Skip to content
CIM-172 Cyber Incidents & Offender Methods

What is ransomware?

The practical answer

Ransomware is malicious activity used to deny access to systems or data and demand payment or another concession.

The key evidential caution

The dangerous assumption is that ransomware always means files were encrypted by one piece of malware.

It may involve:

Key points

  • file encryption
  • system locking
  • data theft
  • threats to publish information
  • service disruption
  • deletion of backups
  • pressure through direct contact
  • claims that may be exaggerated or false

What investigators should establish

Investigators should identify what actually happened.

Were files encrypted?

Were systems made unavailable?

Was data copied?

Were backups altered?

Was a ransom note created?

Did the offender communicate?

Was payment demanded?

Evidential limits

Do not assume that every outage with a ransom note was caused by successful ransomware execution. The note may have been placed manually, copied from another incident or used to create pressure after different access.

Likewise, encrypted files do not prove data was stolen.

Relevant evidence

Relevant evidence may include malicious files, process activity, encryption records, ransom notes, account use, remote access, data staging, outbound traffic, communications and payment instructions.

The same incident may contain several distinct offences or harms.

Keep the stages separate:

Key points

  • initial access
  • privilege escalation
  • discovery
  • collection
  • encryption
  • disruption
  • extortion
  • payment activity

Ransomware evidence may show method, timing, impact and infrastructure. It does not automatically identify the offender or prove every claim made in the ransom demand.

Where several systems are affected, establish whether one central action caused the impact or whether encryption and disruption were deployed separately across different hosts. This can affect both the incident timeline and the number of distinct access routes that must be examined.

Operational takeaway

Treat ransomware as a sequence of access, disruption and extortion activity, and prove encryption, data theft and offender claims separately.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.