Attack outcomes
Ransomware
Ransomware is malicious software that encrypts an organization's files and systems so they cannot be used, followed by a demand for payment to restore them. Operators often steal data first and threaten to publish it. Initial access can come through phished or stolen credentials, exposed remote access, accounts without MFA or unpatched software.
How it works
Attackers get in, often with stolen credentials or an exposed remote service, then escalate privileges, disable backups and spread across the network before triggering encryption everywhere at once. A ransom note explains how to contact them. Some groups run as services that rent the malware to affiliates, who split the payment with its developers.
A real example
In a 2023 notification letter filed with the California Attorney General, Heavy Hammer said its internal servers were compromised by a ransomware attack that it believed followed a phishing attack on several employees.
Source: Heavy Hammer multi-state notification letter — Heavy Hammer, Inc. (filed with the California Attorney General), 2023-06-06
How to stop it
Use phishing-resistant MFA for remote access and admin accounts, keep privileged accounts separate from everyday ones, and protect backups with credentials attackers cannot reach from the main network.
Related terms
Threat actors that use it
- Akira
Profile with government sources
- ALPHV Blackcat
Profile with government sources
- Black Basta
Profile with government sources
- Lazarus Group
Profile with government sources
- LockBit
Profile with government sources
- Scattered Spider
Profile with government sources
Sources
- Heavy Hammer multi-state notification letter — Heavy Hammer, Inc. (filed with the California Attorney General), 2023-06-06
Last reviewed Oct 2, 2026