Close Menu
TrenderHQTrenderHQ

    Subscribe to Updates

    Get the latest creative news and more from TrenderHQ.

    What's Hot

    William Ruto biography: Age, career, and how Kenya’s fifth president rose to power

    September 22, 2026

    List of presidents of Nigeria: From 1960 to Bola Tinubu and how each leader left office

    September 21, 2026

    700 proverbs from around the world, their meanings and examples

    September 21, 2026
    Facebook X (Twitter) Instagram
    TrenderHQTrenderHQ
    • Home
    • Buzz
    • Lifestyle
    • Stories
    • World News
    • Sports
    • Health
    • Videos
    • HQ
    TrenderHQTrenderHQ
    Home » What is ransomware, how it started, and where it stands today
    Technology

    What is ransomware, how it started, and where it stands today

    Digital ReporterBy Digital ReporterSeptember 17, 2026Updated:September 17, 20269 Views
    WhatsApp Facebook Twitter Copy Link LinkedIn Telegram Email
    ransomware
    This image is for illustrative purposes only

    Ransomware is a type of malicious software that blocks access to a victim’s files or systems, usually by encrypting them, and then demands payment in exchange for restoring access [1]. It has grown from a clumsy floppy disk scam in the 1980s into a global criminal industry that now hits an organisation somewhere in the world roughly every 19 seconds [10]. This article traces that path using documented history and current data, and separates the parts of the ransomware story that are proven from the claims that are exaggerated or unverified.

    How it began: a biologist and 20,000 floppy disks

    The first documented ransomware attack happened in 1989, decades before most people had ever touched a computer. Dr Joseph Popp, a Harvard trained evolutionary biologist, mailed around 20,000 infected floppy disks labelled “AIDS Information Introductory Diskettes” to attendees of a World Health Organization AIDS conference [2, 3, 4]. The disk contained a program that appeared to assess a person’s risk of contracting AIDS, but hidden inside was malware that counted the number of times the computer was switched on. After the 90th reboot, it hid directories and encrypted file names on the machine, then demanded $189 be sent to a post office box in Panama to restore access [2, 3].

    This attack, known as the AIDS Trojan or PC Cyborg, is considered the starting point of ransomware history, but it was not a sophisticated threat. It used a simple, symmetric encryption method, and security researchers were able to build tools that reversed the encryption without paying [5]. Because home internet access and email were not yet widespread, it took more than a decade for ransomware to reappear as a meaningful threat [5].

    The modern era begins: 2013 to 2017

    Ransomware re-emerged as a serious problem once two things existed together, widespread broadband internet and an anonymous digital payment method. Bitcoin, created in 2009, provided exactly that [6].

    In 2013, CryptoLocker marked what most security researchers consider the start of the modern ransomware era. It spread through phishing emails and compromised websites, used strong encryption that could not be broken without the attacker’s private key, and demanded payment in Bitcoin [6, 7]. In its first two months alone, CryptoLocker generated around $27 million for its operators, and by the time it was disrupted, the FBI attributed roughly that same total to the group [6, 8].

    Two other shifts followed quickly. In 2015, the Tox ransomware kit introduced the ransomware as a service model, letting people with little technical skill rent ready made ransomware tools and split the profits with the developer [9]. This lowered the barrier to entry for cybercrime dramatically and remains the dominant business model behind ransomware today.

    Then came 2017, described by several security firms as ransomware’s watershed year [7, 9]. In May, WannaCry infected more than 230,000 computers in over 150 countries within four days, using a leaked United States National Security Agency exploit called EternalBlue to spread itself automatically between vulnerable Windows machines, without needing anyone to click a malicious link [7, 8]. It disrupted the United Kingdom’s National Health Service and telecom companies across multiple countries, and researcher Marcus Hutchins is credited with slowing its spread by activating an accidental kill switch built into the code [7]. Total damage from WannaCry is estimated at around $4 billion [7].

    Weeks later, a related attack called NotPetya used the same EternalBlue exploit but behaved differently. It initially looked like ransomware, but it permanently destroyed data rather than allowing recovery even after payment, leading researchers to reclassify it as a wiper malware disguised as ransomware [9, 11]. NotPetya has been attributed to Russian state backed actors by the governments of the United States, United Kingdom, and Australia, and its damage, including a reported $300 million hit to shipping company Maersk alone, brought the combined cost of WannaCry and NotPetya to more than $10 billion [7, 11, 12].

