Skip to content
CIM-173 Cyber Incidents & Offender Methods

Does ransomware always encrypt files?

The practical answer

No. Ransomware does not always encrypt files.

The key evidential caution

The dangerous assumption is that the absence of encrypted data means there was no ransomware or extortion incident.

Some incidents rely on:

Key points

  • data theft
  • threats to publish
  • service disruption
  • account lockout
  • system deletion
  • website defacement
  • fraudulent claims of compromise
  • pressure against customers or partners

An offender may demand payment after stealing data without encrypting anything.

They may also claim to hold data they never obtained.

What investigators should establish

Investigators should establish:

Key points

  • what systems were affected
  • what data became unavailable
  • whether files changed
  • whether encryption occurred
  • whether data was copied
  • what claims were made
  • what evidence supports those claims

Evidential limits

Do not use the ransomware label as a substitute for describing the actual behaviour.

A note demanding payment may be evidence of extortion, but not proof of encryption or data theft.

Likewise, system unavailability may result from containment, shutdown or technical failure rather than offender encryption.

Preserve file metadata, process records, ransom communications, network activity, backups and response actions.

The exact incident type may affect preservation and reporting, but the operational question remains what the offender did and what harm followed.

Some groups now rely mainly on data theft and publication pressure, while others combine theft with partial encryption or selective disruption. The label should therefore follow the observed behaviour rather than assumptions about how a named group usually operates.

A claim of ransomware may also be made by an offender who only gained limited access. Preserve the technical evidence separately from the language of the demand, and avoid allowing the offender’s own description to define the incident.

Operational takeaway

Do not define ransomware only by encryption; establish whether the incident involved denial, theft, disruption, threats or a combination of these.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.