HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Topic · Threats

Ransomware

The most profitable attack model of the decade: how it works, and what to do (and not do).

Dossiers in this section

7 dossiers

The topic in brief

What it is and how it works

Ransomware is malware that locks devices or encrypts files, demanding a ransom to restore access. The model has evolved into double extortion: before encrypting, attackers exfiltrate the data and threaten to publish it. Paying does not guarantee you get the data back and it feeds the market: the shared recommendation from authorities is don't pay.

Prevention works

The most effective defence is well known and unglamorous: verified offline backups, timely patching, multi-factor authentication, reduced internet exposure. The No More Ransom project — an initiative of Europol and the Dutch police with industry — offers a free repository of decryption tools and prevention guidance. For some families a decryptor already exists: before despairing, check.

If you're hit

Isolate systems, preserve evidence, notify the competent authorities (in Italy, CSIRT Italia) and engage an incident responder. The rush to “get everything back up” is the enemy of remediation: a hasty restore onto a still-compromised environment brings the attacker back in.

FAQ

Should I pay the ransom?
No. Authorities advise against paying: it doesn't guarantee data recovery and confirms to attackers that the model works.
Are there free decryption tools?
Yes, for several ransomware families. Europol's No More Ransom project collects free decryptors and should be checked before any other decision.