Threats & attacks

What is Ransomware?

The business guide to ransomware attacks, the damage they cause and the controls and reporting duties that protect your organisation.

What is Ransomware
Key takeaways
  • Ransomware locks organisations out of their own systems or data and demands payment, and modern attacks steal the data first so the leak threat works even when backups restore the files.
  • ENISA called ransomware the most impactful cybercrime threat in the EU in 2025, involved in 81.1% of cybercrime incidents targeting EU organisations.
  • Claimed ransomware victims rose about 50% in 2025 to nearly 8,000 organisations named on leak sites, the most active year on record, while only 28% of victims paid, per Chainalysis.
  • Most attacks start small. Phishing drove about 60% of the intrusions ENISA analysed and exploited software flaws another 21.3%, with unprotected remote logins close behind.
  • Ransomware as a service industrialised the crime. Network access sells for around 439 dollars and the FBI identified 63 new ransomware variants in 2025 alone.
  • WannaCry ransomware infected around 200,000 computers across 150 countries in 2017 using a flaw patched two months earlier, costing the NHS an estimated £92 million.
  • Qilin’s 2024 attack on NHS pathology provider Synnovis postponed 1,710 operations, and an NHS investigation found the attack contributed to one patient’s death.
  • Sweden has been hit through its suppliers three times. Coop’s stores closed in 2021, Tietoevry’s outage ran for weeks in 2024 and the 2025 Miljödata breach reached roughly 200 municipalities and more than 1.5 million people.
  • Cybersäkerhetslagen, in force since 15 January 2026, requires an early warning to MCF (formerly MSB) within 24 hours, a full notification within 72 hours and a final report within one month.
  • Paying guarantees nothing. The UK NCA found data from paying victims still on LockBit’s servers. Multi-factor authentication, fast patching and offline tested backups do the real work.

Ransomware Defined in Plain Terms

Ransomware is malicious software that locks an organisation out of its own systems or data usually by encrypting files until a ransom is paid. Modern attackers also steal the data first and threaten to publish it, so the extortion works even when backups restore the files.

The word describes a crime as much as a piece of code. Behind most attacks sits an organised group running extortion at scale. The EU cyber agency ENISA called ransomware the most impactful cybercrime threat in its 2025 threat landscape and found it involved in 81.1% of cybercrime incidents targeting EU organisations.

The pressure is rising. Blockchain analysts at Chainalysis counted nearly 8,000 organisations named on criminal leak sites in 2025 about 50% more than the year before and the most active year on record for claimed victims. Only 28% of those victims paid so attackers now compensate with volume and have shifted toward smaller organisations.

Sweden has felt this directly. One attack on the HR supplier Miljödata in August 2025 disrupted services across roughly 200 of the country’s 290 municipalities. Understanding how ransomware works has become part of running an organisation.

How a Ransomware Attack Unfolds

A ransomware attack is a sequence that ends in encryption. A typical intrusion runs through five stages.

  • Get in: Through a phishing email, a stolen password or an unpatched system exposed to the internet.
  • Escalate: The attacker becomes an administrator, creates new accounts and switches off security tools.
  • Spread: The intrusion moves from one machine to the servers that matter including the backups.
  • Steal: Sensitive data leaves the network quietly ready for the leak site.
  • Extort: Files are encrypted, a ransom note appears and a deadline starts.

The entry points are unglamorous. Across the intrusions ENISA analysed for its 2025 report, phishing drove about 60% and the exploitation of known software flaws another 21.3%. Stolen credentials for VPN and remote desktop services complete the picture. Finland’s National Cyber Security Centre tied a 2024 wave of Akira attacks to unpatched VPN devices that lacked multi-factor authentication.

The economics explain the volume. Ransomware as a service splits the work. A core group develops the malware and the payment infrastructure while affiliates break in and take a share of each ransom. Initial access brokers sell ready-made footholds into company networks, at an average of about 439 dollars per access in early 2026 according to figures Darkweb IQ shared with Chainalysis.

The FBI identified 63 new ransomware variants in 2025 alone. Nothing about the supply side is slowing down which is why every defence has to assume the first line will sometimes fail.

Types of Ransomware Attacks

The main types of ransomware differ in what they hold hostage and how they apply pressure. Most modern incidents combine several of these at once.