    Double extortion and “big game hunting”

    From around 2018 onward, ransomware groups shifted tactics again. Rather than only encrypting files, groups such as Maze began stealing a copy of sensitive data before encrypting it, then threatening to publish that data publicly if the victim refused to pay, a tactic now known as double extortion [9].

    This meant that even organisations with solid backups, which could restore their systems without paying, still faced pressure to pay to prevent a data leak.

    Around the same period, the group behind Ryuk ransomware popularised “big game hunting,” deliberately targeting large organisations capable of paying multimillion-dollar ransoms rather than spreading indiscriminately [9].

    ransomware
    This image is for illustrative purposes only

    Today, double extortion is close to standard practice. Recent industry data puts the share of ransomware intrusions that combine data encryption with data theft at around 77 to 88 percent, up sharply from just a few years earlier [13, 14].

    Myth: ransomware groups are permanently destroyed by law enforcement takedowns

    Major law enforcement operations against ransomware groups are real and well documented, but the claim that a takedown “ends” a ransomware group is not supported by what has actually happened. In February 2024, a joint United States and United Kingdom operation known as Operation Cronos seized LockBit’s infrastructure, published internal data from the group, and charged several affiliates, after LockBit had reportedly hit more than 2,000 organisations and extracted over $120 million [13, 15]. Around the same time, the BlackCat/ALPHV group collapsed, reportedly after its administrators ran an exit scam and kept a $22 million ransom paid by healthcare company Change Healthcare instead of sharing it with affiliates [16, 17].

    Neither disappearance reduced overall ransomware activity. Displaced LockBit and BlackCat affiliates simply moved to other groups, and RansomHub absorbed much of that talent, becoming the most prolific ransomware operation of 2024 with more than 700 disclosed victims before it too declined sharply by the end of 2025 [16, 17, 18]. LockBit itself resurfaced under a new version in 2026 and had posted 163 victims by the first quarter of the year, re-entering the top tier of active groups despite the earlier takedown [19]. Security researchers now describe the pattern plainly: takedowns disrupt and fragment the ransomware ecosystem, but code gets reused and affiliates get re-recruited elsewhere, so the overall market keeps growing even as individual brand names rise and fall [18, 20].

    Myth: paying the ransom means you get your data back

    This is one of the most persistent and dangerous misconceptions about ransomware, and the data consistently contradicts it. Independent research from Halcyon found that 84 percent of organisations that paid a ransom in the fourth quarter of 2024 still failed to fully recover all of their data [21]. Separate research from Fortinet found that only about 4 percent of organisations that pay a ransom recover everything, and that 80 percent of organisations that pay are attacked again within 12 months [10, 21].

    Sophos, whose annual State of Ransomware survey covers thousands of organisations across 17 countries each year, found that in its 2025 data only around 65 percent of healthcare sector data was actually restored among organisations that paid [21]. Because of this, the United States FBI and most national cybersecurity authorities explicitly advise against paying ransoms, and instead recommend reporting incidents to law enforcement, which the FBI’s own data suggests saves victims an average of $470,000 to $990,000 per incident, partly because free decryption keys are sometimes already available from earlier law enforcement operations [13, 21, 22].

    Where things stand in 2026

    The overall trend in 2026 is one of two things happening at once, rising attack volume and improving defences. Ransomware now appears in 44 to 48 percent of all data breaches tracked by Verizon’s Data Breach Investigations Report, and attack volume rose an estimated 58 percent in 2025 alone [10, 13]. The FBI’s 2025 Internet Crime Complaint Center report, published in April 2026, documented 63 new ransomware variants that year, close to five and a quarter new variants every month, with Akira, Qilin, RansomHub, LockBit, and Medusa named as the five variants with the greatest impact on critical infrastructure [20].

