Onlime helps you
Were you following the news on 12 May 2017?
If so, you have probably heard about what was, at the time, the largest cyberattack in the history of the internet – namely WannaCry, which quickly spread to the computers of both private individuals and companies. The attack hit Telefónica and several other large companies in Spain, FedEx, Deutsche Bahn, Maersk and companies in more than 150 countries around the world.
The aftermath of such an attack is enormous and the damage is great – so great that it is actually hard to grasp.
WannaCry is just one of many ransomware attacks that have wreaked havoc since the very first ransomware appeared almost 30 years ago. If you haven’t been hit by ransomware yet, then cross your fingers and read this article.
We will go through how to best protect yourself against ransomware so you don’t risk losing your valuable files.
Let’s get started.
What is ransomware?
Ransomware is an advanced type of malware that, once it infects you, prevents a user from accessing their files unless a ransom is paid (which, more often than not, still does not give the user access).
To avoid being caught by the authorities, the criminals behind ransomware accept cryptocurrencies – primarily Bitcoin – as payment of the ransom. Transfers in Bitcoin cannot be traced the way ordinary bank transfers can.
The name is a combination of the two words; “Ransom” – which means money demanded for release – and “malware” – which is a term that covers malicious software.
Broadly speaking, there are 3 types of ransomware:
Encryption ransomware
Encryption ransomware uses an algorithm to encrypt files on the affected device. To get the key to decrypt their files, the user is asked to pay a ransom.
Here are two examples of encryption ransomware:
The infamous CryptoLocker
When CryptoLocker broke out, it was called “the nastiest malware ever”, and not without reason.
The people behind CryptoLocker managed to earn roughly 3 million dollars (the equivalent of about 20 million Danish kroner, give or take), and the damage was severe. Although CryptoLocker was relatively easy to remove, the encrypted files on the victims’ computers remained encrypted to such a degree that it was practically impossible to decrypt them. Several victims have since reported that paying the ransom did not lead to the recovery of their files.
CryptoLocker was spread to PCs running the Microsoft Windows operating system. It was typically spread via attachments in emails – that is, PDFs, Word files, Excel files and so on, sent as though they came from trustworthy companies.
CryptoLocker spread between 5 September 2013 and the end of May 2014. It was spread by a so-called “botnet” (more on that later in the article) called Gameover ZeuS, until Interpol, the FBI and others took the botnet down.
CryptoWall
CryptoWall is the successor to CryptoLocker – but it is more sinister.
CryptoWall quickly overtook CryptoLocker’s rate of spread. The one group that (perhaps) is behind CryptoWall had, according to the FBI, already earned 325 million dollars by June 2015 – more than a staggering 2 billion Danish kroner. An astronomical sum.
CryptoWall has evolved since its origin – all the way up to version 4.0.
Lockout ransomware
Lockout ransomware is the type of malware that locks the user out of their device, so the person cannot access their system, files, data and so on. From there, the hacker behind it demands a ransom to give the user access to their device again.
An example of lockout ransomware is the one with the police theme.
In 2012, a wave of ransomware broke out that imitated the police in order to scare the affected user. The ransomware locked the victim out of their computer and then displayed a message claiming that the victim had broken several laws through their online activity – and therefore had to pay a “fine”.
In general, such scare campaigns are often used by the criminals behind these attacks, because fear is one of the ways they can get people to act without thinking.
That’s why you should remember to stay alert..
..if you receive an email that mainly makes you feel either guilty, lucky or lonely.
There are many strong emotions that can well up in us as humans – but we should never act on them right away. That is exactly what the criminals want. They are also human and therefore know our weaknesses.
Read also: Onlime gives the decade’s best computer advice 2010-2020
Leakware
Leakware (also called Doxware) is a type of malware where the user’s personal and private files (for example photos) are threatened with being leaked to others.
The dangerous thing about leakware is that it can be a combination of another type of ransomware that locks your files, and the threat of publishing your confidential files.
In an age with a strong focus on the sharing of nude images, leakware is just one more threat to privacy. This type of attack does, however, require a fair amount of groundwork for the hacker, and therefore politicians, celebrities and company executives are at the greatest risk.
Those were some of the different kinds of ransomware.
As you can probably sense, the threat is not small. IT criminals keep developing their digital arsenal in order to infiltrate users like you.
But keep calm.
If you know how the threat infects you, you can also get better at avoiding it.
That is why it is important to understand how it spreads!
