Ransomware
Ransomware is a type of malicious software (malware) that encrypts a victim’s files, making them inaccessible until a ransom is paid to the cybercriminals for the decryption key. These attacks often spread through phishing emails, malicious websites, or infected links, and can cause significant financial and operational disruption to individuals and organizations. In some cases, attackers may also threaten to leak or sell sensitive data if the ransom isn’t paid, a tactic known as double extortion.
How to protect against and recover from ransomware.
- Ahmed Khanji
- Updated: May 15, 2026
Every 11 seconds an organisation falls victim to a ransomware attack.*
Ransomware is a type of malicious software (malware). When it gets into your device, it makes your computer or its files unusable.
Cybercriminals use ransomware to deny you access to your files or devices. They then demand you pay them to get back your access.
The threat is on the rise in Australia
The world of cybersecurity is tight-lipped but it’s an open secret: For years, Australian organisations have been quietly paying millions in ransoms to hackers after having their data stolen or encrypted.
This money has funded criminal organisations, giving them the resources they need to plot bolder and more elaborate attacks, creating a vicious cycle.
Now experts say Australia, and the world at large, are facing a “tsunami of cyber crime”.
How this type of cyber threat is
affecting businesses in Australia
An Easy Target
In the July to December 2024 reporting period, the OAIC recorded 60 ransomware notifications, making ransomware responsible for 24 per cent of reported cyber incidents.
The average ransomware breach affected 26,878 individuals.
Ransomed for Millions
Recent global ransomware research shows how much pressure organisations face once attackers gain leverage.
The research found that 89% of organisations that experienced a ransomware attack paid a ransom to recover data or stop the attack.
It also found that 20% experienced more than 25 extortion attempts in 2024, showing how often ransomware now forms part of a broader pattern of repeat pressure and disruption.
What to look for
Ransomware can infect your devices in the same way as other malware or a virus. For example:
- Visiting unsafe or suspicious websites
- Opening emails or files from unknown sources
- Clicking on malicious links in email or on social media.
Common signs you may be a victim of ransomware include:
Pop-up messages requesting funds or payment to unlock files.
You cannot access your devices, or your login doesn’t work for unknown reasons.
Files request a password or a code to open or access them.
Files have moved or are not in their usual folders or locations.
Files have unusual file extensions, or their names or icons have changed to something strange.
Pop-up messages requesting funds or payment to unlock files.
Our advice and recommendations
Protective measures can prevent ransomware from occurring in the first place. Visit this page for a handy checklist of preventative steps you can take.
If you have been breached, we recommend you do not pay the ransom. There is no guarantee paying the ransom will fix your devices. It can also make you vulnerable to future attacks. Instead, restore your files from backup and seek advice.
For this reason, it is vital to back up your data and put effective cyber security practices in place.
Depending on the scale of the breach, it is also imperative that you immediately activate security controls and/or get in with a cybersecurity provider for advice and guidance.
How Gridware can help
We partner deeply with clients to understand their needs, working closely and iteratively to provide robust, best-in-class security solutions
Training & Awareness
Your users are the last line of defence. Inform them about the latest email threats, and ensure that they understand their fraudulent nature and know how to report them to your security departments. Gridware security awareness training and phishing simulation provides all necessary tools to train your users to recognise and report phishing emails, which will prevent email fraud and data loss.
Security Assessments
As a provider of CREST-approved vulnerability assessment, social engineering and red teaming services, Gridware’s ethical hacking team has extensive experience of assessing organisations’ technology, personnel and processes against the latest attack techniques and helping organisations to address them.
Protect your data
If ransomware does take control of your data, there’s no need to pay a ransom or go through a difficult and tedious recovery process — if you have a strong, modern, easy-to-use backup solution. We offer superior backup solutions — on-premises or in the cloud — that make it simple and fast to restore an up-to-date copy of any file, whether you’re restoring an entire server or specifically selecting files to restore.
Proactive Monitoring
Firewalls and antivirus software are not able to comprehensively defend against the latest types of memory-resident and polymorphic malware.
Our certified security professionals employ cutting-edge threat intelligence to hunt for malware and other cyber threats and help quickly shut them down.
Insights
Gridware is proud to be a thought-leader in cybersecurity, creating and leading conversations in this space. Check out a selection of our published work from our Sydney based Cyber Defence Centre (CDC), and learn how our cyber expertise has led to partnerships with leading Australian Universities.