Ransomware is malicious software, or an extortion tactic built around it, that blocks access to systems or data until payment is demanded. It usually encrypts files, disables services, or threatens to publish stolen information. The goal is not only to stop operations but also to create pressure by making recovery slow, uncertain, and expensive.
It matters in cyber security because ransomware can interrupt business, expose sensitive data, and force incident response under time pressure. In real attacks, threat actors often combine encryption with data theft, public leak sites, and naming-and-shaming claims to increase leverage. Defenders look for signs such as unusual privilege use, remote access abuse, file-encryption activity, and suspicious outbound transfers. Good defenses include patching, multi-factor authentication, network segmentation, least privilege, offline or immutable backups, and tested recovery plans. These controls do not guarantee prevention, but they reduce impact and make extortion less effective.


