Does ransomware always encrypt files?¶
The practical answer¶
No. Ransomware does not always encrypt files.
The key evidential caution¶
The dangerous assumption is that the absence of encrypted data means there was no ransomware or extortion incident.
Some incidents rely on:
Key points¶
- data theft
- threats to publish
- service disruption
- account lockout
- system deletion
- website defacement
- fraudulent claims of compromise
- pressure against customers or partners
An offender may demand payment after stealing data without encrypting anything.
They may also claim to hold data they never obtained.
What investigators should establish¶
Investigators should establish:
Key points¶
- what systems were affected
- what data became unavailable
- whether files changed
- whether encryption occurred
- whether data was copied
- what claims were made
- what evidence supports those claims
Evidential limits¶
Do not use the ransomware label as a substitute for describing the actual behaviour.
A note demanding payment may be evidence of extortion, but not proof of encryption or data theft.
Likewise, system unavailability may result from containment, shutdown or technical failure rather than offender encryption.
Preserve file metadata, process records, ransom communications, network activity, backups and response actions.
The exact incident type may affect preservation and reporting, but the operational question remains what the offender did and what harm followed.
Some groups now rely mainly on data theft and publication pressure, while others combine theft with partial encryption or selective disruption. The label should therefore follow the observed behaviour rather than assumptions about how a named group usually operates.
A claim of ransomware may also be made by an offender who only gained limited access. Preserve the technical evidence separately from the language of the demand, and avoid allowing the offender’s own description to define the incident.
Operational takeaway¶
Do not define ransomware only by encryption; establish whether the incident involved denial, theft, disruption, threats or a combination of these.