How does ransomware spread?
IT criminals have a toolbox of methods they use to infect users. It is important to familiarize yourself with these methods so you can recognize them when you are exposed to them. You can probably already nod in recognition at the first one, at least.
Phishing (fake messages)
Phishing is a method that IT criminals use to lure the victim into a particular action. It might be to coax confidential information out of the user, or to get them to click on an infected link or attachment – which is a common route of infection for ransomware.
In phishing attacks, the IT criminals pretend to be another person or a “trustworthy” authority. It could be NemID, Danske Bank or a public institution, for example.
They might, for instance, claim in an email that they are from the tax authority (SKAT) and write to you that you have money owed back on your tax assessment – which you can claim by clicking a link. You should of course not do this. Delete the email immediately.
Another phishing trick is CEO fraud, where the scammer claims to be the CEO of a company. By emailing the company’s employees, the scammer can get them to click on links infected with ransomware.
Phishing isn’t just email – it is also seen via SMS (which is called “smishing”), chat messages on social media and more. The general rule is that IT criminals follow people to the places on the internet where they spend their time. Maybe you have already received strange messages on Facebook? Be careful – it isn’t necessarily from a friend!
The best thing you can do here is to be careful with the messages you receive. Never click on links or attachments if you aren’t completely sure they can be trusted. If you get an email from an acquaintance or a “trustworthy” sender that makes you wonder even the slightest bit, you should check with the sender by, for example, calling them.
Watch this info video from skat.dk about how to spot fake emails from the tax authority.
If you are in doubt about whether an email you have received is genuine, you are of course always welcome to contact us. We are good at spotting fake emails 🙂
Vulnerabilities in software
Consider for a moment how much software (how many programs) you have on your computer, your phone and perhaps also your tablet.
It might be Flash, the Microsoft Office suite, Spotify, Skype, various apps and much, much more.
Each piece of software can contain vulnerabilities that IT criminals can exploit. That means the more software you have – for example in the form of apps on your phone – the greater your risk of being hit by ransomware.
Always update your programs and apps!
Software providers continuously discover vulnerabilities and release patches (that is, a patch-up update). You should keep an eye on these and make sure to always update your electronic devices.
You should also be careful with software from an unknown provider. Watch out, for example, for which apps you download, since the provider may be bad at closing the vulnerabilities.
One way you can deal with these vulnerabilities is to use online-based versions of your programs. You can, for example, use Word Online through Onlime and avoid having Word installed on your computer at all.
Infected (“compromised”) websites
IT criminals can set up websites that spread ransomware.
In practice it works like this: the website – which the IT criminal has either set up themselves or hacked – contains a so-called “exploit kit”. An exploit kit is a tool that searches for a vulnerability on the victim’s computer (or other electronic device). By finding a vulnerability in software, the method can be used to infect the victim with ransomware.
The clever thing about exploit kits (for the IT criminals, that is) is that they infect the victim with ransomware automatically when the person visits the malicious website – instead of the victim having to actively click on a download.
Broadly speaking, you can be led to an infected website in three ways:
- By clicking on a malicious link in a phishing email that leads to an infected website
- By clicking on an ad on an otherwise legitimate website that leads to the infected website
- By visiting a previously legitimate website that has been hacked by an IT criminal and now redirects to an infected website. This accounts for 82% of all infected websites, according to the security firm Sophos.
Again, you should bear in mind that all your software (computer programs, apps and so on) should always have the latest updates.
Drive-by attacks
“Drive-by attacks” is the term for the type of attack where the victim does not actively do anything to get infected.
The infected websites with exploit kits mentioned above are therefore a type of drive-by attack.
Malvertising
Malvertising (a contraction of “malware” and “advertising”) is a method that IT criminals use to spread malware through ads on the internet.
It works by pushing ads – which lead to, for example, an infected website – out onto otherwise legitimate websites through advertising networks.
The major American news outlet The New York Times was hit by a malvertising attack in 2009, for example. It meant that many of the website’s users got a pop-up message warning them that they had been hit by a computer virus. The pop-up message also contained a link that falsely claimed it led to an antivirus program. In reality, the link led to malware.
Spotify has also been hit by a malvertising attack. It worked by giving Spotify users an ad that opened a browser with an infected website. As if some types of ads weren’t annoying enough already, it’s worth being aware that some of them can even turn out to be directly harmful.
