Ransomware

Ransomware Part 1: The digital hostage business — what it is and how it became a £300 million problem

Ransomware is not just a technical problem. It is a professional criminal business — and understanding how it works is the first step to defending against it.

Robert Shone 4 min read
Ransomware Part 1: The digital hostage business — what it is and how it became a £300 million problem

Imagine arriving at work one morning to find that every computer in the building has the same message on its screen. Your files are locked. Your systems are frozen. The message says you have seventy-two hours to pay a sum of money — in cryptocurrency, to an anonymous account — or everything will be deleted. And then, sometimes, a second message: we also copied your files before encrypting them. Pay, or we publish them.

This is ransomware. And it is no longer a rare catastrophe. The UK suffered 76 confirmed ransomware incidents in 2025. Globally, 19,000 ransomware attacks target organisations every year. You have almost certainly seen the headlines from the most prominent of them — Marks & Spencer, NHS, Royal Mail — without necessarily knowing what actually happened and why.

This series tells the whole story. What ransomware is, why it keeps hitting hospitals and schools specifically, what the impossible decision about paying looks like from the inside, and what actually protects against it.


So what actually is ransomware?

Ransomware is malicious software — malware — that encrypts the files on a computer or network, making them completely inaccessible to their owners. Encryption, as we have covered on this site before, is the process of scrambling data so that only someone with the correct key can read it. Ransomware uses this process against you: it scrambles your own files with a key that only the attacker holds, then demands payment to hand it over.

The name is exactly what it sounds like: software that holds your data to ransom.

Getting ransomware onto a network is usually straightforward because the entry point is almost always a human decision, not a technical vulnerability. The most common routes are phishing — someone clicks a link or opens an attachment in a convincing email — and compromised credentials, where a username and password obtained from a previous breach are used to log in to a system directly. Once inside, the malware moves quietly through the network for days or weeks before activating, mapping what is there, finding the most valuable files, and positioning itself to cause maximum disruption in the moment it strikes.

Modern ransomware operations also commonly involve double extortion: before encrypting files, the attackers copy them. This gives them a second lever. If you restore from backups and refuse to pay for the decryption key, they threaten to publish your data publicly — client lists, employee records, sensitive documents, whatever they found.


The business model of digital extortion

It is worth being clear about something that gets lost in the technical detail: ransomware is a business. A very large, very profitable, very professionally run business.

The most sophisticated ransomware groups operate with the structures and processes of a mid-sized company. They have developers who write and maintain the malware. Affiliates who carry out attacks in exchange for a cut of the ransom. Negotiators who handle the payment process with victims. Customer service teams — genuinely — who answer victims' questions about how to pay in cryptocurrency. Public relations arms that manage their reputation on criminal forums. And legal teams in some cases, navigating the complexities of operating across international jurisdictions.

The groups behind the most significant UK attacks in 2024 and 2025 — Qilin, which hit Synnovis and NHS supply chains; Scattered Spider, which attacked M&S and Co-op; DragonForce, which has targeted UK retailers and logistics firms — are not lone hackers in hoodies. They are organised criminal enterprises with geographic footprints, revenue targets, and operational security practices.

This matters because it changes how we think about defence. You are not trying to stop one person. You are trying to be a less attractive and less easy target than the thousands of other organisations the same group is simultaneously assessing.


What actually happens during an attack

The seventy-two hour countdown in the ransom note is rarely the beginning of the story. By the time the message appears on screens, the attackers have typically been inside the network for weeks.

This period — called the dwell time — is when the real damage is done. Attackers move laterally through connected systems, escalating their privileges, mapping the network's most important assets, disabling or neutralising backup systems where they find them, and copying files they intend to use as leverage. The encryption, when it finally comes, is the public announcement of an attack that has already been largely successful.

For the organisations involved, the moment the ransom note appears is the moment controlled panic begins. IT systems freeze. Staff cannot access files. Communications fail — email is often on the same network. In hospitals, that means paper prescriptions, manual checks, and delayed procedures. In schools, it means teachers reverting to chalk and textbooks. In retailers, it means tills stop working and orders cannot be processed.

M&S's online shopping was down for more than six weeks following the Scattered Spider attack in April 2025. The estimated cost was £300 million. Co-op was hit by the same group days later. The attacks between them affected millions of UK customers and thousands of employees.


What does this mean for me?

Ransomware is not only a corporate problem. While the largest attacks target organisations, individual home computers can also be infected — typically through a malicious download or a compromised website. A family photo library, a home business, years of documents: all of these can be encrypted.

The entry point is almost always a human decision. A clicked link, an opened attachment, a reused password used on a company system. The technology is sophisticated. The door it comes through usually is not.

Backups are the most important defence for individuals. A backup that is current, tested, and stored somewhere separate from the main system — an external drive kept disconnected, or a cloud backup — means that even if your files are encrypted, you have not lost them.

Next Friday: we look at why hospitals and schools specifically are targeted so relentlessly, and what a ransomware attack looks like from inside an NHS trust.


🧠 The Human Factor

Technology involved Encryption malware, phishing delivery mechanisms, lateral movement tools, and increasingly sophisticated criminal infrastructure operating as organised business enterprises
Root cause Ransomware is a financial crime enabled by human decisions at entry — typically a clicked link, opened attachment, or reused credential — followed by weeks of undetected preparation
What was at risk Organisational files, operations, and sensitive data — with double extortion meaning that even restoring from backups does not guarantee the threat disappears
Prevention Phishing awareness; strong unique passwords and MFA on all accounts; current, tested, offline backups; prompt patching of known vulnerabilities

References and sources

  • NCSC: Ransomware guidance — ncsc.gov.uk
  • Synnovis/Qilin attack — NHS England, The Register, November 2025
  • M&S ransomware attack (Scattered Spider) — BBC, Sky News, April 2025
  • UK ransomware statistics 2025 — cybersecstats.com
  • Sophos: State of Ransomware 2025