What is Ransomware?
Ransomware is malware used to deny access to data or systems and demand payment. Many operators also steal data and threaten disclosure. This combination is often called double extortion. Some extortion campaigns use stolen data without encrypting files. Prepare with tested offline or isolated backups, strong access controls, segmentation, logging, incident response, and controls for common initial-access paths.
Why it matters
Ransomware can stop operations, destroy or encrypt recoverable data, and expose sensitive information. Recovery depends on preparation that starts before the attacker enters the environment.
How it works
- An operator gains initial access through a stolen credential, exposed service, malicious code, social engineering, or another entry path.
- The operator discovers systems, raises privileges, moves to other resources, and can steal data before disruption.
- The malware or operator encrypts or destroys data, interrupts services, and demands payment or threatens disclosure.
Example
An attacker steals an administrator password but cannot use the protected administration route without the required identity-provider session, device context, and Pomerium policy decision. The organization still isolates the endpoint and restores affected data from tested backups.
Pomerium boundary
Pomerium can restrict and log access to applications and administration services that use protected routes. Identity and context policy can reduce one credential-based access path. Pomerium does not detect endpoint malware, protect bypass paths, or replace isolated backups and incident response.
Limits and non-claims
- No single access control prevents every ransomware entry path or action.
- A gateway cannot protect unmanaged endpoints, direct network paths, or data that attackers reach through another service.
- Paying a demand does not guarantee data recovery, deletion of stolen data, or an end to disruption.
Evaluation checklist
- Which identities, privileges, data stores, control planes, and backups can the attacker alter or encrypt?
- Which credential theft, remote access, execution, and lateral path reaches them?
- Can operators isolate access, revoke authority, preserve evidence, and restore tested clean backups?
