Ransomware is a worst-case cyber scenario for organisations.
With multiple prominent attacks on UK businesses in the last year, it’s top of mind for CISOs, who want to understand what steps they can take to improve their defences against the threat.
However, before ransomware can wreak havoc on an organisation, it needs to be deployed. So, how exactly do attackers get ransomware onto systems?
Below is a list of the top methods threat actors adopt to infect organisations with ransomware, which will help business leaders prioritise their defences against the threat.
Unaddressed Data Breaches
Data breaches are difficult to deal with, and many organisations fail to address them properly. In some cases, the data breached can contain credentials or sensitive information that is sold or made public and available to leverage.
Yet, data breaches often go unaddressed by organisations, sometimes for months at a time, giving threat actors time to search and test credentials, which they can leverage to gain access to systems and carry out ransomware attacks.
Insiders
As ransomware payments continue to decline, threat actors are more frequently turning to insiders as an effective means of infiltrating systems.
This occurs when a threat actor contacts employees within an organisation and offers to pay them for their access. This often provides access to systems where the activity is not initially identified as malicious by security teams because the threat actor can use credentials in a way that is consistent with how the true owner uses them. It also provides threat actors with an opportunity to gain a strong foothold on an organisation and enumerate assets before they conduct a larger scale ransomware compromise.
Supply Chain Attacks
Supply chain attacks have become a major concern for organisations as their digital ecosystems grow. In these attacks, threat actors compromise a vulnerability within a supplier, and then pivot further down their supply chain to infect other organisations.
Key examples are Cl0p’s recent exploitation of a Zero Day vulnerability in Oracle’s E-Business Suite, which enabled the threat actor to compromise other organisations that rely on the infrastructure. These attacks are widespread and they can often impact hundreds of organisations via a single flaw.
Vulnerabilities in technology platforms
Exploiting Zero Days or unpatched vulnerabilities in technology platforms is another key way attackers get ransomware onto systems. In these attacks, criminals exploit a vulnerability and use it to gain access to key systems and then use evasive techniques to try and remain undetected by security teams. Once that access is achieved, they drop ransomware before causing havoc for the victim.
Malvertising
With malvertising, attackers can serve malware to users, disguised as adverts on legitimate websites. Using this method, malware is delivered through ads placed on websites as large as YouTube, and its form can be diverse, ranging from adware to infostealers and then becomes another form of data breach.
Phishing
While the basic Nigerian Prince style phishing campaigns are no longer viable, threat actors still commonly rely on phishing to execute ransomware attacks. These attacks can range from socially engineering employees at target organisations, to sending out emails en masse to internet users, which are designed to look like correspondence from genuine organisations.
The trick is to encourage recipients to give away sensitive information, such as login credentials, or to click on links, which enable attackers to drop ransomware. Even if the user doesn’t enter sensitive information, simply clicking on a link is enough for a threat actor to become aware the user may be more likely to engage in more sophisticated attacks
Vishing
Voice Phishing, or Vishing, involves criminals phoning up victims and attempting to steal credentials over the phone. This is often achieved by impersonating employees or IT help desks and requesting password resets. Vishing saw a new prominence last year, and when combined with social engineering means data is often transmitted with little validation. Once more, organisations often fall short of providing employees with techniques to spot when this may be occurring.
AI and Deepfakes
Social engineering can also be performed using generative AI tools today. The past few years have seen a boom in low-cost and easily accessible text, image, and video-generation tools which can be used to make convincing fake content or clones of individuals. Criminals can use AI and deepfakes to trick people into handing over sensitive information or clicking on links, enabling threat actors to then drop ransomware.
Edge Devices
Network-edge devices are easy to forget about: these are quiet entry points into systems like firewalls and VPNs which are often not subject to EDR tools, are often skipped for security monitoring due the volume of logs they can create and remain unobserved. Even simple misconfigurations, like leaving old VPNs switched on, can allow attackers to gain a foothold to deploy ransomware.
Recommended reading
- Data Theft Surges to 96% of Ransomware Attacks
- Comment | The History of Ransomware
- Ransomware “Supergroups” Emerge After Record‑Breaking Year of Attacks
Ultimately, the ways attackers can breach systems and deploy ransomware are numerous. And unfortunately, just like there is no one-size-fits-all for attack execution, there is no one-size-fits-all for attack solution.
However, there are good practices organisations should follow.
These include keeping all systems up to date and patched; adopting Zero Trust principles, working with SOCs that can actively monitor systems; and practising good security hygiene, while enforcing basic technical controls across organisations, like MFA. These need to be paired with risk management profiling, approaching the potential avenues for attacks in order to proactively improve defences.
Security is about vigilance and defense in depth.