  • Crypto ransomware: Encrypts files and demands payment for the decryption key. WannaCry remains the best-known example.
  • Locker ransomware: Locks the whole screen or device rather than individual files. More common against consumers than organisations.
  • Double extortion: Steals data before encrypting it and threatens publication on a leak site. Qilin and Akira both run this model and it is now the norm.
  • Triple extortion: Adds a third lever such as DDoS attacks or direct calls to the victim’s customers and patients.
  • Extortion without encryption: Skips the malware and simply steals data, betting that the threat of a leak is enough.
  • Wipers in disguise: Destructive malware dressed up with a ransom note. The 2017 NotPetya outbreak looked like ransomware but was built to destroy data.

Ransomware as a service is the business model underneath most of these. The operator builds the encryptor, the leak site and the negotiation portal, then rents the kit to affiliates. Qilin affiliates reportedly keep up to 80 to 85% of each ransom according to the US Center for Internet Security, and the UK National Crime Agency identified 194 affiliates when it seized LockBit’s platform in 2024.

The 82 distinct variants ENISA observed against EU organisations in a single year come from this rental economy. Names change constantly. The playbook barely does.

The Business Impact of Ransomware

The ransom is rarely the biggest number. Downtime is. When a cyber attack halted Jaguar Land Rover’s production lines from late August 2025, the UK’s Cyber Monitoring Centre put the financial impact at an estimated £1.9 billion across more than 5,000 organisations and described it as the most economically damaging cyber event to hit the UK. Production only returned to normal levels in mid-November.

Service organisations feel the same force as weeks of manual workarounds. Restoration after the Akira attack on Tietoevry’s Swedish data centre in January 2024 stretched over weeks while universities and government agencies ran payroll on backup routines. Synnovis put the cost of the 2024 attack on its pathology services above £32 million.

The payment picture has improved for defenders without shrinking the threat. Chainalysis tracked about 820 million dollars in ransom payments in 2025, down for a second year from the 2023 record of roughly 1.25 billion dollars and only 28% of victims paid. The median payment still jumped to almost 60,000 dollars and claimed attacks rose by half.

Two costs sit outside every spreadsheet. A breach of personal data brings regulatory exposure as the Miljödata leak that affected more than 1.5 million people shows. When hospitals are hit, the price is measured in patient harm.

The FBI notes that the 32 million dollars of ransomware losses reported to it in 2025 exclude downtime, lost business and recovery costs, so official loss figures understate the damage.

Real-World Ransomware Cases

Five incidents show how the same crime plays out in different settings. Each ended with a clear lesson.

WannaCry, the Worm That Hit 150 Countries

On 12 May 2017 WannaCry ransomware spread itself through a Windows file-sharing flaw using the leaked EternalBlue exploit. Europol called the outbreak unprecedented and estimated around 200,000 infected computers across 150 countries within days.

The UK’s NHS was among the worst hit. About a third of hospital trusts and some 595 GP practices were disrupted, roughly 19,000 appointments were cancelled and the Department of Health and Social Care later estimated the cost at £92 million. No NHS organisation paid the ransom and a researcher’s kill-switch domain stopped the spread the same day.

Microsoft had patched the flaw two months earlier so every infected machine was running software that could have been updated in March. The US and UK later attributed the attack to North Korea, but the operational lesson stands regardless of the attacker. Patch fast especially anything reachable from the internet.

Kaseya and Coop Sweden, the Supply Chain Attack

On 2 July 2021 the REvil gang pushed ransomware through a vulnerability in Kaseya VSA, an IT management tool, reaching up to 1,500 businesses in at least 17 countries. The gang demanded 70 million dollars for a universal decryptor.

In Sweden the visible victim was Coop. Most of its roughly 800 supermarkets closed for several days because the supplier running its point-of-sale systems, Visma Esscom, was caught in the attack and the tills stopped working.

Coop was never the target and its own network was not breached. The stores closed anyway which is why supplier contingency plans belong in every continuity exercise.

Tietoevry and Akira, Weeks of Disruption in Sweden

During the night of 19 to 20 January 2024 the Akira group encrypted virtualisation and management servers in one of Tietoevry’s Swedish data centres. The blast radius was national. The Primula payroll service used by a majority of Swedish universities and around 30 government authorities went down. So did Filmstaden’s ticketing, the retailers Rusta and Granngården and healthcare systems in Uppsala County.

