Ransomware and Cyber Extortion
Encrypt, steal, threaten, demand. Here's how the attack runs and which control breaks each step.
Cyber extortion is a threat delivered or carried out through a digital channel, used to force the victim to pay. Ransomware is its best-known form: malicious software encrypts an organisation's files so they can't be opened, and the attacker demands payment, usually in cryptocurrency, for the key. Many groups now also copy the data before encrypting it and threaten to publish it, so restoring from backup no longer ends the threat.
Banks and their technology vendors are attractive targets because downtime is so costly: a branch network that can't open its core banking system can't serve anyone. The same pressure works on individuals in sextortion, where a victim is threatened with release of private images.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
How a Ransomware Attack Usually Unfolds
The defender's view: each stage is a point where a control can stop it.
- 1
Entry
A phishing email, a stolen remote-access password, or an unpatched internet-facing server.
- 2
Spread
The attacker moves through the network and gains administrator rights, often over days or weeks without being noticed.
- 3
Data theft
Sensitive data is copied out, to be used as leverage later.
- 4
Backups targeted
Online backups are deleted or encrypted so the victim can't simply restore.
- 5
Encryption and demand
Files are encrypted across as many systems as possible, and a ransom note gives payment instructions and a deadline.
Controls Mapped to the Stages
Email filtering and staff awareness
Type
Preventive
What it stops
The phishing email that opens the door
Multi-factor authentication on remote access
Type
Preventive
What it stops
Entry with a stolen password
Timely patching
Type
Preventive
What it stops
Entry through known software flaws
Least-privilege access and network segmentation
Type
Preventive
What it stops
Spread from one machine to the whole network
Security monitoring of unusual activity
Type
Detective
What it stops
Spread and data theft before encryption begins
Offline or immutable backups, tested by restoring
Type
Corrective (mitigation)
What it stops
Being forced to pay to recover data
Incident response plan rehearsed in advance
Type
Corrective (mitigation)
What it stops
Confused, slow decisions on the day
| Control | Type | What it stops |
|---|---|---|
| Email filtering and staff awareness | Preventive | The phishing email that opens the door |
| Multi-factor authentication on remote access | Preventive | Entry with a stolen password |
| Timely patching | Preventive | Entry through known software flaws |
| Least-privilege access and network segmentation | Preventive | Spread from one machine to the whole network |
| Security monitoring of unusual activity | Detective | Spread and data theft before encryption begins |
| Offline or immutable backups, tested by restoring | Corrective (mitigation) | Being forced to pay to recover data |
| Incident response plan rehearsed in advance | Corrective (mitigation) | Confused, slow decisions on the day |
The Law That Applies
Extortion is defined in section 308 of the Bharatiya Nyaya Sanhita, 2023 (formerly IPC sections 383 and 384): intentionally putting a person in fear of injury and thereby dishonestly inducing them to hand over property. The BNS illustration explicitly covers a threat sent through an electronic device. Punishment is up to 7 years, or a fine, or both. The ransomware itself falls under the IT Act: introducing a computer contaminant, damaging data and denying access to authorised users are all section 43 acts, and doing them dishonestly or fraudulently is an offence under section 66. Sextortion adds IT Act sections 66E and 67A.
For the bank as victim, the reporting clock matters. CERT-In's April 2022 Directions require ransomware and other listed incidents to be reported to CERT-In within 6 hours of noticing them, and require ICT system logs to be kept for a rolling 180 days. RBI has its own reporting requirements for banks, covered on the bank incident-reporting page.
Quick practice on banking operations. No signup.
Paying Does Not Close the Incident
Payment does not guarantee a working key, does not stop a leak of data already copied, and does not remove the attacker's access. The bank's reporting duties, forensic investigation and customer obligations apply whether or not a ransom is paid. Any decision on payment belongs to the bank's board-approved crisis process with legal and regulatory input, never to an individual.
How the IIBF Exam Tests This
Expect control-classification questions: offline backups are a corrective or mitigation control, not a preventive one; MFA and patching are preventive. Also definition questions on extortion versus cheating. Extortion works through fear; cheating works through deception. A caller who frightens a victim into paying is extorting; one who tricks a victim into paying is cheating.
FAQs
What is ransomware in simple words?expand_more
Malicious software that locks an organisation's files by encrypting them, followed by a demand for payment to unlock them. Many attackers also steal the data and threaten to publish it.
What is the punishment for cyber extortion in India?expand_more
Extortion under BNS section 308 carries up to 7 years, or a fine, or both. The attack on the computer system adds IT Act section 66 (up to 3 years, fine up to ₹5 lakh, or both).
Within how many hours must a ransomware attack be reported to CERT-In?expand_more
Within 6 hours of noticing it, under CERT-In's Directions of 28 April 2022, which list ransomware among the reportable incident types.
What is the best protection against ransomware for a bank?expand_more
Layers: email filtering, MFA on remote access, patching and least-privilege to prevent entry and spread; monitoring to detect it early; and offline, tested backups so systems can be restored without paying.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
