# What is Ransomware?

> Ransomware is malicious activity designed to coerce payment by denying access to systems or data, threatening disclosure, or combining both.

- Canonical URL: https://yellowcube.eu/glossary/ransomware/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Traditional ransomware encrypts files or systems, but many operations first steal data and may use theft, public exposure, customer contact, or service disruption as additional leverage.

A ransomware event is often the visible end of a longer intrusion. Attackers may have already stolen credentials, moved laterally, disabled safeguards, accessed backups, and exfiltrated information before the ransom demand appears. Response therefore requires investigation of the full compromise, not only restoration of encrypted files.

### Key points

- **Common entry paths:** Stolen credentials, exploitable internet-facing systems, phishing, malicious downloads, remote services, and supply-chain compromise.
- **Risk reduction:** Strong identity controls, prompt remediation, segmentation, monitored endpoints, protected management paths, and tested offline or immutable backups.
- **Response priority:** Protect life and essential services, contain spread, preserve evidence, assess theft, coordinate stakeholders, and recover from known-good sources.
- **Important limitation:** Backups improve recovery but do not prevent data theft, fraud, regulatory impact, or recurrence from an unresolved entry point.

### Related terms

[Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Endpoint detection and response (EDR)](<https://yellowcube.eu/glossary/endpoint-detection-and-response/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Business continuity](<https://yellowcube.eu/glossary/business-continuity/>) · [Data exfiltration](<https://yellowcube.eu/glossary/data-exfiltration/>)

### Sources

[CISA: StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide) · [CISA: Ransomware information](https://www.cisa.gov/stopransomware/general-information)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