Restoration stretched over weeks with affected organisations falling back on manual routines. Tietoevry never disclosed the exact entry route. Finland’s National Cyber Security Centre had warned that month that the ongoing Akira wave was breaking in through unpatched Cisco VPN devices that lacked multi-factor authentication, a flaw patched in autumn 2023.

Two controls close that door. Patch internet-facing VPN devices as a priority and require multi-factor authentication on every remote login without exception.

Synnovis and Qilin, Ransomware in the Hospital Lab

On 3 June 2024 the Qilin ransomware group attacked Synnovis, the pathology provider for NHS hospitals in southeast London. Blood testing slowed to manual pace across major hospitals. More than 10,000 appointments were disrupted and 1,710 operations postponed at King’s College Hospital and Guy’s and St Thomas’ trusts.

No ransom was paid and roughly 400GB of stolen data, including patient information, was published. In June 2025 King’s College Hospital NHS Foundation Trust confirmed that one patient died unexpectedly during the incident and that a long wait for a blood test result caused by the attack was a contributing factor. Synnovis has put its own costs above £32 million.

The entry route has never been publicly confirmed, so honesty matters more than a neat moral here. What the incident proves is the value of limiting blast radius. Segmented systems and rehearsed manual fallbacks decide whether a supplier outage is an inconvenience or a clinical emergency.

Miljödata, One Supplier and 200 Municipalities

On Saturday 23 August 2025 Miljödata, an HR systems supplier used by about 80% of Swedish municipalities detected an intrusion. The attackers demanded 1.5 bitcoin. Systems for handling medical certificates, rehabilitation cases and workplace injuries went down across roughly 200 of Sweden’s 290 municipalities plus regions and universities.

In mid-September the stolen data appeared on the dark web and the Swedish Prosecution Authority confirmed that more than 1.5 million people were affected. A group calling itself Datacarry claimed the attack and the leak ranks among the largest known personal data exposures in Swedish history.

For every organisation that outsources HR, payroll or IT, the questions write themselves. What data does the supplier hold, does the contract require security measures you can verify and what is the plan for the week their systems are gone?

Ransomware and Compliance

For organisations in scope of NIS2, ransomware readiness is now written into Swedish law. Cybersäkerhetslagen (SFS 2025:1506) came into force on 15 January 2026 and transposes the directive. Article 20 of NIS2 places responsibility with the management body and supervisory authorities can hold board members personally accountable. Read more in the guide to NIS2 in Sweden.

Article 21 lists the measures a ransomware programme must cover.

  • Continuous monitoring (Article 21.2a): Detection capability that runs around the clock.
  • Incident handling (Article 21.2b): A tested plan for containing and reporting attacks.
  • Business continuity (Article 21.2c): Backups and crisis procedures that keep services running.
  • Supply-chain security (Article 21.2d): Security requirements on the suppliers whose outage would stop you.
  • Awareness training (Article 21.2g): Staff who can recognise the phishing attempts that start most intrusions.

Fines reach €10 million or 2% of global turnover for essential entities and €7 million or 1.4% for important entities.

The reporting clock is strict. An organisation in scope must send an early warning to MCF (formerly MSB) and its sector authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours and a final report within one month.

Ransomware that steals personal data is also a breach under GDPR which means notifying IMY within 72 hours under Article 33. Financial entities carry parallel duties under DORA Article 17, supervised by Finansinspektionen. See the guides to GDPR compliance and DORA compliance.

How to Spot a Ransomware Attack

By the time files start renaming themselves, the attack is days or weeks old. Encryption is the finale. The useful warning signs come earlier. Most of them live in logs rather than inboxes.

  • Odd remote logins: VPN or remote desktop sessions at strange hours or from unfamiliar locations.
  • New privileged accounts: Administrator accounts nobody remembers creating.
  • Security tools going quiet: Antivirus or endpoint agents disabled, uninstalled or silenced.
  • Backups being touched: Deleted shadow copies, wiped backup jobs or unexpected logins to backup consoles.
  • Unfamiliar software: Remote access or file-transfer tools appearing on machines that never needed them.
  • Unusual outbound traffic: Large transfers to unknown destinations, often the data theft in progress.

Late signs are unmistakable. Files with new extensions, ransom notes in every folder and systems locking one after another. At that point the job is containment, so disconnect affected machines from the network but do not switch them off, because memory can hold evidence and sometimes encryption keys.

