Lifecycle of a Ransomware Attack – Learnings from NetDiligence Cyber Risk Summit

by Michael Bruemmer 5 min read July 28, 2021

Ransomware needs to be on your radar. Here’s why.

Ransomware review

Ransomware is a cyberattack where cybercriminals take over an organization’s computer network with malware. Once they assume control, the criminals demand a ransom to restore the victim’s encrypted data access. With an estimated generation of $412 million in 2020 alone1, the frequency of these attacks is growing.

At Experian, we handle many data breach cases and know that7 of 10 breaches involve ransomware. This summer, NetDiligence dedicated a panel at its Cyber Risk Summit on the Lifecycle of a Ransomware Event and invited us to talk about our solutions to help business leaders prepare to minimize interruptions spurred by ransomware.

The lifecycle of a ransomware attack includes five stages:

Ransomware Attack

1. Attack

Bad actors attack to discover assets, take data, extort it for direct payment, or profit from reselling data on the dark web. They can also launch a‘double-take’ attack: first collecting ransom to access data and demanding secondary payment to keep it off the dark web. Hackers prey on company networks, searching for vulnerabilities and accessing encrypted files through phishing or planting malicious links to infect the network with malware. More than double the global rate of 14%2, U.S ransomware attacks have become more aggressive, accounting for 30% of all cyberattacks in 20202. At Experian, we’ve seen an even higher occurrence, with 59% of the events serviced 2021 to date involving ransomware.

2. Discovery

Once attackers infiltrate a system, they demand a ransom for the decryption key to unlock the encrypted files. Companies usually discover the attack through a ransom note emailed to an executive, a file left on a server, or even a flashing warning on all connected computers. If they leave a message including their contact information, ransom sum, payment delivery time, and consequences for unmet conditions, such as tipping off the media, releasing stolen data, or selling it on the dark web.

Next, companies will contact their cyber insurance carrier to log stolen information, get systems back online, navigate legal issues, and facilitate hacker negotiations. Since only about one-third of companies have cyber insurance, most will rush to hire cybersecurity counsel post-attack3, amounting to more stress and delays since it can take months for large companies or those without backups to determine the extent of the damage.

At Experian, almost allevents involving ransomware take about 20% more time to begin breach notification. Whether there is an incident plan in place or not, companies experience immense panic.

3. Negotiation

Typically, a company will hire a professional, either directly or through their cyber insurance, to negotiate with hackers. While hackers expect price haggling, the ransom price could still be hefty. According to the cybersecurity firm, Coveware, the average ransom was $154,000 in Q4 2020, down from $230,000 the year before4. But hackers can drive up the price. Prime example: JBS, the world’s largest meat processor, paid an $11 million ransom in June 2021 to prevent customer data from being compromised.

In a perfect world, the ransomware negotiation process goes this way:

  • Establish communication with the attackers
  • Obtain proof of decryption
  • Obtain data exfiltration proof
  • Negotiate a (huge) discount
  • Celebrate

Unfortunately, negotiations can be tricky, and the process rarely goes this way. Sometimes attackers go “dark” or request additional payments. Additionally, decryption tools may have bugs that skip mapped network drives or skip folders with long paths and unusual characters.

An investigation is key to determine how hackers got in, what was exposed, and if they still have access—knowing exactly how and what was compromised will help in the negotiation.

4. Settlement

After the ransom negotiations are over, companies must carefully consider the strategy behind the decision to pay or not to pay the ransom. The FBI generally discourages ransom payments because they may entice other criminals to engage in ransomware and paying does not guarantee data recovery. Additionally, the Office of Foreign Asset Control (OFAC) has payment bans and restrictions that support national security that must be upheld or face fines. At this stage, companies need to ensure that the ransom settlement does not violate constantly evolving regulations.

If companies settle, the payment will typically be delivered via cryptocurrency like Bitcoin since it is harder to detect the payees. The hackers will mix the bitcoin for others diluting the currency flow and making it difficult to trace.

5. Post-Event

For many companies, the settlement is just the beginning of ransomware attack costs. Companies will also have to pay to restore back-ups, rebuild systems and implement stronger cybersecurity controls to avoid future attacks. As discussed at the Cyber Risk Summit, here are five recommendations for companies to enforce tighter cyber control:

  1. Advanced Endpoint Monitoring System
  2. Restrict Remote Desktop Protocol (RDP)
  3. Regularly Update Software and Operating Systems
  4. Implement Password Management Policies
  5. Establish and Update Incident Response Plan and Ransomware Playbook

Ransomware is just getting started. To minimize the impact of an attack, companies create a proactive preparedness plan. Determining to protect and scan for threats, establish negotiation and payment rules, and external breach communications, is critical.

