Skip to content
Mindcraft Impuls

Ransomware:
Why the ransom note is only the final step

Approx. 7 minutes read

Experience this topic as an interactive Cyber Snack:
just click and learn it all in 5 minutes.

Cyber Snack: start ransomware interactively

You sit down at your computer in the morning. The screen says: 'Your files have been encrypted.' Next to it, a countdown is running. A lot is decided in this moment, and the first reflex is often the wrong one. Yet the ransom screen is not the beginning of the attack. It is its last, visible step.

Ransomware has long been more than malware that encrypts files. Modern attacks unfold in phases, they steal data before they lock anything, and they put companies, hospitals, and private individuals under pressure on several levels at once. People who understand how this works react more calmly in an emergency, and more correctly.

The September Cyber Snack makes exactly that tangible: with a real case from Germany, a look behind the scenes of an attack, and clear rules for the first few minutes.

The first minutes: isolate and report

Anyone who sees a ransom screen usually has two impulses: get rid of the problem quickly, or find out how bad it is. Both lead in the wrong direction. Paying quickly guarantees neither that the data will come back nor that stolen copies will be deleted. And rebooting the computer several times or checking whether files still open wastes time, can destroy traces, and may even help the attackers.

The right reaction is unspectacular: disconnect the device from the network, stop clicking, stop experimenting, and inform IT or the security team immediately, ideally by phone. This is exactly the order recommended by authorities such as the US Cybersecurity and Infrastructure Security Agency (CISA): isolate affected systems immediately and report incidents through a channel the attackers cannot read.

First aid for a ransom screen

Disconnect the device from the network: unplug the LAN cable, switch off Wi-Fi. Do not reboot the computer repeatedly and do not test files. Inform IT or the security team immediately, ideally by phone. Do not pay, do not negotiate with the criminals, no rescue attempts of your own.

The Unimed case: an attack via the billing service provider

Illustration of a data chain from patient to hospital to billing service provider, with an attacker arrow aimed at the provider
The attack did not target the hospital, but the service provider in the middle of the data chain.

A case from Germany shows how important a fast reaction is. In mid-April 2026, attackers targeted Unimed, a billing service provider based in Saarland which, by its own account, handles billing for private and self-paying patients for around 95 percent of German university hospitals. So the attackers did not go after a hospital, but after the service provider where the data of many hospitals comes together.

University hospitals in several German states were affected, including Freiburg, Heidelberg, Tübingen, Ulm, Cologne, Düsseldorf, Mainz, and Homburg. In total, well over 100,000 patients were involved, around 54,000 of them at Freiburg University Hospital alone. Most of the data consisted of basic details such as name, address, and date of birth. In a smaller share of cases, however (around 900 in Freiburg and more than 800 in Cologne), the stolen documents also contained information on diagnoses and treatments.

According to Unimed, the attackers' actual goal was to encrypt the systems completely and then demand a ransom. That failed: the attack was detected and repelled, and billing was running again shortly afterwards. The worst damage was prevented. But the problem was not solved, because the attackers had already copied data from a limited area beforehand. And no backup in the world can bring that back.

What a medical record is worth to criminals

For the hospitals, the data leak became a trust problem; for the patients, a real risk. Health data is among the most valuable information traded on the dark web. A widely cited overview by the credit agency Experian puts the price of a complete medical record at up to around USD 1,000, while login credentials for subscription services often sell for one to ten dollars.

The reason is simple: a credit card can be blocked with a click, a password can be changed. A diagnosis, however, cannot be reset. Anyone who knows that a person has a particular condition can exploit that knowledge for years.

A password can be changed, a credit card can be blocked. A diagnosis stays forever.

One record, several buyers

That is why the same record can be exploited several times: for identity theft, for insurance fraud, and for targeted extortion using real diagnoses. A message that names an actual condition or treatment feels far more threatening and credible than any generic phishing email.

Anyone who receives such an extortion email should never give in to the demands and should not reply either. Every response only confirms to the criminals that the contact details are real and that the pressure is working. Better: keep the message, do not delete it, and report it to the police.

How modern ransomware unfolds

Illustration of a phase bar with six segments, of which only the last one is highlighted
Five of the six phases of a ransomware attack remain invisible to those affected.

Ransomware almost never starts with the ransom screen. It starts with access to the system. The most common doors are a phishing email with an attachment or link, stolen or weak passwords, and unpatched vulnerabilities or exposed remote access. Increasingly sophisticated forms of social engineering add to this, such as fake support calls or manipulated invitations to online meetings.

Our insights on web meetings and AI agents show what such entry points look like in everyday work. And our insight Passwords are never 100% secure explains why a single password is never enough.

