This evergreen history article uses authoritative archives and official records. Exact dates are used when documented; gradual inventions and rollouts are described as periods rather than being assigned a misleading single birthday.
Quick facts
- The 1989 AIDS Trojan, also called the PC Cyborg Trojan, is widely cited as the first known ransomware attack.
- Early ransomware locked screens or encrypted files, but weak payment and distribution systems limited scale.
- Cryptocurrency and anonymous online services helped ransomware become a global criminal business in the 2010s.
- Ransomware-as-a-service divided work among developers, access brokers and affiliate attackers.
- Modern groups often steal data before encryption and threaten leaks, customers or recovery systems to increase pressure.
Origins and founding
In 1989, biologist Joseph Popp mailed thousands of floppy disks labeled as AIDS information to researchers and organizations. After repeated boots, the program hid file names and demanded payment sent to a postal box in Panama. The cryptography was flawed, but the incident established the basic ransomware idea: deny access to data and demand money for restoration.
Later malicious programs displayed lock screens or encrypted selected files. Payments through premium phone numbers, vouchers and early digital money were awkward, and many campaigns remained regional. The growth of online crime markets and strong public-key cryptography changed the economics.
The product takes shape
CryptoLocker in 2013 demonstrated a highly effective combination of email delivery, strong encryption, command-and-control infrastructure and Bitcoin payment. Law-enforcement action disrupted it, but many imitators followed. Cryptoworms such as WannaCry and NotPetya in 2017 spread rapidly across networks by exploiting unpatched systems.
Ransomware groups professionalized. Developers rented malware to affiliates in exchange for a share of payments. Initial-access brokers sold compromised credentials. Leak sites supported double extortion: attackers stole data and threatened publication even if a victim could restore encrypted files.
Technology and major features
A ransomware intrusion often begins with phishing, stolen remote-access credentials, an exposed VPN appliance or exploitation of a known vulnerability. Attackers escalate privileges, disable security tools, map the network and reach backups. Encryption is usually the final visible stage after days or weeks of preparation.
Modern operations may avoid encrypting every byte; they prioritize critical systems and use fast partial-encryption methods. Data exfiltration, denial-of-service attacks and direct contact with customers or regulators create additional leverage. Cryptocurrency helps move payments, although blockchain analysis also gives investigators evidence.
Growth and wider influence
Ransomware disrupted hospitals, schools, governments, factories and pipelines. The Colonial Pipeline incident in 2021 showed how an information-technology compromise could affect physical fuel distribution. Healthcare attacks delayed treatment, and municipal attacks interrupted public services.
The business model created a global response involving cybersecurity companies, insurance, law enforcement and sanctions. Governments discouraged ransom payment because it funds crime, but victims sometimes paid when operations or lives were at risk. Recovery costs often exceeded the ransom itself.
Challenges, criticism and responsibility
Paying does not guarantee decryption or deletion of stolen data. It may make a victim a future target and can violate sanctions. Poorly protected backups fail when attackers delete online copies or obtain backup credentials. Public attribution is difficult because groups rename themselves and reuse infrastructure.
Prevention requires more than antivirus. Organizations need phishing-resistant authentication, rapid patching, segmented networks, least privilege, endpoint detection, tested offline or immutable backups and rehearsed incident response. Staff should know how to report suspicious activity quickly.
Where it stands in 2026
By 2026, ransomware remained one of the most damaging forms of cybercrime. Groups increasingly targeted edge devices, cloud accounts, virtualization platforms and recovery infrastructure. Generative AI could improve phishing and reconnaissance, while defenders used automation for detection and containment.
The most effective strategy is resilience: assume an attacker may gain a foothold and limit how far it can spread. International cooperation, cryptocurrency tracing and disruption of hosting or affiliate networks can raise criminal costs, but no single takedown will eliminate the market.
Timeline
| Year | Location | Event | Why it mattered |
|---|---|---|---|
| 1989 | International research community | The AIDS Trojan is distributed by floppy disk | Creates the first widely recognized ransomware incident. |
| 2005–2012 | Eastern Europe and global internet | Screen-locking and file-encrypting malware grows | Builds a repeatable cyber-extortion model. |
| 2013 | Global | CryptoLocker combines strong encryption with Bitcoin | Demonstrates profitable large-scale ransomware. |
| 2017 | Global | WannaCry and NotPetya spread across networks | Shows ransomware-like malware can disrupt critical systems worldwide. |
| 2019–2026 | Global criminal ecosystem | Double extortion and ransomware-as-a-service dominate | Turns attacks into specialized organized businesses. |
Frequently asked questions
What was the first ransomware?
The 1989 AIDS Trojan, also known as the PC Cyborg Trojan, is widely regarded as the first known ransomware attack.
Should a victim pay a ransom?
Law-enforcement agencies generally discourage payment because it funds criminals and offers no guarantee. Organizations should involve legal counsel, incident responders, insurers and relevant authorities before any decision.
What is double extortion?
Attackers steal data and threaten to publish it in addition to encrypting systems.
What is the best defense against ransomware?
Layered controls are essential: strong authentication, patching, least privilege, segmentation, monitoring and tested offline or immutable backups.
Final perspective
Ransomware evolved from one crude floppy-disk scheme into a specialized global economy. The lesson is that recovery planning is a security control, not an administrative task. Organizations that know their assets, restrict privileges and test restoration are far harder to extort.