Botnets
A botnet is a group of computers (or other electronic devices) that IT criminals control and use for malicious actions. The unsettling thing about botnets is that your computer can be part of one without you knowing it. That’s why it’s a good idea to read this part carefully:
A computer that is part of a botnet is called a “zombie” – but not in the literal sense of the supernatural creature from horror films. IT criminals use zombie computers either to steal your data or to carry out harmful actions. Or, most often; both at once.
Being part of a botnet is not the same as having ransomware. But if your computer is a zombie computer, IT criminals can use it to spam millions of internet users with ransomware.
The routes of infection for the malware that puts your computer into a botnet are the same as with ransomware – for example through infected links.
One sign that your computer is part of a botnet is if your computer is sluggish and slow to respond.
With a good anti-malware program, you can scan your computer and in many cases get rid of botnet malware. That’s not a guarantee, of course, but it’s a good place to start.
What are the consequences of ransomware?
Ransomware attacks target private individuals, companies and public organizations alike, and having your files encrypted is, without doubt, a troublesome experience.
As a private user, it can mean that your priceless family photos get encrypted, so you lose them forever. This consequence alone is enough to turn most people’s stomachs. Photos and videos are some of the most precious things in their digital lives, if you ask most people. The nostalgia of looking back at memories from the past is worth a great deal to a lot of people. Besides the loss of photos, it can also mean that your important documents, contracts and so on get encrypted, leaving you with a lot of hassle to deal with. For a private individual, the consequence is one of soft values – unlike for companies.
The consequences will be significant for companies and organizations, since these have many files that get encrypted. On top of that, several computers are connected to each other through the network, so ransomware can spread and do even greater damage than by hitting just a single computer. This can have both financial consequences for the company and, in the worst case, consequences for the employees in the form of layoffs.

An example of a public institution that has been hit by ransomware can be found at the hospitals in the Region of Southern Denmark. There, in just two months, they were hit twice by ransomware, and it led the region to send 20,000 employees on a course focused on IT security. The course is meant to strengthen the employees’ ability to recognize threats that can result in ransomware – for example the ones we have described in this post. If just one employee fails and ends up opening their computer to infection, it can, as in this case, have far-reaching consequences for a great many people.
The NHS (the national health service in England) has also been hit by ransomware. Here, however, the disaster was even worse, as they had to cancel operations and so on. It was a result of WannaCry – the largest ransomware attack ever.
WannaCry also hit French car factories, for example the company Renault, and it resulted in several of them having to stop production.
Region of Southern Denmark
The financial consequences of ransomware
Worldwide, ransomware has major financial consequences. Both in the form of the money that people feel compelled to pay the IT criminals, but also the damage to companies and organizations that the attacks cause in the form of lost production, downtime and so on.
Already back in 2015, ransomware attacks cost a full 325 million dollars according to Microsoft, and since then the volume of this type of attack has been rising. In fact, the volume of attacks increases by 350% annually (according to a Cisco report from 2016).
The security company Cybersecurity Ventures estimated that ransomware damage cost an estimated 5 billion dollars in 2017 – more than 15 times as much as in 2015.
Varying ransoms
The average ransom that the IT criminals behind ransomware demand to unlock victims’ files again was 679 dollars in 2016 (the equivalent of 4,370 Danish kroner).
However, the size of the ransoms varies a great deal, and the attacks targeted at specific organizations or companies tend to demand higher sums of money.
Things looked bad for a South Korean web company that was charged 1 million dollars (the equivalent of 6.5 million Danish kroner) to get its IT unlocked. The company had had 153 Linux servers locked, on which it stored more than 3,400 websites for customers – all of which were now locked.
So it wasn’t just a disaster for the web company, but also for its customer base of other companies that had to live with downtime on their websites.
Even though it is usually advised against, the South Korean company nonetheless chose to pay the ransom to the IT criminals. There was simply too much data and too much business at stake not to.
Even though the IT criminals behind ransomware attacks run a cynical “business model”, there are examples where they are nonetheless inclined to cooperate and actually help their victims.
In the case of the South Korean web company, the people behind the ransomware offered that the company could pay the ransom in three installments. At the same time, the company had managed to negotiate the ransom down from 1.62 million dollars (the equivalent of 10.5 million kroner).
The lack of morals among the IT criminals is hard to hide, though. It came to light, for example, when a hospital had its IT systems locked by ransomware. Here the ransom was nearly 3.7 million dollars (the equivalent of just under 24 million Danish kroner).
