Ransomware
Malware that encrypts your files and demands payment for the key, now almost always combined with stealing the data first.
Modern ransomware is a business model, not a virus. A crew gets in through a phished credential or an unpatched internet-facing service, spends days or weeks quietly mapping the network, deletes or encrypts the backups, copies the data out, and only then triggers the encryption. By the time you see the ransom note the damage is finished.
That sequence is why paying is not a recovery plan. The stolen copy still exists whether or not you pay, which is why most incidents now involve a second demand not to publish. The controls that actually matter are the ones that break the chain early: phishing-resistant MFA, patching what faces the internet, and backups the attacker cannot reach.
Where this comes up
Ransomware sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.