Breaches are our business at Experian. We know ransomware breaches have more complex FAQs, letter versions, and increased call center escalations.

To learn howExperian’s Reserved Responsesolution can prepare your business for a data breach,click here.

Sources:

1Washington Post, “How Ransomware Attacks Work”, July 2021

2Verizon 2021 Data Breach Investigations Report

3Washington Post, “Ransomware Axa Insurance Attacks”, June 2021

4Covewave, “Ransomware Marketplace Report”, Q4 2020

Related Posts

Rewriting the Road Ahead with Longer Loan Terms and Increased Refinancing Options

The automotive market is entering a new phase defined not just by what consumers are buying, but by how they’re choosing to finance it. According to Experian Automotive’s State of the Automotive Finance Market Report: Q1 2026, nearly one-third (35.55%) of all new vehicle loans now stretch more than six years, up from 30.83% in Q1 2025. Similarly on the used side, 31.54% of loans extended more than six years, an increase from 28.60% last year. The shift highlights why affordability is reshaping how consumers are financing their vehicles, particularly in larger and higher-priced vehicles. Refinancing gains traction as interest rates stabilize In addition to longer-term loans, consumers are becoming increasingly deliberate with their financing decisions and managing monthly payments as refinancing activity has gained momentum. For instance, consumers who refinanced this quarter lowered their interest rate by 2.2% and saved an average of $81 on their monthly payment. Credit unions, in particular, continued to play a major role in helping consumers secure more affordable payment options. In Q1 2025, credit unions accounted for the lion’s share of automotive refinancing at 63.43%, from 62.31% a year ago. By comparison, banks went from 23.51% to 22.59% year-over-year. Furthermore, those who refinanced with a credit union saved an average of $101 this quarter, whereas those who refinanced with banks saved $60. Expanding credit access through flexible financing Another notable trend this quarter was the incessant growth in subprime financing as credit accessibility across the market continues to increase. In the first quarter of this year, subprime borrowers made up 15.75% of total vehicle financing, from 14.40% last year. For new vehicles in particular, the subprime market went from 5.61% to 6.88% year-over-year, while subprime in used vehicle financing grew to 20.60% this quarter, from 19.36% a year ago. Increased activity in the subprime segment highlights continued confidence in the automotive market and underscores the importance of expanded financing options. As consumers seek greater flexibility with financing decisions that fit their lifestyle, lenders and dealers have the opportunity to approach them with more personalized solutions. These trends are helping keep both new and used vehicle markets moving forward, while creating new opportunities for consumers to manage payments and purchase confidently. To learn more about automotive finance trends, view the full State of the Automotive Finance Market Report: Q1 2026 presentation on demand.

Published: June 2, 2026 by Melinda Zabritski
Staying Competitive After Trigger Leads Evolve: A Roadmap For Lenders