    At the same time, Sophos’s seventh annual global survey, covering more than 2,100 IT and security leaders across 17 countries, found genuine progress. The proportion of victims who ended up paying a ransom fell to 48 percent in 2026, the lowest recorded in three years, while the share who successfully recovered encrypted data using backups rose to 66 percent, up from 54 percent a year earlier [22, 23]. Median ransom demands themselves have fallen sharply too, from around $2 million in 2024 to roughly $698,000 in the most recent Sophos data, largely because organisations have gotten more confident refusing or negotiating down extortion demands [22, 23]. However, this masks a separate finding, the total cost of recovering from an attack, excluding any ransom paid, has kept climbing, averaging around $1.7 million per incident in 2026, an 11 percent rise on the previous year [24].

    The market itself has also fragmented rather than consolidated. A widely cited 2026 industry report found that, unlike previous years which had one dominant group defining the landscape, 2026 saw growth spread across a wider set of operators using different strategies, from Qilin’s high volume approach across dozens of countries to Clop’s mass exploitation of single software vulnerabilities to hit hundreds of victims at once [18].

    Ransomware in Africa and Asia

    Ransomware is often reported as a mainly Western problem because the United States alone accounts for roughly half of all publicly confirmed attacks, a gap partly explained by the country’s mandatory breach disclosure and SEC reporting rules that force more incidents into public record than most other jurisdictions [20, 25]. The picture in Africa and Asia is different in character but no less serious.

    INTERPOL’s 2025 Africa Cyberthreat Assessment Report identified ransomware, online scams, and business email compromise as the most prevalent cyberthreats across the continent, and found that 90 percent of African countries reported needing significant improvement in their cybercrime law enforcement and prosecution capacity [25]. Check Point Research’s regional tracking in mid-2026 recorded Africa averaging roughly 3,008 attempted cyberattacks per organisation per week, close behind the Asia-Pacific region’s 3,060 [26].

    Asia-Pacific has become one of the fastest growing regions for ransomware specifically. Group-IB’s 2026 regional data named India as the most targeted country in the Asia-Pacific region in February 2026, followed by Thailand, Australia, and Taiwan, with manufacturing accounting for nearly 27 percent of regional incidents [27]. Healthcare institutions in Indonesia and Japan have also been named as targets during 2026, including a reported $100 million ransom demand against a Japanese hospital that the organisation did not pay [27, 28, 29].

    What to do during an active ransomware attack, according to CISA and the FBI

    Much of what circulates online about responding to ransomware is generic advice with no clear source behind it. The most authoritative guidance available is the joint #StopRansomware Guide published by the United States Cybersecurity and Infrastructure Security Agency, together with the FBI, the National Security Agency, and the Multi-State Information Sharing and Analysis Center, which lays out a specific, sequenced checklist for the moment an attack is discovered [30, 31].

    The guidance is explicit that the first three steps should be followed in order, before anything else.

    1. Isolate the infected systems immediately. Disconnect the affected device or devices from the network first. If several systems or an entire subnet appear affected, CISA recommends taking the network offline at the switch level rather than trying to unplug each device one by one [30, 31, 32].
    2. Only power a device down if you genuinely cannot disconnect it from the network any other way. Powering off before disconnecting destroys evidence stored in the device’s volatile memory that investigators may need later, so disconnection is always the preferred first move [31, 33].
    3. Once isolation is complete, triage the affected systems for recovery, prioritising the ones your organisation needs most to keep operating [32].

    A few further points from official guidance and incident response practitioners matter just as much in the first hours of an attack.

    • Coordinate the isolation quietly, using phone calls or other communication that does not run over the network the attacker may be watching. CISA’s own response checklist warns that tipping off attackers that they have been detected can cause them to move laterally to preserve their access, or to trigger the ransomware more widely before containment is complete [33].
    • Photograph any ransom note with a separate device rather than the infected one, and avoid deleting, reformatting, or reinstalling anything before your incident response plan or a forensic team has examined it [34].
    • Activate your incident response plan and involve leadership, legal counsel, IT vendors, and cyber insurance providers early, even before the full scope of the attack is known [34, 35].
    • Report the incident to law enforcement as early as possible, through the FBI’s Internet Crime Complaint Center in the United States or the equivalent national cybercrime unit elsewhere. Incident response practitioners are clear that this is not an admission of failure. It gives investigators access to subpoena power, threat intelligence tying the attack to known campaigns, and sometimes free decryption tools left over from earlier law enforcement operations, and as noted above, the FBI’s own data shows early reporting saves victims hundreds of thousands of dollars on average [13, 21, 22, 34].
    • Do not pay the ransom before exhausting other options. CISA, the FBI, and Canada’s Canadian Centre for Cyber Security all advise against payment, both because it does not guarantee recovery, as the data earlier in this article shows, and because it funds further attacks [21, 35].
    • Only reconnect systems and restore data once the incident has formally been declared over by your designated IT security authority, restoring from offline backups and taking care not to reintroduce the infection into systems that are already clean [31].