Once inside, the attacker looks around the network, searches for admin accounts and backups, and copies data to their own systems. Encryption only comes at the very end. The ransom note is therefore the very last, visible step of a chain that has often been running for days or weeks. Many variants deliberately search for reachable backups in order to delete or encrypt them as well.

That is exactly why reporting immediately is so crucial. Every anomaly reported early (a strange login, a suspicious email, a computer behaving oddly) can stop the attack before everything has been copied and encrypted.

Double and triple extortion

Because the data is stolen before encryption, criminals have two levers. Level one: 'Pay, or your systems stay locked.' Level two: 'Pay, or we publish your data.' This double extortion is standard today. The German Federal Office for Information Security (BSI) also observes that attackers increasingly threaten to publish stolen data as an additional lever.

If the criminals also contact customers, business partners, or patients directly, a third level of pressure emerges. The extortion then no longer hits only the organization, but also the people whose data was stolen. In this case, backups only help with recovery. They do not protect against publication.

The three levels of pressure

Level 1: the systems stay locked. Level 2: the stolen data is published. Level 3: customers, partners, or patients are extorted directly. Backups only help against level 1. Against levels 2 and 3, what helps most is stopping an attack before data leaves the network.

Why paying is not a good solution

Illustration of a cycle of ransom payments, more resources for criminals, and further attacks
Every payment finances the next wave of attacks.

That leaves the most delicate question: why not simply pay? First, because a ransom guarantees nothing, neither working decryption nor the deletion of stolen copies. Second, because every payment finances the criminals' business model. The more successful they are, the more resources they have for the next attacks. The BSI therefore advises against engaging in ransom payments as a matter of principle, and the FBI explicitly does not support paying either.

Nevertheless: we do not blame victims, even if they pay. Anyone under attack is under enormous pressure. That is exactly why nobody decides alone in such situations. In companies, IT, security, data protection, legal, and the police come together, in Germany for example via the central cybercrime contact points of the state police. And in private life: do not pay, call the police immediately.

Three myths, fact-checked

Myth: If you pay, you can be sure the stolen data will be deleted. False. There is no guarantee at all, neither of clean decryption nor that copies are really destroyed.

Truth: Even if backups exist, a data leak can still be critical. Correct. Backups protect against data loss, but not against publication. The Unimed case shows exactly that.

Myth: Ransomware only affects large corporations. False. Hospitals, municipalities, service providers, mid-sized companies, and private individuals are affected too.

Three protective measures that really help

1. Install updates

Take software updates seriously, on your computer, your smartphone, and your router. Many attacks exploit known vulnerabilities for which a patch has long been available.

2. Use 2FA or passkeys

Protect important accounts with two-factor authentication or, even better, with passkeys. Then a stolen password alone is no longer enough for an attack.

3. Keep backups separate from the computer

Create regular backups on an external drive and disconnect it from the device afterwards. Only a backup the malware cannot reach helps in an emergency.

Our insight on passkeys explains how they work and why they leave phishing with nothing to steal.

What awareness teams should take from this

For CISOs and awareness managers, the Unimed case shows two things. First: the attack surface does not end at your own firewall. Service providers where the data of many organizations comes together are particularly attractive targets. Second: the decisive phase of a ransomware attack is invisible to employees. Only small anomalies become visible, and they are only reported if people recognize them and are not afraid to admit mistakes.

Effective awareness therefore does not start with the ransom screen, but with the doors in front of it: phishing, passwords, updates, and a reporting culture in which an early warning is praised rather than punished. Equally important is a practiced first-aid routine: everyone should know how to disconnect a device from the network and whom to call in an emergency, including at night and on weekends.

Conclusion

Ransomware is systematic extortion: encryption and publication of data are deliberately used as leverage. It affects companies, hospitals, and public authorities, but also every single individual.

That is why three maxims apply: don't click in panic, don't negotiate on your own, report immediately. Nobody becomes invulnerable that way, but everyone becomes much better prepared.

Sources

heise online, May 2026: "Patient data affected: Cyberattack on billing service provider for clinics"; Deutsches Ärzteblatt, May 22, 2026: "Weitere Unikliniken melden Tausende bei Dienstleister gestohlene Patientendaten"; Stuttgarter Zeitung and apotheke adhoc, May 22, 2026.

Experian, December 6, 2017: "Here's How Much Your Personal Information Is Selling for on the Dark Web".

BSI: "Ransomware-Angriffe" (situation report and recommendations); CISA et al.: "#StopRansomware Guide"; FBI: "Ransomware" (guidance for victims).

Topic cluster