What is ransomware, and how does it reach Canadian organizations?

Ransomware locks an organization's files and demands payment. How it gets in, and the defences that stop most attacks.

By Luis Freitas

Illustration: What is ransomware, and how does it reach Canadian organizations?

Illustration Illustration: CybersecurityNews.ca

Explainer

Key points

  • Ransomware encrypts files and often steals data first
  • Most attacks start with phishing, stolen passwords or unpatched systems
  • MFA, patching and tested offline backups stop most of them

Ransomware is malicious software that encrypts an organization's files and systems, then demands a payment, usually in cryptocurrency, for the key to unlock them. Many groups now also steal data before encrypting it and threaten to publish it, a tactic known as double extortion.

How it gets in

  • Phishing emails that trick staff into opening a file or entering a password.
  • Stolen or guessed passwords for remote access such as VPNs and remote desktop.
  • Unpatched vulnerabilities in internet-facing systems.
  • Compromised IT service providers with access to many clients.

What stops most attacks

  • Multi-factor authentication on email, VPN and remote access.
  • Prompt patching, starting with internet-facing systems.
  • Offline or immutable backups that are tested regularly.
  • An incident response plan that names who to call, including your insurer and legal counsel.

The Canadian Centre for Cyber Security recommends against paying ransoms and encourages victims to report incidents to the Cyber Centre and to local police.

Editor's Picks

The best of The Rightup, delivered to you weekly.

On Display
Illustration: How to turn on multi-factor authentication in Microsoft 365

How to turn on multi-factor authentication in Microsoft 365

Illustration: How to report a phishing email or scam text in Canada

How to report a phishing email or scam text in Canada

AMD security advisory (AV26-1014)