So ransomware comes with varying ransoms, and it is especially when organizations and companies are hit that we see the largest sums.
Who is behind ransomware?
The barrier to becoming an IT criminal who spreads ransomware is incredibly low.
For just 39 dollars, you can buy a lifetime license to a piece of software that can spread ransomware to countless users.
This is called ransomware as a service (RaaS), and it means you don’t have to be a sneaky hacker to be behind an attack. At the same time, it also means there isn’t just one person behind ransomware, but countless guilty parties.
The sale of ransomware-as-a-service licenses takes place over “the dark web”. It is the part of the internet that requires specific software or configurations to access. You can’t get onto the dark web simply through your normal internet browser.
On the dark web, IT criminals can anonymously sell and share illegal goods, for example weapons, drugs and, in this case, licenses to ransomware software.
There are several families of ransomware, and there are also several groups of people behind each family. From December 2015 to 2016, the number of ransomware families grew by a full 600%.
So the people behind it are busy, and it suggests there are several of them.
One particularly notable group is “Shadow Brokers” – a hacking group that made the large WannaCry attack possible by publishing a vulnerability in Windows that the NSA (National Security Agency) had discovered.
Shadow Brokers is notorious for publishing software vulnerabilities so that IT criminals can freely exploit them to target attacks against innocent victims. They use the aforementioned dark web to pass on – and even sell – the vulnerabilities.
So Shadow Brokers is only responsible for finding vulnerabilities that other hackers can exploit. It is not known whether the group itself is involved in carrying out ransomware attacks.
It is, after all, difficult to trace the people behind it – mainly because the ransoms are paid in the anonymous Bitcoin currency.
Here, however, is what has been determined about a couple of ransomware attacks:
- CryptoWall 4.0 was sent out from servers in Russia, according to the security company Bitdefender. That doesn’t necessarily mean the people behind it are from here, only that their servers, from which the victims’ computers downloaded CryptoWall, were located here.
- WannaCry was possibly created by hackers who speak fluent Chinese, according to researchers from Flashpoint. Others speculate that the attack originates from North Korea, but the researchers from Flashpoint have found evidence that the message was translated from another language into Korean. The researchers analyzed the 28 language variations of the ransomware message that popped up on victims’ computers demanding the ransom of 300 dollars in bitcoins. They found that only the English and Chinese versions appeared to have been written by a human.
In addition, there is one specific Russian man known to be behind the massive spread of CryptoLocker.
Here is the infamous hacker:
Evgeniy Bogachev: Russia’s most notorious hacker and the man behind the “Gameover ZeuS” botnet
Evgeniy Bogachev is said to be the mastermind behind CryptoLocker as well as the “Gameover ZeuS” botnet, which spread CryptoLocker to a high degree.
With a bounty of 3 million dollars (the equivalent of 19.3 million Danish kroner) for information leading the FBI to his capture, Bogachev is the most wanted IT criminal.
At his peak, Bogachev had control over more than one million computers around the world, which he used, among other things, to drain millions of kroner out of unsuspecting private citizens’ and companies’ bank accounts. Bogachev also used this network of computers to send out CryptoLocker en masse.
The US continuously keeps an eye on Bogachev in case he should try to leave his home country of Russia. But even though he has previously travelled internationally using three different fake passports, it is unlikely that he will take the risk and leave Russia, since he appears to be well protected there.
According to US intelligence, Bogachev is in league with the Russian government, which gladly turns a blind eye to his IT crime in order to boost its espionage capabilities.
As you can probably sense, it isn’t easy to single out specific perpetrators for all the evil IT crime spreading through our world. Many people are ‘accomplices’ without even being aware of it, while others pay a small share to take part in the ‘loot’ – almost like buying a stock. Ethics and morals are in short supply in the criminal world, both physically and digitally.
How has ransomware evolved over time?
Ransomware has changed significantly since the very first attack. Here are some of the most notable attacks in history.
The first attack ever: “the AIDS Trojan”
Although ransomware is a new concept for many people, the first attack actually dates all the way back to 1989 – from before email even existed. It was called the AIDS Trojan. The well-known ancient Greek tale of how Odysseus, after a 10-year siege, succeeds in capturing the city of Troy through cunning has given its name to the famous “Trojan horse”. The same name recurs in the IT world, where the principle is reused to conquer innocent computer users.
The term “trojan” in the PC world refers to malicious PC programs that are designed to deceive victims by disguising the programs’ true intent.