Trigger leads have long been the preferred solution for identifying high-intent mortgage borrowers. But with the implementation of the Homebuyers Privacy Protection Act (HPPA), which introduces new limitations and consumer protections around trigger leads, that playbook will need to shift. Now, lenders are quickly facing a pivotal shift in how they discover, engage, and convert prospective borrowers into customers. The industry now stands at a crossroads. Lenders who adapt early—leaning into predictive tools, consent-based engagement, and smarter prescreening—will redefine borrower acquisition in a more privacy-centric era.  HPPA: A structural change to mortgage marketing  The HPPA amends the Fair Credit Reporting Act by significantly restricting the use of mortgage inquiries for prescreen purposes. As of March 5, 2026, credit bureaus may only provide or utilize mortgage inquiries to:  End users with explicit borrower consent  The originator of the consumer’s current mortgage  The servicer of the consumer’s current mortgage  An insured depository institution or credit union where the consumer has an existing account  While these exemptions may provide continuity for banks and credit unions, many mortgage brokers and nonbank lenders will need to overhaul their prescreen practices—or risk being cut off entirely from a previously high-performing acquisition channel.  Why this isn’t just a compliance shift—It’s a strategic recalibration  Mortgage triggers in prescreen allow lenders to react instantly to consumer intent. Lenders rely on a prompt and convincing narrative to entice applicants to switch lenders. Mortgage inquiry triggers are effective and were, therefore, a prospecting strategy for many lenders. Recent legislative changes significantly restrict the availability of these inquiry triggers, and impacted lenders are focusing on a more intentional prospecting strategy to compete.   Without these mortgage triggers in prescreen, lenders need to ask:  Who are we trying to reach?  What early signals can we act on?  How do we earn permission and attention before a mortgage inquiry ever happens?  Transforming the funnel: From reaction to anticipation  The shift in mortgage inquiry-based prescreen isn’t the end of high-intent lead targeting. It’s the beginning of a more strategic and intentional approach—one that leverages earlier indicators of mortgage readiness and focuses on building relationships, not just closing transactions.  Here’s where the momentum is evolving, creating a new and smarter funnel:  Prescreen marketing: Using credit and behavioral attributes to help identify consumers who meet specific lending criteria before they signal active intent.  Predictive modeling: Leveraging propensity scores or custom models to prioritize outreach based on conversion likelihood.  Consent-based engagement: Implementing compliant mechanisms to capture and manage borrower opt-ins at scale.  The power of predictive modeling  According to recent industry interviews, propensity modeling is emerging as one of the most effective replacements for trigger-based prescreen. These models analyze hundreds of credit attributes—such as utilization, account mix, account age, and depth—to help identify consumers statistically more likely to seek a mortgage.  For lenders just beginning to use predictive modeling, off-the-shelf models can be a quick way to identify potential borrowers. For example, when layering propensity scores on top of credit eligibility, which can improve borrower targeting, many lenders see an increase in open mortgage loan rates.  Meanwhile, custom-built models, which analyze a lender’s own campaign performance over time, offer the highest level of precise targeting. These models isolate the attributes most predictive of conversions within a specific product mix—optimizing not just volume, but fit.  Speed without traditional triggers? It’s possible  One of the biggest concerns among lenders is maintaining the speed historically enabled by trigger leads. But that concern may be overblown.  Self-service prescreen platforms now allow marketers to generate qualified lead lists in as little as 24 hours, enabling rapid response during rate drops, competitive shifts, or seasonal demand spikes.   For those new to prescreening, batch campaigns still offer value, especially with analyst support.   Don’t overlook retention  In an era of intense acquisition competition, retention becomes a key differentiator.  Lenders who monitor property status, cash flow, and consumer credit behavior can proactively identify when an existing borrower is likely to list, refinance, or exit. Armed with that intelligence, lenders can re-engage with the borrower at the right moment—sometimes before a competitor is considered or contacted.  This level of behavioral intelligence may soon separate proactive lenders from reactive ones.  Actions instead of reactions  The evolution of trigger-based prescreen doesn’t just require new tools; it demands new thinking. Lenders should begin by auditing their current pipelines and determining:  What percentage of our acquisition is dependent on triggers?  What share of our book falls under the HPPA exemptions?  How will we scale compliant opt-in collection?  Are our current prescreen or modeling capabilities future-ready?  Those who answer these questions today—and act on them—won’t just be in compliance with the new laws, they’ll lead in a transformed market. Lenders should also be asking:   Do we have the infrastructure to collect and act on borrower consent?  Are our acquisition teams equipped to run prescreen campaigns — both batch and self-service?  What predictive models are we using (or could we use) to prioritize leads?  Are we proactively monitoring our portfolio to catch retention risks early?  How are we preparing our sales teams for longer, more consultative buying journeys?  Conclusion  The HPPA signals a shift away from relying on passive, inquiry-based prescreen acquisition and the beginning of smarter, more strategic engagement with potential borrowers. Lenders who embrace this transition early will find themselves not just compliant, but competitive—with deeper borrower insights, better conversion rates, and stronger long-term customer relationships.  The market is moving. The only question is: will you lead the change or chase it?  Citation  Experian. (2025, November). Interview: How the Homebuyers Privacy Protection Act is reshaping mortgage marketing—and what lenders should do now [transcript]. Experian Mortgage Insights. Insights based on lender feedback, campaign performance data, and analysis of prescreen marketing strategies and predictive modeling outcomes were gathered from Experian client engagements and internal mortgage analytics between May and October 2025. Homebuyers Privacy Protection Act timeline and legal context referenced from legislation signed September 5, 2025, with implementation beginning March 5, 2026.   

Published: April 22, 2026 by Ivan Ahmed