Back to blog
0 to 100 Ransomware attack and how to manage it

0 to 100 Ransomware attack and how to manage it

11 August 2026

What is ransomware attack?

Ransomware is a type of malware that infects computers and encrypts or locks files, preventing employees from accessing important data. Cybercriminals then demand money in exchange for unlocking or restoring access to the data.

The ransom demanded can sometimes reach seven or eight figures, making ransomware attacks extremely costly. Even after a payment is made, there is no guarantee that the data will be recovered. Cybercriminals may also steal sensitive information, such as customer data, and publish or sell it on the dark web, allowing others to misuse the information as well.

When did the first ransomware attack happen and who ran it?

The first known ransomware attack occurred in 1989 and involved malware called the AIDS Trojan, also known as PC Cyborg. It was created by Joseph Popp, a biologist who distributed around 20,000 infected floppy disks to people connected with an international AIDS conference and other mailing lists. The disks appeared to contain useful AIDS-related information, but after being installed, the malware eventually hid or locked access to files and demanded a payment of US$189 to PC Cyborg Corporation.

The attack is widely regarded as the first documented ransomware attack and introduced the basic idea that modern ransomware still uses today: restricting access to a victim's data and demanding money to restore it. Popp was later arrested and charged with blackmail, although he was ultimately found mentally unfit to stand trial.

Stages of ransomware attack

A ransomware attack typically moves through a series of stages before a victim ever sees a ransom demand.

Stage 1: Initial Access

Stage 2: Post-Exploitation

Stage 3: Understand and Expand

Stage 4: Data Collection and Exfiltration

Stage 5: Deployment and Extortion

The main ways of a ransomware attack are phishing, vulnerability exploitation, and compromising remote access protocols like RDP.

Ways of ransomware attack

The most used method for attackers carrying out ransomware attacks is phishing, and the most common vulnerability is human vulnerability: an employee who ignores the red flags of an email and clicks on an attachment file.

Although your staff may have completed cybersecurity training before, they may still be targeted due to the more convincing methods attackers use and also their access to AI to write convincing texts or use voice agents.

Main types of ransomware

Crypto Ransomware Attack

Action

Scrambles and encrypts files like documents, videos, and photos.

Your computer still runs, but your data is completely inaccessible without the decryption key.

Real-World Example: WannaCry (2017)

Real-World Damage

It hit the UK's National Health Service (NHS), scrambling patient data, shutting down hospital computers, and forcing the cancellation of roughly 19,000 medical appointments.

What Happened

This attack infected over 200,000 computers globally across 150 countries. It automatically scanned networks for a specific Windows security vulnerability (EternalBlue) to encrypt device files.

Wannacry Ransomwar Attack

Locker Ransomware Attack (System Blockers)

Action

Locks you completely out of your operating system user interface.

Impact

You cannot access your desktop or apps; only a full-screen ransom note appears.

Real-World Example

Petya (2016)
What Happened

Unlike crypto ransomware that leaves the operating system running, Petya immediately forced a computer reboot. It then overwrote the Master Boot Record (MBR), completely blocking the Windows operating system from loading.

Real-World Damage

Users turned on their computers only to find a red screen with a full-screen skull icon and a demanding ransom message, with zero access to any applications.

Leakware / Doxware (Exfiltration Ransomware)

Action

Steals sensitive personal or corporate data instead of, or in addition to, encrypting it.

Impact

Threatens to publish trade secrets, customer records, or private photos online if you refuse to pay.

Real-World Example

Cl0p (MOVEit Breach - 2023)
What Happened

The Cl0p gang bypassed encryption entirely for thousands of victims. Instead, they exploited a vulnerability in the widely used MOVEit file-transfer software to steal mass amounts of sensitive data.

The Tactic

Cl0p listed hundreds of major corporations and government agencies on their "name-and-shame" leak site. They extorted the entities solely on the threat of making those stolen documents completely public.

Scareware (Fake Software)

Action

Mimics official security software or police alerts via pop-ups claiming your PC is infected or compromised.

Impact

Panics users into purchasing fake cleanup tools or paying bogus "fines" to unlock their browser.

