Cybercrime

What is ransomware and how does it work?

Ransomware is a dangerous form of malware that locks or encrypts systems, steals data, and demands a ransom. In this article, we explain how ransomware works, what types exist, and why professional help is essential in the event of an attack.

If you are currently affected by a ransomware attack, we are available to assist you at any time by phone available. We take over the coordination of an incident response team and support you in all aspects of damage management.

Table of Contents:

  1. What is ransomware?
  2. How does a ransomware attack work?
  3. The different types of ransomware
  4. Common infection routes
  5. Legal consequences and liability risks
  6. Professional support in case of crisis
  7. Conclusion
Hacker attack, ransomware, help

Table of Contents

1. What is ransomware?

Ransomware is a special type of malware designed to encrypt systems or files. The goal is to extort a ransom from the affected individuals or companies. The attackers promise to return control of the data after the ransom is paid.

2. How does a ransomware attack work?

A ransomware attack usually takes place in several steps:

  1. InfectionThe ransomware is introduced via phishing emails, infected attachments, or compromised websites.
  2. ExecutionAfter activation, the ransomware encrypts files or blocks access to the system.
  3. BlackmailAn extortion letter (e.g. on the screen) demands the payment of a ransom in cryptocurrency.
  4. Ransom demandThe attackers promise to provide the decryption key after payment.

3. The different types of ransomware

1. Crypto-Ransomware Encrypts files so that they are no longer accessible. Examples: WannaCry, CryptoLocker.

Locker Ransomware Block access to the entire system without encrypting files.

3. Modern Extortion Methods

  • Double ExtortionData is not only encrypted, but also stolen. The perpetrators are threatening to publish sensitive information.
  • Triple ExtortionIn addition to encrypting and exfiltrating data, the attacker threatens to launch a denial-of-service (DDoS) attack, inform customers or business partners, or blackmail them as well with the stolen data.

The cybercriminals systematically and regularly exfiltrate the data before initiating the encryption. This data is frequently offered for sale on the dark web or published on „leak sites“ to increase the pressure on the victims.

4. Common transmission pathways

  • Phishing emailsDeceptive emails with malicious attachments or links.
  • Insecure RDP (Remote Desktop Protocol) accessOpen RDP ports are exploited by attackers.
  • Drive-by-DownloadsMalware is downloaded unnoticed when visiting infected websites.
  • External storage mediaInfected USB flash drives or hard drives spread ransomware.

5. Legal Consequences and Liability Risks

A hacker attack can have far-reaching legal consequences:

Liability risks for managing directors:

  • Personal liability for breach of organizational duties
  • Potential claims for damages due to inadequate IT security measures
  • Liability for breach of reporting obligations

Claims for damages from third parties:

  • Customers can claim compensation for material or non-material damage caused by leaked data
  • Business partners can assert contractual penalties or claims for damages
  • Insurance recourse claims for breach of duty

Regulatory consequences:

  • GDPR fines for violation of reporting obligations
  • Sector-specific sanctions (e.g., in the financial or health sector, or critical infrastructure)
  • Regulatory requirements

6. Professional support in times of crisis

In ransomware attacks, prompt and professional action is crucial. ATB.LAW specializes in the legal management of cybersecurity incidents and works with leading IT security companies and IT forensic experts specializing in hacker attacks. These partners ensure:

  • 24/7 on-call service for emergencies
  • Immediate intervention for damage control
  • Highly specialized forensic investigations
  • Professional crisis management

The interdisciplinary team offers:

Legal support by ATB.LAW:

  • Immediate initial legal assessment and continuous support
  • Coordination with authorities and insurance companies
  • Accompanying crisis communication
  • Conducting ransom negotiations with attackers on the dark web
  • Defense against unjustified claims
  • Support for GDPR-compliant processing

Technical expertise through specialized IT security partners:

  • Immediate Incident Response
  • Containment of the attack
  • Forensic evidence collection
  • System Restore
  • Vulnerability analysis

The close integration of legal and technical expertise, combined with the team's permanent availability, ensures that no valuable time is lost in an emergency and that all necessary measures are coordinated and carried out in a legally secure manner.

7. Conclusion

Ransomware is a serious threat to businesses. Knowing how it works and spreads helps minimize risks. In an emergency, professional help is crucial to limit damage and ensure recovery. In addition to restoring system functionality, legal protection is a priority to minimize personal liability risks and meet regulatory requirements. Professional guidance helps navigate the complex technical and legal challenges of a cyberattack.

For further information and individual consultation, please feel free to contact us Roman Taudes (taudes@atb.law) and his team are available at any time.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes