Ransomware has become a serious cybersecurity problem for businesses of every size. It is a type of malware that can lock users out of systems or encrypt files, leaving data unreadable. Criminals then demand a ransom in exchange for restoring access — though payment does not guarantee recovery.
The threat goes back decades. In 1989, Joseph Popp distributed roughly 20,000 floppy disks labeled “AIDS Information.” The disks carried what became known as the AIDS Trojan, an early documented form of ransomware.
After repeated computer startups, the malware hid or encrypted access to files and demanded payment to PC Cyborg Corp. in Panama.
Today, ransomware is far more sophisticated. Payment demands often involve cryptocurrency, and the attack may begin with something as ordinary as an email. My colleague Zach Rowell and I gave a cybersecurity presentation this Summer, and one slide focused on a simple scenario: What if someone sends an HR department a Dropbox link titled “Resumes”? You do not know the sender, but your company has several jobs posted. Do you open it? No.
Security tools may not immediately flag a seemingly clean Excel file or other attachment. But malicious content can be layered or embedded in ways designed to evade defenses. Robust security tools can stop many attacks before execution, but that depends on how well an organization’s security posture is configured.

Federal cybersecurity guidance likewise identifies phishing, compromised credentials, and malicious attachments as common initial access vectors and recommends user training, filtering, and phishing-resistant multifactor authentication.
What happens if you are infected?
Some companies hire incident-response firms or ransomware negotiators to help recover data and deal with attackers. A strong, redundant backup strategy can reduce the need to negotiate in the first place.
But what happens when the person hired to help is secretly working with the hackers?
Florida saw exactly that this year. The U.S. Department of Justice says Angelo Martino, a former ransomware negotiator from Land O’Lakes, abused his position at a cyber incident-response company in 2023. While advising ransomware victims, he provided BlackCat/ALPHV attackers with confidential information about clients’ negotiating positions and strategies, helping the criminals maximize ransom demands.

He also conspired with other cybersecurity professionals to deploy ransomware against additional U.S. victims.
According to federal prosecutors, Martino and his co-conspirators successfully extorted one victim for about $1.2 million in Bitcoin and divided their share of the ransom. Law enforcement seized $10 million in assets from Martino, and he was sentenced in July to 70 months in federal prison.
The case was part of Operation Riptide, an FBI campaign targeting cybercriminals, their infrastructure and their financial networks. The FBI says the coordinated effort produced more than 200 arrests, six technical infrastructure takedowns and the seizure of 170 domains and servers.
In a separate Riptide action, the FBI supported an international takedown of First VPN Service, infrastructure allegedly used by ransomware groups and other cybercriminals.
The FBI’s work deserves credit, but businesses and individuals still have to keep their guard up. Emails, texts and calls should be scrutinized before you act. Hackers have turned everyday communication tools into delivery systems for fraud and malware, so unexpected messages deserve verification.
Seen a fake e-vite lately? Invited to a party you know nothing about? Do not click. Receive an email supposedly from Microsoft asking you to verify your password? Do not click the link. A bank email asks you to confirm a routing number? Verify it independently. Someone claiming to be the IRS or a Sheriff’s Office demands immediate payment? Stop and confirm the request through an official channel. A Facebook message asks for gift cards? A text says your Netflix payment is late? Treat unexpected demands for money or credentials as suspicious.
The basics matter.
Use strong, unique passwords. Enable multifactor authentication. Keep systems patched. Maintain offline or otherwise protected backups and test them. Invest in appropriate threat-protection tools for your organization. CISA’s #StopRansomware Guide provides practical prevention and response guidance, including recommendations for phishing awareness, multifactor authentication and offline, encrypted backups.
Hackers are relying on you to make a bad decision — to trust something that is not true. AI is making fraudulent messages, images and voices more convincing. Check the actual sender address, independently confirm financial requests before proceeding, and never give anyone your password.
There is no silver bullet. But better technology, better habits and better cooperation can lower the risk of a cyber incident.
And when criminals do get through, aggressive law enforcement makes the cyber battlefield a little less comfortable for the people trying to exploit it.
