Shaun Stockman, Senior Director of Business Development, Americas at Ontrack. We work with insurers, DFIR teams, and IT departments after the ransom note has already appeared on the screen, so I've seen how these attacks unfold from the recovery side more times than I can count.
Ransomware doesn't start with encryption. That's the last step, and by the time you see it, the attacker has usually been inside your network for days or weeks already. I want to walk through what happens before that screen locks, because understanding the sequence changes how you respond to it, and it changes what your recovery options look like.
Every ransomware attack starts with initial access, and this part is rarely dramatic. I think people picture a genius hacker cracking a firewall in real time, but it's usually something much more boring: an unpatched VPN appliance, a remote desktop port left open to the internet, or an employee who reused a phished password.
Initial access brokers have made this even more routine. These are criminal groups whose entire business is breaking into networks and then selling that access to whoever runs the ransomware. So the person who gets in the door and the person who eventually demands payment are often two different criminal operations, working a few steps apart.
Once they're in, attackers don't touch anything valuable right away. They map the network, find domain controllers, identify backup systems, and figure out which servers hold the data that would hurt the most if it disappeared. This reconnaissance phase can take anywhere from a few hours to a few months depending on how the group operates and how quickly they're noticed.
Most of what happens in this phase would look completely normal to an untrained eye. The attacker is logging in with valid, stolen credentials. They're browsing shared drives the way any employee might. That's part of why detection is so hard. Nothing looks broken yet. The systems still work, the files still open, and there's no reason for anyone to suspect that someone else is already walking around inside the network deciding what to take first.
Here's where a single infected laptop turns into a company-wide crisis. Attackers use the access they've gained to move laterally, meaning they hop from one machine to another, escalating privileges as they go until they control domain admin credentials. From there, they can touch almost anything on the network.
This stage is also when attackers go after your backups specifically. I've seen cases where the malware targeted backup tapes and snapshots before it ever touched the primary data, because a company that can restore from backup has no reason to pay. Deleting or corrupting backups first is deliberate. That's a calculated move: taking away your options before they even make their demand.
If you want a sense of what this actually looks like from the inside once an organization realizes it's happening, our guide on dealing with a ransomware attack walks through what needs to happen in the first hours, from isolating devices to bringing in legal counsel.
This is the part that's changed the most in the last few years. Attackers now exfiltrate data before they encrypt anything. They quietly copy sensitive files out to their own servers, and only once that copy is complete do they trigger the encryption that locks you out.
This is called double extortion, and it's why the calculation around paying has gotten so much more complicated. Even if you have clean backups and don't need the decryption key at all, the attacker still has your data. They can threaten to publish or sell it, and in some cases report it to regulators. That threat doesn't go away just because you restored your systems. I'd say this is the single biggest shift in how these groups operate, and it's why “we have backups” isn't the full answer to a ransomware attack anymore.
We've written before about the decision organizations face here, and whether paying the ransom is worth it is rarely a simple yes or no. Some attackers don't provide a working decryption tool even after payment. Some variants, wipers in particular, aren't designed to give your data back at all.
Once the ransom note appears, most people assume the fight is over, you either pay or you don't, and either way the data is gone unless a decryption key shows up. That's not quite right. Encryption doesn't always destroy data as thoroughly as attackers want you to believe, and depending on how the malware behaves and what storage systems were involved, there can be paths back to the data that don't involve the attacker at all.
I've worked cases where corrupted backup tapes were still recoverable, and others where deleted volumes on NetApp storage could be walked back in time to unencrypted versions using the file system's own consistency points. No two cases look the same, which is part of why a rushed decision to pay or to wipe everything and start over can close off options you didn't know you had. We've documented a few of these recoveries if you want to see what that looks like in practice.
I get why the instinct is to wipe the affected drives and rebuild from scratch. It feels like the safe move. But that instinct can destroy the very evidence a recovery engineer or forensic investigator needs to work with. Before anything gets reimaged or reformatted, get a second opinion on what's recoverable. That might cost you a day or two, but wiping first costs you the option entirely.
If you're the one who gets the call when this happens, whether you're on an IT team, a DFIR bench, or the insurance side assessing a claim, the sequence above should shape your first moves. Isolate affected systems immediately, but don't wipe anything, and preserve the encrypted data and any ransom note exactly as found. Then get a specialist involved before making a final call on paying; that assessment can reveal recovery paths that change the whole decision.
How long are attackers inside a network before they deploy ransomware? It varies a lot, but dwell time of several days to a few weeks is common. Some groups move faster, especially when they're buying access from an initial access broker rather than doing their own reconnaissance.
Does paying the ransom guarantee I get my data back? No. Some victims never receive a working decryption key even after paying, and double extortion means your stolen data can still surface later regardless of payment.
Can data be recovered without paying the ransom? Often, yes. It depends on the ransomware variant and what storage systems were hit, plus whether backups were only partially destroyed. This is exactly the kind of thing a data recovery specialist should assess before any ransom decision gets made.
Why do attackers target backups first? Because a company with intact backups has no financial reason to pay. Destroying or encrypting backups early removes that option and increases the pressure to negotiate.
Ransomware groups keep refining their playbook, but the sequence itself hasn't changed. What has changed is how much leverage attackers build before you even know they're there, which is exactly why the first hour matters as much as it does.