---
title: Could your Organization be the next Ransomware victim?
description: Ransomware is a type of malware that restricts access to the infected computer system, and demands that the user pay a ransom to the malware operators to remove the restriction. Some forms of ransomware systematically encrypt files on the system's hard drive, then spread to any shared network drives and other computers, and make it difficult or impossible to decrypt without paying the ransom for the encryption key.  Other forms of Ransomware may simply lock the system and display messages intended to coax the user into paying to acquire the key. Ransomware typically propagates as a trojan, whose payload is disguised as a seemingly legitimate file.
image: https://info.blueorangecompliance.com/hubfs/Chained_hands1.jpg
---

[![](https://info.blueorangecompliance.com/hs-fs/hubfs/BOC_Logo_RGB_2C_BlueOrange%20-%20resize%20for%20screen%20branding%20zoho.jpg?width=308&height=97&name=BOC_Logo_RGB_2C_BlueOrange%20-%20resize%20for%20screen%20branding%20zoho.jpg)](https://info.blueorangecompliance.com/)

- [Contact Us](https://www.blueorangecompliance.com/contact-us/)

# Could your Organization be the next Ransomware victim?

Posted by [John Dimaggio](https://info.blueorangecompliance.com/blog/author/john-dimaggio) on Mar 8, 2016 3:20:11 PM

 In [Ransomware](https://info.blueorangecompliance.com/blog/topic/ransomware)

Ransomware is a type of malware<https://en.wikipedia.org/wiki/Malware> that restricts access to the infected computer system, and demands that the user pay a ransom<https://en.wikipedia.org/wiki/Ransom> to the malware operators to remove the restriction. Some forms of ransomware systematically encrypt<https://en.wikipedia.org/wiki/Encryption> files on the system's hard drive, then spread to any shared network drives and other computers, and make it difficult or impossible to decrypt without paying the ransom for the encryptionkey. Other forms of Ransomware may simply lock the system anddisplay messages<https://en.wikipedia.org/wiki/Scareware> intended to coax the user into paying to acquire the key. Ransomware typically propagates as a trojan<https://en.wikipedia.org/wiki/Trojan_horse_(computing)>, whose payload is disguised as a seemingly legitimate file.

CryptoLocker is ransomware trojan<https://en.wikipedia.org/wiki/Trojan_horse_(computing)> which targets computers running Microsoft Windows. CryptoLocker propagates via infected email attachments, and via an existing botnet. When activated, the malware encrypts<https://en.wikipedia.org/wiki/Encryption> certain types of files stored on local and mounted network drives using RSA public-key cryptography, with the private key stored only on the malware's control servers. The malware then displays a message which offers to decrypt the data if a payment (through eitherbitcoin or a pre-paid cash voucher) is made by a stated deadline, and threatens to delete the private key if the deadline passes.

 **How does it get in?**

Typically, the virus propagates as a trojan, entering a system through, for example, a downloaded file or a vulnerability in a network service. Recently, there also have been entry points through infected Advertisements on legitimate websites, who outsource their advertising content. The program then runs a payload, which typically takes the form of a scareware<https://en.wikipedia.org/wiki/Scareware> program. Payloads may display a fake warning purportedly by an entity such as alaw enforcement agency, falsely claiming that the system has been used for illegal activities, contains content such as pornography<https://en.wikipedia.org/wiki/Pornography> and "pirated" media, or runs a non-genuine<https://en.wikipedia.org/wiki/Windows_Genuine_Advantage> version of Microsoft Windows. The malware may also encrypt attached storage devices such as USB drives or external hard disks

**Prevention, Protection, and Best Practices**

Install Malware detection software, and ensure Antivirus software is in place and that both are kept up-to-date. Using software or other security policies to block known payloads from launching will help to prevent infection, but will not protect against all attacks.

Use credentials with the least amount of necessary access to systems to help prevent the spread of the virus by reducing the number of network touchpoints (ie, file shares, printers, servers, etc.). It is always a best practice for users to use non-administrative credentials, and only elevate credentials when necessary for installation, maintenance, etc.

Keep data backups stored in locations inaccessible to the infected computer. This will allow data to be restored to its state at backup time.

Finally, don’t underestimate the complexity of IT security. Security vulnerabilities may be present in operating systems, applications, configurations or risky end-user practices. Hire a compliance partner to perform penetration testing and vulnerability scanning as part of a comprehensive security regimen. A compliance partner can quickly execute the necessary tests to determine the likelihood of real-world threats against an organization’s IT assets and physical security.

 *BlueOrange Compliance has been providing privacy and security assessments, remediation and guidance since the inception of HITECH, and has over 50 years of experience in technology security, compliance and healthcare. Our national client base consists of hospitals, physician provider practices, Nursing Facilities, LTC Pharmacies, LPCs, CCRCs, homecare, hospice and business associates. If you want to learn how BlueOrange Compliance can help you turn HIPAA complexity into HIPAA compliance, visit us at [blueorangecompliance.com](http://www.blueorangecompliance.com).*

 

[<< Previous Post](https://info.blueorangecompliance.com/blog/dont-forget-about-hipaa-privacy)

[Next Post >>](https://info.blueorangecompliance.com/blog/is-your-organization-ready-for-the-2016-ocr-random-hipaa-audits)

### Recent Posts

### Topic Cloud

- [Cyber Security (10)](https://info.blueorangecompliance.com/blog/topic/cyber-security)
- [OCR Random Audits (8)](https://info.blueorangecompliance.com/blog/topic/ocr-random-audits)
- [HIPAA Security (3)](https://info.blueorangecompliance.com/blog/topic/hipaa-security)
- [Common Scams (1)](https://info.blueorangecompliance.com/blog/topic/common-scams)
- [HIPAA Privacy Compliance (1)](https://info.blueorangecompliance.com/blog/topic/hipaa-privacy-compliance)
- [Meaningful Use (1)](https://info.blueorangecompliance.com/blog/topic/meaningful-use)
- [Password Strategies (1)](https://info.blueorangecompliance.com/blog/topic/password-strategies)
- [Penetration Testing (1)](https://info.blueorangecompliance.com/blog/topic/penetration-testing)
- [Phishing (1)](https://info.blueorangecompliance.com/blog/topic/phishing)
- [Ransomware (1)](https://info.blueorangecompliance.com/blog/topic/ransomware)
- [Security Awareness Training (1)](https://info.blueorangecompliance.com/blog/topic/security-awareness-training)

### Popular Posts

### CTA Area

© 2026 BlueOrange Compliance