Skip to main content Scroll Top

How ransomware gangs pressure victims, and how to reduce your risk

FTI Insights: Security

Most people picture ransomware as a message on the screen: your files are locked, pay to get them back. That is still part of it. But the groups behind today’s attacks run something closer to a business, and by the time the ransom note appears they have usually been inside the network for days, copying data, collecting passwords and switching off defenses.

As of September 2026, the numbers are still sobering. Sophos’s State of Ransomware 2026 survey of 2,158 IT and security leaders (responses gathered January to March 2026) found that 56% of attacks succeeded in encrypting data, and put the average cost of recovery at about $1.7 million, before any ransom.

Understanding how an attack works makes the defenses make sense. None of them is magic, but together they reduce your risk considerably and shorten recovery if the worst happens.

How a modern attack unfolds

1. Getting in

Attackers usually walk in through an unlocked door rather than break a wall. Increasingly, that door is someone’s login. In its 2026 Active Adversary Report, drawn from the incidents its own response teams handled, Sophos found that about two-thirds of root causes were related to compromised identity: stolen or guessed passwords, phishing and similar. Multifactor authentication was missing in 59% of cases. Exploited vulnerabilities, meaning known security flaws that had not been patched, remain a major route in, especially on firewalls and VPNs.

The same report found attackers moved quickly (a median of three days inside before detection) and deployed ransomware outside business hours in 88% of cases, when fewer people are watching.

2. Collecting passwords

Once inside, the goal is more access. In an incident Sophos investigated in July 2024, attackers using the Qilin ransomware got in through a VPN (remote access) portal that had no multifactor authentication, using stolen credentials. They later pushed a script to every computer on the network that collected the passwords saved in Google Chrome each time a user logged in. One breach became access to every web account those staff had saved in their browser.

Passwords are also stolen in bulk by “infostealers”, malware built to harvest saved passwords, browser cookies and payment details, whose results are then sold to other criminals. In May 2025, Microsoft led legal action against one called Lumma, reporting that it had identified more than 394,000 infected Windows computers in the two months before. This is not only a Windows problem, either. Sophos reported in September 2024 that information stealers made up more than half of its macOS detections over the previous six months, led by one called Atomic macOS Stealer. These are typically spread through fake installers for popular apps, promoted through ads and search results, and they go after saved passwords, browser cookies and the macOS Keychain.

3. Switching off the alarm

Before the main attack, criminals try to disable security software. Sophos has tracked a toolset for years that loads a malicious driver deep in Windows to shut down or even delete endpoint protection, and reported in August 2024 that its authors kept swapping stolen or forged code-signing certificates to stay ahead of blocks. The lesson for a business is simple: an attacker’s first job is to blind you, so your security tools need to resist being turned off.

4. Stealing, then encrypting

Only then comes the part most people know. Data is copied out, files are encrypted (scrambled so they cannot be read without a key), and a ransom is demanded. Stealing the data first gives the criminals leverage even if you can restore from backup: pay, or we publish it.

How the pressure works

In research published in August 2024, Sophos X-Ops documented how ransomware groups turn up the heat on victims who do not pay quickly. Tactics they described include:

  • Threatening to contact customers, partners, the media and regulators.
  • Publishing the names and personal details of executives and staff.
  • Claiming to have combed the stolen data for legal or financial problems.
  • Encouraging customers whose data was taken to sue.
  • Phoning employees and customers directly.

What about AI? The Active Adversary Report found that AI is adding scale and noise, such as more convincing phishing emails, but has not yet replaced the hands-on work of an attack. The basics below still decide most outcomes.

The aim of all this pressure is to make you feel that paying is the fastest way to make it stop. Paying offers no assurance the data is deleted or that you will not be targeted again. The best time to decide how you would respond is now, calmly, not in the middle of an incident.

Practical steps that reduce risk

These line up with CISA’s #StopRansomware Guide and with what the Sophos research above shows attackers relying on.

  • Backups kept separate. Keep at least one copy of critical data offline or otherwise out of reach of your normal network accounts, and test restoring from it. Backups an attacker can reach, they will try to delete.
  • Multifactor authentication everywhere it counts. Email, VPN and remote access, cloud services and administrator accounts first. MFA means a second proof of identity beyond the password, such as an app prompt or a security key. The Qilin case above started with a VPN that lacked it. Passkeys and security keys resist phishing better than text-message codes.
  • Patch promptly. Prioritize anything reachable from the Internet: firewalls, VPNs and remote access servers. See Windows updates: timely, not rushed for how we balance speed and stability.
  • Endpoint protection with tamper protection. Tamper protection stops the security agent from being disabled or removed without authorization, which is exactly what attackers try first. Pair it with people watching the alerts around the clock, including nights and weekends, when most ransomware is launched.
  • Stop saving passwords in the browser. Use a proper password manager, and change passwords for other services after any breach.
  • Staff awareness. Teach people to install software only from official sources, question unexpected password prompts, and report odd emails quickly. A fast report is worth more than a perfect one.
  • An incident plan. Know who to call, how to isolate machines, where the offline backups are, and who speaks to customers. Write it down and walk through it once a year.

How FTI helps

Our managed IT service covers most of that list as routine work, built on Kaseya and secured with Sophos firewall, endpoint and email protection, with tamper protection on and backups kept out of reach. We explain that choice in Why we chose Sophos.

Our biggest advantage is AI-assisted operations. AI watches monitoring data and security logs all the time and puts the full picture in front of our engineers, who decide and act. With our help desk staffed 24/7 and senior engineers on call, an alert at 2 a.m. gets a person.

No setup makes a business immune. The goal is to make you a harder target, catch problems early, and be able to recover without paying anyone.

Talk to us about protecting your business from ransomware