Real-World Example

Chronos / FakeAntivirus Pop-ups
What Happened

Users browsing malicious sites are hit with aggressive, un-closable browser pop-up windows that flash warning lights and sound simulated sirens.

The Tactic

The pop-ups alert the user that dozens of viruses have been found on their device. The user is tricked into paying for a useless "premium security tool" to clean the fake infection.

Mobile Ransomware (Device Hijackers)

Action

Targets smartphones and tablets, usually via malicious third-party app downloads.

Impact

Blocks user access to the mobile screen, steals contact logs, or encrypts device storage.

Real-World Example

Cyber.Police (Android)
What Happened

Primarily spread via untrusted third-party app stores or adult websites, this malware targets mobile operating systems.

The Tactic

Once installed, it takes over the Android layout, rendering the home button, back button, and power options useless. It demands a payment, often via Apple Gift Cards or cryptocurrency, to give the phone back to the owner.

Ransomware-as-a-Service (RaaS)

Action

A subscription business model where professional developers lease ransomware variants to low-skilled hackers, known as affiliates.

Impact

Massively scales the volume of global attacks, with profits split between the developers and attackers.

Real-World Example

Qilin
What Happened

Qilin operates as a massive franchise, renting its encryption tools to independent criminal affiliates in exchange for a cut of the profits.

Real-World Damage

Qilin was responsible for a major attack on London pathology provider Synnovis, which severely disrupted blood testing across several NHS hospitals.

Ways of ransomware

One of the most common methods attackers use to carry out a ransomware attack is phishing. In many cases, the biggest vulnerability is human error, such as an employee ignoring warning signs in an email and clicking on a malicious attachment or link.

Even if your staff have completed cybersecurity training, they may still be targeted because attackers are using increasingly convincing techniques. With access to AI, cybercriminals can create more realistic emails, messages, and even voice interactions, making phishing attempts harder to identify.

What is a phishing campaign and how does it work?

A phishing campaign is an organised attempt to trick people into revealing sensitive information or taking an unsafe action.

Attackers may send fake emails, text messages, or login pages that appear to come from a trusted company, manager, bank, or supplier. Their goal is often to steal passwords, financial details, or access to business systems.

It is called a campaign because it is a planned series of phishing attempts, not usually just one message.

Attackers may send hundreds or thousands of similar emails over several days, targeting a particular company or group. The messages often share the same goal, such as stealing passwords, spreading ransomware, or tricking employees into making payments using different types of phishing; similar to how a marketing campaign uses coordinated messages to achieve one objective.

What to do after being a ransomware attack victim

Receiving a ransomware email does not always mean the company has been successfully attacked. Treat it as a serious incident until checks show otherwise.

  • Do not reply, click links, open attachments, or pay anything.
  • Keep the email as evidence. Do not delete it. Record when it arrived, who received it, the sender address, payment demand, cryptocurrency wallet, deadlines, and any claimed stolen data.
  • Check whether systems are affected. Look for encrypted files, inaccessible systems, unusual administrator accounts, suspicious logins, disabled security software, or evidence that data was copied.
  • If compromise is suspected, isolate affected devices from the network. Disconnect network cables and Wi-Fi, but avoid wiping, rebuilding, or unnecessarily switching devices off because this can destroy forensic evidence.
  • Contact the company's IT provider, cyber insurer and legal adviser immediately. The insurer may require the company to use an approved incident-response supplier.
  • Start an incident log. Record every decision, action, time, person involved and external report made.
  • Use a clean device and separate communication channel. Assume the normal email or collaboration system may be monitored.

Incident Log Example

The NCSC recommends rapid containment, investigation and structured recovery during ransomware attack.

If someone already clicked or opened the attachment, they should immediately stop using the device, disconnect it from Wi-Fi and network cables, and contact IT. The business should isolate affected systems, activate its incident-response plan, preserve evidence, check backups, and assess whether data was accessed or encrypted.

How to report it without an internal process

A director or senior manager should temporarily take ownership and appoint:

  • One incident coordinator;
  • One technical lead;
  • One person responsible for legal and data-protection decisions;
  • One person responsible for staff, customer and media communications.