    This sequence exists because the earliest minutes of a ransomware incident largely determine how far it spreads. Attackers who realise they have been spotted will often try to encrypt or steal as much as possible before losing access, so containment speed, more than any single perfect decision, is what current expert guidance treats as the priority in the moment [34, 36].

    What actually reduces ransomware risk

    Based on the documented data above rather than assumption, a few practices have a genuine, measurable track record.

    • Maintaining tested, offline backups matters more than almost anything else. Backup based recovery, not ransom payment, is now the leading way organisations get their data back, used successfully in 66 percent of 2026 cases [22, 23].
    • Multi factor authentication and identity security are increasingly central. Sophos’s 2026 research found ransomware attacks increasingly begin with stolen identities and credentials rather than software vulnerabilities, which dropped from the leading root cause at 32 percent to just 18 percent in a single year [22].
    • Reporting incidents to law enforcement rather than negotiating quietly has a measurable financial benefit, saving victims hundreds of thousands of dollars on average and sometimes surfacing existing free decryption tools [13, 21].
    • Refusing to pay, where recovery through backups is possible, avoids funding future attacks and does not guarantee data return in any case, per the recovery statistics above [10, 21].

    Ransomware’s story, from one biologist’s floppy disks to a fragmented, multi billion dollar criminal industry, is really a story about incentives. Every time defenders close one opening, whether a specific software vulnerability or a specific criminal brand, the underlying economics of ransomware push attackers toward the next one. The documented data through 2026 shows that defences are working better than before, but the overall market has not shrunk, it has simply changed shape.

    Disclaimer: This article reflects cybersecurity research and reporting current as of September 2026, and is provided for general information only. It is not incident response, legal, or professional advice for any specific situation, and ransomware statistics vary between reporting organisations because they track different datasets, so figures are best treated as directional trends rather than fixed totals. If your organisation is currently experiencing a ransomware attack, or you are deciding how to respond to one, consult your own IT security team, an incident response provider, and legal counsel before taking any action, since the right sequence of steps can depend on details specific to your systems, your jurisdiction’s breach notification laws, and your existing incident response plan. If you spot an error or an outdated figure in this article, please contact us at TrenderHQ, we welcome the correction.