The honest caveat is that none of this is reliably visible to the naked eye. Attackers use legitimate credentials and legitimate tools precisely so their activity blends into normal administration. Spotting the early stages takes continuous monitoring of endpoints and logs which is a staffing question as much as a tooling one. That is the problem managed detection and response exists to solve.

How to Defend Against Ransomware

No single product stops ransomware. The organisations that recover well combine trained people, rehearsed processes and a short list of technical controls done thoroughly.

  • Train and rehearse: Phishing starts about 60% of intrusions, so teach staff what current lures look like and make reporting one click with no blame attached.
  • Require multi-factor authentication everywhere: Every VPN, remote desktop, email and admin login gets it. The Akira wave broke in where it was missing.
  • Patch on a clock: Prioritise anything reachable from the internet. WannaCry’s patch had been available for two months.
  • Keep offline, tested backups: Attackers hunt online backups and delete them. Keep at least one copy offline or immutable and rehearse a full restore before you need it.
  • Segment the network: Separate critical systems and backups from the general network so one compromised machine cannot reach everything.
  • Monitor and respond around the clock: The early signs above only matter if someone sees them in time, whether an internal team or a service.
  • Set supplier requirements: Contract for security measures, breach notification and continuity plans with every supplier whose outage would stop you. Coop and 200 municipalities learned this the hard way.
  • Write and rehearse the incident plan: Decide in advance who isolates systems, who calls the police and CERT-SE and who owns the 24-hour report to MCF.

Plan never to pay. Only 28% of victims paid in 2025 and the UK National Crime Agency found data from paying victims still sitting on LockBit’s seized servers, so payment buys neither deletion nor certainty. Before any decision, check the free decryptors at No More Ransom, the Europol-backed project that has helped more than six million victims and involve the police early.

Start with the two controls that would have stopped the biggest cases in this guide. Turn on multi-factor authentication for every remote login and patch your internet-facing systems this week.

Myths & Facts

Myth

Ransomware only hits big companies.

Paying the ransom gets your data back and ends the incident.

Good backups make you immune.

Ransomware only arrives through email.

Antivirus will stop it.

Once systems are restored, it is over.

Fact

Attackers shifted toward small and medium organisations in 2025 as large firms stopped paying, according to Chainalysis. Any organisation where downtime or a data leak is expensive is a viable target.

Only 28% of victims paid in 2025, and the UK National Crime Agency found data from paying victims still stored on LockBit's seized servers. Payment guarantees neither decryption nor deletion.

Attackers hunt and delete online backups before encrypting, and they steal data first, so leak extortion works even with perfect restores. Offline tested copies cut downtime but do not undo the breach.

Phishing drove about 60% of the intrusions ENISA analysed, but exploited software flaws accounted for 21.3% and stolen remote-access credentials without multi-factor authentication are a routine entry point.

Ransomware operators log in with valid credentials, use legitimate admin tools and disable security software before encrypting. Catching them takes continuous monitoring of behaviour across endpoints and the network.

Restoration after the Tietoevry attack ran for weeks, regulators expect reports within days and stolen data can resurface months later. Recovery is a programme, not a reboot.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. It is Friday evening. A colleague in IT mentions that a new administrator account appeared today which nobody remembers creating, and the antivirus service on two servers has stopped without explanation.

    What do you do?

    • Wait until Monday, it is probably maintenance
    • Report it to security immediately as a possible intrusion in progress
    • Delete the account yourself and restart the antivirus
  2. Every card terminal in your stores stops working at once. Your own network looks clean, and the supplier that runs the point-of-sale systems is not answering its phones.

    What is the most likely explanation to raise with management?

    • A power fault at head office
    • A cyber attack on the supplier that runs the tills
    • Staff entering wrong codes across all stores
  3. You arrive to find servers encrypted and a note demanding bitcoin within 72 hours. Backups exist but have never been test-restored.

    What is the right first move?

    • Pay quickly to meet the deadline
    • Activate the incident plan, isolate affected systems and start the 24-hour reporting clock
    • Wipe everything and reinstall from scratch straight away
  4. An email that looks like your payroll provider asks you to log in again because of an urgent system migration. The link leads to a login page that looks right.

    What do you do?