The business can then use this simple temporary reporting route:

Report an active attack to the police

For a UK business, charity or organisation experiencing a live cyberattack, call Report Fraud on 0300 123 2040 immediately. The live cyberattack service operates 24 hours a day. Reports can also be submitted through the Report Fraud website. In Scotland, criminal reports may also need to go to Police Scotland.

2. Report to the NCSC

Use the NCSC Report a Cyber Incident service. The NCSC can receive technical incident information and may provide guidance or coordinate support, particularly for significant incidents.

https://report.ncsc.gov.uk

3. Assess whether the ICO must be notified

Ransomware can be a personal-data breach even when data was only encrypted and not proven stolen, because the company may have lost access to personal information.

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ransomware-and-data-protection-compliance

The company must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach when it is likely to create a risk to individuals' rights and freedoms. The company should notify affected people without undue delay where the risk to them is high. All personal-data breaches and the reasoning behind reporting or not reporting must be documented.

https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide

An initial ICO report can be made before every fact is known and supplemented later. It should include, as far as known:

  • What happened and when;
  • Systems, records and people potentially affected;
  • Types of personal data involved;
  • Likely consequences;
  • Containment and recovery measures;
  • A company contact for further information.

4. Notify other relevant parties

Depending on the business, it may also need to inform:

  • Your cyber insurer;
  • Customers or employees at high risk;
  • Affected suppliers and data controllers;
  • The FCA or another sector regulator;
  • Payment providers and banks;
  • Contractual customers with breach-notification clauses.

Should the company pay?

The NCSC and UK law enforcement do not encourage ransom payments. Payment does not guarantee recovery, deletion of stolen data, or protection from another demand.

https://www.reportfraud.police.uk/ransomware

A payment can also be unlawful if money or economic resources are provided to a sanctioned person or organisation. No payment or negotiation should happen without specialist legal advice, insurer involvement and sanctions checks.

https://www.gov.uk/government/publications/financial-sanctions-guidance-for-ransomware/financial-sanctions-guidance-for-ransomware

Useful official websites

National Cyber Security Centre: ransomware attack response, recovery guidance and incident reporting.

https://www.ncsc.gov.uk/section/advice-guidance/all-topics/ransomware

Report Fraud: police reporting for fraud and cybercrime, including the 24-hour live business attack number.

https://www.reportfraud.police.uk/reporting-a-fraud/

Information Commissioner's Office: ICO breach assessment, reporting and 72-hour guidance.

https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/72-hours-how-to-respond-to-a-personal-data-breach

Business.gov.uk: a practical business cyberattack response guide and links to assured incident-response professionals.

https://www.business.gov.uk/support/digital-data-protection-and-cyber-security/responding-to-cyber-attack-on-your-business/

GOV.UK Cyber Security Guidance for Business: government guidance, Cyber Essentials support, Cyber Resilience Centres and approved advisers.

https://www.gov.uk/government/collections/cyber-security-guidance-for-business

OFSI ransomware sanctions guidance: important before considering or facilitating any payment.

https://www.gov.uk/government/publications/financial-sanctions-guidance-for-ransomware/financial-sanctions-guidance-for-ransomware

Can Optimise Cyber help in a ransomware attack?

Optimise Cyber Solutions helps with preparation, staff response skills, ransomware attack exercises, awareness training and developing an incident-reporting process. Optimise was founded by the former UK national cyber incident-response lead and provides practical, scenario-based cyber training aligned with NCSC guidance.

Optimise Cyber can help you coordinate the initial response, understand your reporting obligations and strengthen your incident process. Where specialist live forensics or recovery is required, we will confirm the appropriate technical response route.

More from the blog

Types of phishing attacks that could cost Businesses over £100M
Post

Types of phishing attacks that could cost Businesses over £100M

Learn about the types of phishing attacks targeting businesses and employees, including workplace scams, warning signs and modern phishing methods.

3 August 2026Read more
Is Microsoft Teams Secure for Confidential Information? (+5 Security Tips)
Post

Is Microsoft Teams Secure for Confidential Information? (+5 Security Tips)

Is Microsoft Teams secure for confidential information? Learn how phishing, fake IT support, malicious links and role-based scams can put business data at risk.

28 July 2026Read more