Ransomware attacks have become quite popular in recent years. Breaches and hacks have led to employee training on cybersecurity as well as the development of sophisticated access management tools. As technology adapts to new threats, hackers are adapting their strategies. The FBI has identified a specific type of ransomware that is now categorized as extortion. So, let’s break down the difference between a traditional ransomware attack and a targeted extortion attempt.

Characteristics of a Ransomware attack
Organizations that have not experienced ransomware attacks still know about them. During an attack, an organization loses access to files and data. The organization must pay a ransom, usually in the form of bitcoin, to regain access. Ransomware victims are usually random targets. Ransomware “waits around the corner” for a failed security update in a company, or the use of an infected hosting client , or the existence of hardware with an easily exploited processor. Whatever the case, hackers exploit the flaw by creating a trap. If network is flawed, then the ransomware gains access. Ransom is usually a general percentage that varies little between victims, regardless of the value of the organization or the data.

Characteristics of an Extortion Attack
The main difference between ransomware and extortion attacks is the means by which the hacker identifies the victim. Victims are specifically targeted because of their high-value digital assets. An attack with this signature is considered extortion. Extortion attacks are on the rise and are set to occur with greater frequency than traditional, opportunistic ransomware attacks. In addition to targeting based on value rather than access, hackers are demanding higher ransoms.

Reduction and prevention
Mitigation efforts are more practical than preventative measures because preventative measures rely heavily on human perfection. A simple human error, such as clicking on a suspicious link or clicking on a malicious ad or unknowingly downloading an infected document, can lead to a ransomware attack on the system that can easily become a global hack.
Some useful mitigation strategies include backups, up-to-date system and security patches, and managed threat detection and response protocols.
Regardless of the attack, ransomware destroys a company's reputation and disrupts workflows. Recovering from an attack requires strong contingency plans.