    Reference

    • [1] AIDS Trojan | PC Cyborg | Original Ransomware, KnowBe4
    • [2] Ransomware history highlights: from AIDS Trojan to Locky, Veeam
    • [3] A Brief History of Ransomware, Varonis
    • [4] Ransomware Turns 35. How It All Started In 1989, Cybersecurity Ventures
    • [5] The First Ransomware Attack: Lessons Learned from History, Ransomware.org
    • [6] Ransomware history: emergence and evolution, Stormshield
    • [7] The History and Evolution of Ransomware Attacks, Flashpoint
    • [8] Tracing the History of Ransomware: Major Attacks and Developments, CyberMaxx
    • [9] The History and Evolution of Ransomware, TechTarget
    • [10] Ransomware Statistics 2026 | 48 Facts From Verizon, Sophos and IBM, CNIC Solutions
    • [11] The Evolution of Ransomware: A Case Study of WannaCry and NotPetya, ResearchGate
    • [12] The History and Evolution of Ransomware, BlackFog
    • [13] Ransomware Statistics [2026]: Costs, Trends and Attack Data, StationX
    • [14] 2026 Global Ransomware Statistics Key Trends and Costs, DeepStrike
    • [15] 46 Ransomware Statistics and Trends Report 2026, VikingCloud
    • [16] Ransomware Trends 2026: AI Attacks and Defense Strategies, Adaptive Security
    • [17] Ransomware Surged 49 Percent: 8,159 Victims 2026, Shattered.io
    • [18] 2026 Ransomware Report: 7,551 Victims, Up 24.9 Percent, Black Kite
    • [19] Ransomware Statistics 2026: Attacks, Costs and Trends, Complete Guide, Axis Intelligence
    • [20] Ransomware Statistics 2026: Attacks, Costs and Trends, Bits From Bytes
    • [21] Ransomware Recovery Cost 2026: 1.53M Mean Plus Sector Breakdown, Axis Intelligence
    • [22] Ransomware 2026: 79 Percent of Attacks Start With Stolen Identity, The Source Code
    • [23] The Evolution of Ransomware in 2026: Key Takeaways from Global Report, SecureWorld
    • [24] Sophos Ransomware Report 2026: Email and Identity Attacks Surge as Recovery Cost Hits 1.7 Million, InfotechLead
    • [25] Ransomware Trends 2026: AI Attacks and Defense Strategies, Adaptive Security
    • [26] New Ransomware Leader Emerges as Global Cyberattacks Rise in June 2026, Intelligent CISO
    • [27] Ransomware 2026 Trends: Attacks Up, Payments at 23 Percent Low, Tech Insider
    • [28] July 2026 Threat Trend Report on Ransomware, ASEC
    • [29] Healthcare ransomware attacks rose 14 percent in first half of 2026, report finds, DOTmed
    • [30] #StopRansomware Guide, CISA
    • [31] I’ve Been Hit By Ransomware!, CISA
    • [32] Ransomware Response Checklist, CISA
    • [33] Ransomware Response Checklist, CISA (PDF)
    • [34] Ransomware Incident Response: Your Complete Preparation Guide, Adaptive Security
    • [35] A Practical Guide for Ransomware Response, TruvoCyber
    • [36] Ransomware Response Checklist: Step-by-Step Guide for 2026, IR-OS

    Share this:

    • Share on Facebook (Opens in new window) Facebook
    • Share on X (Opens in new window) X
    Ransomware
    Share. WhatsApp Facebook Twitter LinkedIn Email Telegram Copy Link
    Digital Reporter

    Digital Reporter is a section under TrenderHQ's editorial team. We make every effort to ensure our information is accurate, though occasional errors may occur. Readers are encouraged to verify details with other trusted sources. For corrections, updates, or feedback, please email: info@trenderhq.com. To advertise with us or support our cause through a donation, reach out via our contact page or email: hello@trenderhq.com

    Related Posts

    The world’s best-selling phones of 2025: what the data actually shows

    September 17, 2026

    61 AI tools and what they’re best known for

    September 15, 2026

    File systems explained: How FAT32, NTFS, exFAT, ext4, APFS and others store your data

    September 15, 2026
    Leave A Reply Cancel Reply

    Ads
    Demo
    Top Posts

    Odo Broni: Daddy Lumba’s Wife Priscilla Ofori

    July 30, 20252,811

    10 Simple Steps to Achieve Greatness in Your Life

    August 13, 20232,360

    British Man who posted luxury on social media gets drugged and murdered for his watches!

    January 13, 20232,122

    Christmas Dates for the Next 10 Years (2024 – 2033)

    November 28, 2024952
    Don't Miss
    Lifestyle

    William Ruto biography: Age, career, and how Kenya’s fifth president rose to power

    September 22, 20264

    William Samoei Ruto, born 21 December 1966 in Sambut, Kenya, is now 59 and has…

    Share this:

    • Share on Facebook (Opens in new window) Facebook
    • Share on X (Opens in new window) X

    List of presidents of Nigeria: From 1960 to Bola Tinubu and how each leader left office

    September 21, 2026

    700 proverbs from around the world, their meanings and examples

    September 21, 2026

    Salary transparency: Is it helping or hurting employers who adopt it early?

    September 21, 2026

    How to build an employer brand that attracts top talent in a competitive market

    September 21, 2026

    Skills-based hiring vs degree hiring: What the latest global data shows

    September 21, 2026

    Oceania and Australia’s time zones explained: The complete list

    September 21, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news and more from TrenderHQ.

    TrenderHQ © 2026 | powered by Intek Multimedia.

    • About Us
    • Contact
    • Privacy
    • Disclaimer
    • Services
    • Advertise

    Type above and press Enter to search. Press Esc to cancel.