Does ransomware always encrypt files?¶
No. An extortion incident may rely on data theft, publication threats, account lockout, deletion, defacement or service disruption without encrypting files.
Let observed behaviour define the incident¶
Establish which systems and data were affected, whether files changed, what became unavailable, whether collection or transfer occurred, and what claims and demands were made.
A payment note proves a demand, not encryption or theft. System unavailability may come from containment, shutdown or technical failure. Conversely, absence of encrypted files does not exclude a theft-and-publication scheme.
Test offender claims separately¶
Groups may combine selective encryption with theft, or claim a compromise far beyond their access. Preserve file metadata, processes, communications, network activity, backups and response actions independently of the language used in the demand.
Avoid defining the incident by how a named group is reputed to operate. State the evidenced denial, disclosure, disruption and threat components and any unproved claims.
Key takeaway
Ransomware is not synonymous with encryption; report the actual denial, theft, disruption and extortion behaviours that evidence proves.