The story behind the AIDS Trojan is almost unbelievable. Just listen:
It started at the WHO’s international AIDS conference, where people from all over the world had gathered, including from Denmark. Every single participant at the conference was sent a package from a company called “PC Cyborg Organization”, and each package contained a diskette with the label ‘AIDS Information - Introductory Diskettes’ on it.
For the participants at the conference, it was plausible enough; they had taken part in a conference about AIDS, and now they were being sent material about the disease.
The diskettes – of which there were 20,000 in total – did indeed have a program on them that could assess a person’s risk of being infected with AIDS based on the person’s answers in an interactive survey. But the diskettes also contained what later got the name “the AIDS Trojan”. A virus that encrypted the victim’s files after the person had started up their PC 90 times.
After the encryption, a message appeared on the PC screen. Here the victim was asked to pay a ransom of 189 dollars by sending the money to a PO box in Panama.
A number of notable things set the AIDS Trojan apart from today’s ransomware:
- It infected via a diskette, rather than through, for example, emails or links
- The ransom was demanded in an analogue currency, the classic dollar, rather than the digital currency Bitcoin
- The money had to be sent off physically, rather than through an electronic transfer
The AIDS Trojan unfortunately had major consequences – both for private individuals, but especially for the hundreds of medical research institutions to which the diskettes had been deliberately distributed. According to The Independent, an AIDS organization in Italy lost 10 years of work because of the virus.
And who was the guilty party behind the AIDS Trojan?
The strange thing about the trojan was that the man behind it was not the archetypal criminal with a past in rough environments and a tainted criminal record.
No, the man behind it was Dr. Joseph L. Popp, a biologist with a PhD from Harvard. And given his background, no one can know what motives drove Popp to release his malicious code.
The story is rather paradoxical. Many of the victims were members of the World Health Organization’s international AIDS conference – but Popp himself was a part-time consultant for that very same organization in Kenya, and he was actively engaged in AIDS research.
The English newspaper The Guardian put forward his motive as being that he had been denied a job at the health organization. But the excuse that the judge ultimately accepted was that Popp was simply raving mad.
Fortunately, Popp was caught in good time – because a report later made clear that the doctor had plans to distribute an additional 2 million diskettes.
The attack nonetheless laid the groundwork for the cruel ransomware attacks that continue to plague technology today for private individuals, companies and organizations all over the world.
Six years after the attack, a set of encryption algorithms was invented called “public-key cryptography”. A technology that is the cornerstone of many ransomware encryptions.
Enough about the first attack. Let’s look at the ransomware attack that has had the greatest impact over time.
Namely WannaCry.
Read on.
The largest ransomware attack ever: “WannaCry”
WannaCry hit in more than 150 countries, where private individuals, companies, authorities and organizations had their data encrypted.
It happened on 12 May, when the attack broke out and spread at lightning speed. When an IT system was hit, the files on that system were encrypted. WannaCry was therefore an encryption ransomware.
As with other ransomware attacks, the victim was charged a ransom in Bitcoin – this time of 300 dollars – to get their files decrypted.
WannaCry stood out from the usual ransomware attacks because the attack could infect the user automatically – rather than requiring a manual action from the user first. The infection was through a vulnerability in the SMB protocol in Windows systems that had not been updated with a security update.
The vulnerability that made the whole attack possible was discovered by the NSA and then stolen and leaked by the hacking group Shadow Brokers.
WannaCry taught us an important lesson:
Always keep the software on your IT updated. Microsoft had, in fact, already released an update before the attack that blocked the hole WannaCry exploited. So for many, the attack could have been avoided if they had simply installed Microsoft’s update.
WannaCry also had a successor that some considered even more dangerous than WannaCry itself.
The successor was called Petya, and it could hit even very large companies – including the giant Maersk (which probably needs no introduction).
Petya was better at spreading itself, since the attack had two options: either through the vulnerability in Windows that WannaCry also exploited, or through two administration tools in Windows.
For an entire organization to be infected, only a single PC in the organization needed to have the vulnerability. Petya could then hit that one PC and spread to other PCs, even if they did not have the vulnerability.

For a huge company like Maersk, the ransomware attack cost an unimaginable amount of money.
This is what Maersk experienced – the company responsible for shipping every seventh container globally. The company had to check 80,000 servers and 1,100 IT systems for Petya.
Fortunately, Maersk managed to recover and start accepting bookings again after roughly 5 days.
