Ransomware: What Really Happens When Hackers Lock Your Files
The locked-screen moment is the loud part. Understanding what happens before it is where defenders find their advantage.
4 min readIntermediate Aug 24, 2026
Explain Like I'm Not a Hacker
Ransomware is like a burglar who quietly copies your keys, checks every room over several visits, and only locks the doors and leaves a note on the way out for good.
The 30-second explanation
Attackers get in quietly, often through a stolen password or a malicious attachment, and take their time looking around instead of striking right away. They map out which servers matter, where the backups live, and what data would hurt most to lose or have published. Only once that groundwork is done do they lock everything at once and leave a ransom note. The loud, visible part โ a screen full of demands โ is the end of the story, not the beginning.
How it works
- 1
1. Get in
Phishing that harvests a password, an internet-exposed remote-access service like RDP or VPN, or a purchased stolen login gets the attacker a foothold.
- 2
2. Look around
Using legitimate admin and remote-management tools rather than custom malware, the attacker maps file shares, domain controllers, and where backups are stored.
- 3
3. Take data
Sensitive files are compressed and uploaded to an attacker-controlled cloud storage or file-transfer service before anything is locked.
- 4
4. Lock files
Ransomware is pushed out to as many endpoints and servers as possible in a short window, deleting backup snapshots first, then a ransom note is dropped on every affected machine.
When people picture ransomware, they picture a screen suddenly announcing that every file is locked. That moment is real, but it's almost always the last chapter of a story that started days or weeks earlier. First the attacker gets a foothold, often through a stolen password used on a remote-access service, or a malicious attachment that runs a script on one machine. Then they move carefully instead of loudly, escalating from a normal user account to an administrator one, using built-in tools like remote-management software or scheduled tasks that don't look out of place in a log. Along the way they map out where the file servers, databases and backup systems live. Often they copy sensitive data out to an external server before touching anything else, so they still have leverage later even if the victim recovers everything from backup. Only after all of that does the encryption go out, usually pushed to as many machines as possible within a short window, followed by a ransom note pointing to a payment portal and a countdown.
Real-world example
A staff member's password is stolen through a fake sign-in page delivered by email. Over the next several days, someone signs in remotely with that password outside normal working hours, browses file shares they've never touched before, and quietly tests access to the backup server. None of it trips an obvious alarm, because every action uses a valid login and ordinary tools. Then, on a weekend evening, machines across the organisation start showing a ransom note within minutes of each other โ the visible end of access the attacker had actually held for days. Not every operation plays out as one dramatic weekend, though. Some groups deliberately encrypt a handful of lower-priority systems first and use the disruption as pressure to speed up negotiation before they touch anything critical.
How to spot it
Unfamiliar admin tool activity
Remote-management or scripting tools running on machines that don't normally use them, or at unusual hours.
Large, unexplained outbound transfers
A sudden burst of data leaving to an unfamiliar cloud storage domain or IP address, especially compressed into archive files first.
Security tools going quiet
Backup jobs failing silently, or endpoint protection and logging agents being disabled or uninstalled without a documented change.
Mass file changes in a short window
A large number of files being renamed with a new extension or modified within minutes across multiple machines at once.
What to do
- 1Isolate affected machines from the network the moment something looks wrong โ pull the network cable or disable Wi-Fi rather than shutting the machine down, which can destroy evidence in memory.
- 2Preserve logs and disk images before restoring from backup, and involve incident response so the entry point is found and closed, not just the symptom fixed.
- 3Keep backups offline or immutable, so a compromised administrator account cannot reach or delete them.
Stay curious. Stay safer.
This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.
Keep reading
- AI + SOC Workflows
AI in Incident Response: How I Use It During Real Investigations
2 min read - SOC & Blue Team
SIEM: The Security Camera System for Your Entire Network
4 min read - Credential Attacks
Credential Theft: How One Stolen Password Opens Every Door
4 min read - Security Basics
MFA: The Second Lock That Hackers Can Still Pick
4 min read