What is Ransomware?
Ransomware is malware that encrypts your files, and once you pay the ransom, you may never get access to those files again. It can also leave your files vulnerable to future attacks and expose confidential information.
It’s often spread via phishing, drive-by downloads, compromised software or by clicking on malicious advertisements (malvertising). Once it’s installed, it can encrypt files and devices within your network and subsequently block access to them. Cyber actors display a ransom message that requires payment in cryptocurrency for a decryption key or they may threaten to publicly release the data if the ransom is not paid.
Once ransomware gets into a system, it’s easy for attackers to use lateral movement to infect other systems and increase damage. Once on a device, it can encrypt essential files including databases, spreadsheets and important datasets for z/OS as well as encrypt key z/OS system infrastructure like the root directory.
Ransomware can cause significant financial loss. If you don’t have backups, your personal files can be lost permanently and could cost thousands of dollars to recover. Many organizations choose to pay the ransom, but it’s not always a good option.
Paying a ransom can encourage criminals to attack again. It also doesn’t guarantee that you’ll be able to restore your files and can mark you as a target worth targeting again. It’s best to focus on prevention with strong cybersecurity tools, employee education and a thorough incident response plan.