Ransomware is malicious software that encrypts files, may steal them and can block an entire computer system. Criminals demand payment to restore access and may threaten to publish the stolen information. Even if the victim pays, recovery is not guaranteed. The consequences include financial losses, downtime, reputational damage, lost trust and, in extreme cases, bankruptcy.
Ransomware is on the rise
According to CERT Polska, ransomware was one of the greatest cybersecurity threats in Poland. A Sophos study cited by CERT Polska found that 77% of surveyed organizations had experienced ransomware, compared with 13% in 2020. The affected sectors included digital infrastructure, public administration, education, healthcare, water utilities, trade, manufacturing, insurance, tourism, transport, construction, real estate and logistics.
Criminals increasingly use multiple extortion. They demand money not only for decrypting files, but also for not informing customers, business partners, regulators or the public about a breach. If they steal partner or customer data, those organizations can become the next targets. One campaign can therefore create a domino effect affecting thousands of entities.
It starts with phishing
Ransomware can spread through malicious websites and vulnerable services, but phishing remains one of the most common entry points. Attackers send links or attachments in formats such as DOC, XLS, PDF or HTML. Opening the message may download malware or connect the victim to a site controlled by the criminal.
After execution, the malware may remain dormant on a network drive or run immediately. It scans local and network storage for valuable file types, then encrypts, steals or destroys them.
Money is (not) everything
CERT Polska reported that the average global loss from a ransomware attack almost doubled, from less than USD 800,000 in 2020 to more than USD 1.8 million in 2021. Nearly half of attacked companies paid the ransom, compared with 32% in 2020. In Poland, the average ransom paid by affected companies was approximately PLN 670,000.
Ransomware also causes downtime, operational costs and lost business. Two-thirds of affected companies reported a decline in revenue; 22% lost between PLN 2.8 million and PLN 5.8 million, while one in ten recorded losses of up to PLN 29 million.
Strong encryption can make recovery without backups extremely difficult, but payment still does not guarantee the return of files. NotPetya demonstrated that decryption may be technically impossible. Paying also encourages criminals and provides resources for their next attack.
How to defend against a ransomware attack
When technical safeguards fail, an employee may be the last line of defense. If the attack is recognized quickly, the organization can limit its consequences. Continuous security awareness training and realistic phishing simulations help employees recognize suspicious messages and report them before ransomware is executed.
Combine education with tested, offline backups, timely patching, multi-factor authentication, restricted privileges, network segmentation and an incident-response plan. The goal is to make the company resilient enough to restore operations without negotiating with the attacker.