Another company that lost an astronomical sum was the European building giant Saint-Gobain. The company estimates its own loss in sales at a full 1.9 billion Danish kroner as a result of the Petya attack. A large sum compared with the relatively small amount of just one million kroner that the people behind Petya and WannaCry are estimated to have earned.
What is the solution to ransomware?
Phew…
This article has been a big read with many concrete examples of how badly things can go for both companies and private individuals when ransomware attacks happen.
But we still need to cover what is probably the most important thing for you:
Namely how you protect yourself, prevent or get rid of ransomware.
For that there are several solutions you should use.
Let’s take a look:
Use a reliable backup
The best tip against ransomware is that you should have a reliable backup.
With a backup, you can restore all your data (that is, files and so on), even if they have been hit by ransomware. With a recent and good backup, you therefore don’t have to worry so much about losing your files in a ransomware attack – just be annoyed at the hassle an attack causes.
If you have few files, you can manually back up to an external hard drive or a USB stick.
The ultimate option, however, is to use an external provider, for several reasons:
- With a backup off-site, you make sure the backup is placed away from your computer. That way, ransomware can’t spread from your computer onto your backup (which is important to avoid)
- With a backup off-site, you can arrange for the backup to be taken automatically, so you always have a recent backup. After all, you don’t want your backup to have been taken too long ago, because then you would miss out on the files you have saved in the meantime
Backup with Onlime. Learn more about backup with Onlime and why you can use us
Antivirus and anti-malware: protection against ransomware
Besides backup, there are a number of tools you can have installed on your computer to prevent ransomware.
The best known is probably antivirus / anti-malware software, which often costs a monthly or annual fee. We have written about this before in our article about the ultimate security setup for your IT.
Anti-malware / antivirus are tools that don’t just help you avoid ransomware, but also other IT threats. The main point is that most modern IT threats are malware – and not viruses. That is why it makes the most sense to choose anti-malware software.
There is free anti-malware out there that will give you sufficient protection. Sometimes it will also be worthwhile paying for even better protection – depending on your needs.
Read more: Antivirus - learn more about it on our topic page.
Caution when you’re online
One of the most important tips for avoiding IT threats like ransomware is that you should move around online with caution.
That means you shouldn’t trust anyone whatsoever unless you are completely sure of the sender. This actually applies to all communication that isn’t face-to-face. That is:
- On social media (for example messages in Facebook’s Messenger, Snapchat, Instagram, dating apps and so on)
- On email (even if the email comes from an authority or a person you know – because the email can be forged)
- On SMS
With all these means of communication, IT criminals have the chance to exploit our busy everyday lives by imitating the messages we interact with on autopilot.
Fortunately, with caution and forethought you can avoid many of the fake messages. You just need to know what to look for.
Here are some classic traits of the fake messages from IT criminals:
- Spelling mistakes
- Bad grammar
- Excessive use of fear or time pressure
- Suspicious or awkward language
When you see the above traits, you should be careful with the message. It is probably a fake message.
If you spot a fake message, you can do the following:
- Avoid clicking on links or attachments in the message (since this is a common route of infection for ransomware and other malware)
- Contact the claimed sender to confirm whether the email is genuine or not
- Only enter your confidential information on secure websites (that is, websites that run over https rather than http). You should also never send money or confidential information on request in a message
With caution on the internet and in your communication, you will reduce your risk of being infected with ransomware.
Should you pay the ransom?
It is strongly advised against paying the ransom, unless it concerns critical data. If you pay, you are helping to give the IT criminals a reason to continue their crimes. On top of that, you don’t know whether you will even get your data back after paying, and you therefore risk wasting your money.
Conclusion
A piece of malicious software that encrypts the victim’s files and demands a ransom to unlock them again.
That is a short way of explaining today’s biggest IT threat. A threat that, over recent years, has plagued private individuals, companies and organizations by causing destruction worth billions of kroner.
Even one of Denmark’s largest companies has been hit – namely Maersk, which proves that everyone is in the danger zone.
There are, however, a number of ways you can prevent or cure an attack. We have gone into depth on the methods in this blog post, including:
- That you should have a reliable backup
- That you should consider antivirus / anti-malware software
- That you should move around online with caution
See also our 5 tips to protect yourself against IT criminals for a quick and concrete checklist.
We hope you have expanded your knowledge of ransomware. If you have questions about the threat, you are welcome to contact us.
Thanks for reading 🙂