    • Log in, payroll matters are urgent
    • Ignore it and delete the email
    • Report it to IT and verify with the provider through a known channel

Knowledge Test

  1. What share of ransomware victims paid in 2025, according to Chainalysis?

    • 28%
    • 50%
    • 75%

    Only 28% of victims paid in 2025, a record low, even though claimed attacks rose by about half.

  2. How did WannaCry spread so far in 2017?

    • Through a Windows flaw Microsoft had patched two months earlier
    • Through a zero-day flaw with no available fix
    • Through infected USB sticks

    WannaCry used the EternalBlue exploit for a flaw patched in March 2017, so every infected machine was missing an available update.

  3. What is double extortion?

    • Encrypting the same files twice
    • Stealing data and threatening to leak it in addition to encrypting
    • Demanding two payments in different currencies

    Double extortion pairs encryption with data theft so the leak threat works even when backups restore the files.

  4. Under Cybersäkerhetslagen, how quickly must an organisation in scope send its early warning?

    • Within 24 hours
    • Within 72 hours
    • Within one month

    The cascade is an early warning within 24 hours, a full notification within 72 hours and a final report within one month.

  5. Roughly how many of Sweden's 290 municipalities were disrupted by the 2025 Miljödata attack?

    • Around 20
    • Around 200
    • All 290

    One supplier attack disrupted services across roughly 200 of Sweden's 290 municipalities plus regions and universities.

  6. Finland's National Cyber Security Centre linked the 2024 Akira wave to VPN devices that were what?

    • Unpatched and lacking multi-factor authentication
    • Too new to be supported
    • Running unusual operating systems

    The wave broke in through unpatched VPN devices with no multi-factor authentication, which is why those two controls top the defence list.

Why Training Matters

Phishing starts about 60% of the intrusions that end in ransomware, which makes your staff the most attacked surface you have. Training changes what happens in the first minutes. An employee who recognises a credential-harvesting page, questions an odd invoice or reports a strange login prompt hands the security team the head start that containment depends on.

It is also a legal expectation. NIS2 Article 21.2g and Cybersäkerhetslagen make security awareness a required measure for organisations in scope, with management accountable for seeing it done. Practical, scenario-based security awareness training turns that duty into a habit your organisation keeps.

Frequently Asked Questions

What is ransomware in simple terms?

Ransomware is malicious software that locks you out of your own systems or files until a ransom is paid. Modern gangs also steal the data and threaten to publish it. The goal is extortion, and the target is any organisation where downtime or a leak is expensive.

How do ransomware attacks usually start?

Most ransomware attacks start with a phishing message or an exposed technical weakness. ENISA's 2025 analysis found phishing behind about 60% of intrusions and vulnerability exploitation behind 21.3%. Stolen passwords for VPN or remote desktop services that lack multi-factor authentication are another common way in.

What is ransomware as a service?

Ransomware as a service (RaaS) is a criminal business model where a core group builds the malware and rents it to affiliates who carry out attacks for a share of each ransom. Qilin, Akira and LockBit all ran this model, which is why attack volumes keep rising.

What are the main types of ransomware?

The main types of ransomware are crypto ransomware (encrypts files), locker ransomware (locks whole devices) and double extortion (also steals data and threatens to leak it). Newer variations add pressure such as DDoS attacks. Some skip encryption entirely and extort on the stolen data alone.

Should a business ever pay the ransom?

Paying is a last resort with no guarantees. Only 28% of victims paid in 2025, and the UK National Crime Agency found data from paying victims still on LockBit's servers. Check No More Ransom for a free decryptor, involve the police and take legal advice before any decision.

Why is WannaCry still relevant today?

WannaCry remains the clearest lesson in why patching matters. In May 2017 it infected around 200,000 computers across 150 countries, using a Windows flaw Microsoft had patched two months earlier. The NHS alone cancelled about 19,000 appointments at an estimated cost of £92 million.

What is Qilin ransomware?

Qilin is a ransomware-as-a-service operation first observed in 2022 and one of the most active groups of 2025 according to FBI and ENISA reporting. Its 2024 attack on NHS pathology provider Synnovis disrupted more than 10,000 appointments and contributed to a patient's death.

What must a Swedish organisation do after a ransomware attack?

A Swedish organisation in scope of Cybersäkerhetslagen must send an early warning to MCF (formerly MSB) and its sector authority within 24 hours, a full notification within 72 hours and a final report within one month. If personal data leaked, GDPR requires notifying IMY within 72 hours.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.