS 2025:1506) came into force on 15 January 2026 and transposes the directive. Article 20 of NIS2 places responsibility with the management body and supervisory authorities can hold board members personally accountable. Read more in the guide to NIS2 in Sweden.
Article 21 lists the measures a ransomware programme must cover.
- Continuous monitoring (Article 21.2a): Detection capability that runs around the clock.
- Incident handling (Article 21.2b): A tested plan for containing and reporting attacks.
- Business continuity (Article 21.2c): Backups and crisis procedures that keep services running.
- Supply-chain security (Article 21.2d): Security requirements on the suppliers whose outage would stop you.
- Awareness training (Article 21.2g): Staff who can recognise the phishing attempts that start most intrusions.
Fines reach €10 million or 2% of global turnover for essential entities and €7 million or 1.4% for important entities.
The reporting clock is strict. An organisation in scope must send an early warning to MCF (formerly MSB) and its sector authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours and a final report within one month.
Ransomware that steals personal data is also a breach under GDPR which means notifying IMY within 72 hours under Article 33. Financial entities carry parallel duties under DORA Article 17, supervised by Finansinspektionen. See the guides to GDPR compliance and DORA compliance.
How to Spot a Ransomware Attack
By the time files start renaming themselves, the attack is days or weeks old. Encryption is the finale. The useful warning signs come earlier. Most of them live in logs rather than inboxes.
- Odd remote logins: VPN or remote desktop sessions at strange hours or from unfamiliar locations.
- New privileged accounts: Administrator accounts nobody remembers creating.
- Security tools going quiet: Antivirus or endpoint agents disabled, uninstalled or silenced.
- Backups being touched: Deleted shadow copies, wiped backup jobs or unexpected logins to backup consoles.
- Unfamiliar software: Remote access or file-transfer tools appearing on machines that never needed them.
- Unusual outbound traffic: Large transfers to unknown destinations, often the data theft in progress.
Late signs are unmistakable. Files with new extensions, ransom notes in every folder and systems locking one after another. At that point the job is containment, so disconnect affected machines from the network but do not switch them off, because memory can hold evidence and sometimes encryption keys.
The honest caveat is that none of this is reliably visible to the naked eye. Attackers use legitimate credentials and legitimate tools precisely so their activity blends into normal administration. Spotting the early stages takes continuous monitoring of endpoints and logs which is a staffing question as much as a tooling one. That is the problem managed detection and response exists to solve.
How to Defend Against Ransomware
No single product stops ransomware. The organisations that recover well combine trained people, rehearsed processes and a short list of technical controls done thoroughly.
- Train and rehearse: Phishing starts about 60% of intrusions, so teach staff what current lures look like and make reporting one click with no blame attached.
- Require multi-factor authentication everywhere: Every VPN, remote desktop, email and admin login gets it. The Akira wave broke in where it was missing.
- Patch on a clock: Prioritise anything reachable from the internet. WannaCry’s patch had been available for two months.
- Keep offline, tested backups: Attackers hunt online backups and delete them. Keep at least one copy offline or immutable and rehearse a full restore before you need it.
- Segment the network: Separate critical systems and backups from the general network so one compromised machine cannot reach everything.
- Monitor and respond around the clock: The early signs above only matter if someone sees them in time, whether an internal team or a service.
- Set supplier requirements: Contract for security measures, breach notification and continuity plans with every supplier whose outage would stop you. Coop and 200 municipalities learned this the hard way.
- Write and rehearse the incident plan: Decide in advance who isolates systems, who calls the police and CERT-SE and who owns the 24-hour report to MCF.
Plan never to pay. Only 28% of victims paid in 2025 and the UK National Crime Agency found data from paying victims still sitting on LockBit’s seized servers, so payment buys neither deletion nor certainty. Before any decision, check the free decryptors at No More Ransom, the Europol-backed project that has helped more than six million victims and involve the police early.
Start with the two controls that would have stopped the biggest cases in this guide. Turn on multi-factor authentication for every remote login and patch your internet-facing systems this week.



