./resources / blog

Ransomware in 2026: Double Extortion & Defense

Ransomware stopped being a single piece of malware years ago. Today it is a criminal supply chain — affiliates, brokers, and negotiators — that steals your data before it ever encrypts a file. Defending against it means breaking the intrusion at every stage, not just restoring from backup.

The word "ransomware" still conjures a single image: a skull on a locked screen demanding payment for a decryption key. That picture is a decade out of date. Modern ransomware is the final act of a deliberate, human-operated intrusion that may have begun weeks earlier. Understanding the campaign as a chain of steps — each one an opportunity to detect and stop it — is the foundation of effective defence.

Intrusion kill chain & controls InitialAccess Execution Persistence CredentialAccess LateralMovement Exfiltration Encryption MFA / patch EDR Hardening LAPS / tiering Segmentation DLP / egress Immutablebackups Preemptive Cyber Security
Figure 1. Each stage of the intrusion is an opportunity to break the chain — the accent nodes map a concrete defensive control to every step.

Ransomware-as-a-Service

The economics changed everything. Ransomware-as-a-Service (RaaS) splits the crime into specialised roles. A core group develops and maintains the ransomware, the leak site, and the payment infrastructure. Affiliates rent that toolkit and carry out the intrusions, sharing a cut of the proceeds. Initial access brokers sell ready-made footholds — valid VPN credentials, exposed remote services, or already-compromised hosts. This division of labour means an attacker no longer needs to write malware; they only need to buy access and follow a playbook, which is why the volume of attacks has stayed stubbornly high.

Double and triple extortion

Encryption alone became a weak form of leverage once organisations improved their backups — so attackers added pressure. Double extortion steals data before encrypting it, threatening to publish it on a leak site if the ransom is not paid. Restoring from backup no longer makes the problem disappear, because the stolen copy is still in the attacker's hands. Triple extortion piles on further: contacting the victim's customers directly, launching denial-of-service attacks, or threatening regulatory disclosure. The lesson is stark — a good backup protects availability, but it does nothing for confidentiality once data has been exfiltrated.

The intrusion kill chain

Human-operated ransomware follows a recognisable sequence, shown along the top of Figure 1. It begins with initial access — phishing, a stolen credential, or an exposed service. Then comes execution of tooling, persistence to survive reboots, credential access to harvest more privileges, and lateral movement across the network toward high-value systems. Only near the end do attackers perform exfiltration of the data they intend to hold hostage, followed by mass encryption. Crucially, that whole sequence often unfolds over days, giving defenders a window to intervene.

Dwell time is your opportunity

The gap between initial access and encryption is called dwell time, and it is where defence is won or lost. An attacker who is detected during credential access or lateral movement can be evicted before any data leaves or any file is encrypted. Every stage crossed without detection, however, compounds the damage.

Layered defence, mapped to the chain

The accent row in Figure 1 pairs each stage with a control that disrupts it. Phishing-resistant multi-factor authentication and disciplined patching shrink the initial-access surface. Endpoint detection and response (EDR) catches execution and suspicious behaviour. System hardening removes the footholds attackers use for persistence. Local admin password randomisation (LAPS) and tiered administration blunt credential theft. Network segmentation constrains lateral movement. Data-loss prevention and egress monitoring flag exfiltration. And immutable backups ensure that even successful encryption is survivable. No single control is sufficient; their overlap is the point.

Backups are the control of last resort — but only if they cannot be altered or deleted. An attacker who can encrypt your backups has no reason to negotiate.

Immutable backups and recovery

Because attackers now hunt for backup systems specifically, the backup strategy must assume the production environment is fully compromised. Immutability — write-once storage that cannot be modified or deleted for a defined retention period — is what makes backups trustworthy under attack. Equally important is the ability to actually restore: an untested backup is a hypothesis, not a plan. Regular, timed recovery drills turn "we have backups" into a defensible recovery-time objective. Guidance from national bodies such as CISA reinforces offline, immutable, and regularly tested backups as core to resilience.

Prepare to respond, not just prevent

Prevention will sometimes fail, so the mature organisation rehearses the response. A ransomware-specific incident plan defines who declares an incident, how systems are isolated, when law enforcement is engaged, and how the organisation communicates while its primary systems may be down. Tabletop exercises expose the gaps — missing contact lists, unclear decision authority, backups nobody has restored — long before a real incident does. The goal is to make the worst day a rehearsed procedure rather than an improvisation.

Key takeaways

  • Ransomware is a criminal service economy — affiliates and access brokers, not lone malware authors.
  • Double and triple extortion mean a clean restore no longer resolves the incident; stolen data stays stolen.
  • Human-operated attacks follow a kill chain, and dwell time gives defenders a window to intervene.
  • Defence is layered — a specific control maps to each stage, from MFA to segmentation to immutable backups.
  • Immutable, tested backups and a rehearsed incident plan turn a catastrophe into a recoverable event.
#ransomware #threat #backups #defense
All articles Test your ransomware readiness