Laptop on an office desk showing a locked screen warning

Business ContinuityCybersecurity

Malware vs. ransomware: How to tell the difference

Malware vs ransomware comes down to one relationship: ransomware is a type of malware. Malware is the umbrella term for any software installed to harm you or steal from you. Ransomware is the type built to extort a payment, usually by locking your files and threatening to publish data it copied first. Telling them apart matters, because they call for very different responses in the first hour.

Two calls on the same morning show it. One employee says her computer is slow and pop-ups keep appearing. Down the hall, another can’t open anything on the shared drive, and every folder has a new text file with instructions for paying in cryptocurrency. Both are malware problems. Only the second is ransomware.

Malware vs ransomware at a glance

Most malwareRansomware
GoalSteal data, logins or computing power quietlyGet paid
VisibilityHides for as long as it canAnnounces itself with locked files and a ransom note
ScopeOften one computer or one accountUsually the whole network, including file servers and backups
First responseIsolate and rebuild the device, reset passwordsA business emergency that may involve your insurer, legal counsel, law enforcement and regulators

The two are also linked. Ransomware attacks often start with ordinary malware, such as an infostealer or trojan that gives the attacker a foothold. Catching that first, quieter infection is one of the best ways to stop ransomware before it starts.

What counts as malware

The FTC describes malware as harmful software installed on your device without your knowledge, and lists viruses, spyware and ransomware as common types. The ones you are most likely to hear about:

Laptop with a warning graphic on its screen in a dark room
  • Viruses and worms, which spread by attaching to files or by copying themselves across a network.
  • Trojans, which pretend to be something useful, like a PDF reader or an invoice, and open a door for the attacker.
  • Spyware and keyloggers, which record what you type and do.
  • Infostealers, which grab saved passwords, browser cookies and session tokens so attackers can sign in as you.
  • Remote access tools, which give an attacker hands-on control of the machine.

Most of these are designed to stay hidden. The longer the attacker goes unnoticed, the more data and credentials they collect.

What makes ransomware different

Ransomware encrypts your files, servers or backups so you can’t use them, then demands payment for the key. It wants to be noticed, because the ransom note is the point. Today’s attacks usually go further: attackers spend days or weeks inside a network first, copying sensitive data, then threaten to publish or sell it if you don’t pay. That is often called double extortion, and it means good backups solve only half the problem.

48%

of breaches in Verizon’s 2026 Data Breach Investigations Report involved ransomware, up from 44% the year before

The same report has better news too. In Verizon’s data, 69% of ransomware victims didn’t pay, and the median payment fell to $139,875. Verizon also notes that small and mid-sized businesses are disproportionately affected, often with fewer resources to respond.

How both get in, and how they show up

Malware and ransomware use the same front doors. Verizon’s 2026 report found that exploiting software vulnerabilities is now the top way into breached organizations, ahead of stolen credentials for the first time. Watch unpatched firewalls and VPNs, accounts without multifactor authentication, phishing emails and fake login pages, fake downloads and search ads, and vendors or remote support tools that already have access to your systems.

The warning signs differ. General malware tends to show up as a computer that suddenly runs slowly or crashes, new toolbars or a changed home page, security software turned off, or login alerts you didn’t trigger. Ransomware shows up as files that won’t open and have new extensions, a ransom note on the desktop, many files on a shared drive changing at once, and backups failing or deleted without explanation.

What to do in the first hour

  1. Disconnect the affected device from the network. Unplug the cable or turn off Wi-Fi, and avoid powering it off, since memory can hold evidence.
  2. Call your IT provider. For ransomware, also call your cyber insurer before you hire anyone or contact the attackers, since many policies require it.
  3. Don’t pay without advice. The FBI does not support paying, because it doesn’t guarantee you get your data back and it funds more attacks. The Treasury Department’s OFAC has warned that paying a sanctioned group can bring civil penalties.
  4. Change passwords from a clean device, starting with email and admin accounts, and confirm MFA is on.
  5. Restore from clean backups only after the infection is removed, or you will reinfect the restored systems.
  6. Report it to the FBI at ic3.gov, and check your notification duties under state law or industry rules.

Healthcare organizations have an extra step. HHS says that when ransomware encrypts electronic protected health information, a breach is presumed unless you can show a low probability that the data was compromised. Our healthcare IT page covers how that plays out.

Protection that covers both

The same layers work against both threats: fast patching, MFA on every account, application control that blocks unknown programs, staff training that makes reporting easy, and endpoint detection and response watched around the clock. Every one of our clients has a 24/7 security operations center that can isolate a device at 2 a.m., which is part of our cybersecurity services. Across all of our clients, we have had zero ransomware events, zero malware outbreaks and no reportable data breaches.

Backups decide whether ransomware becomes a bad day or a bad month. Our server backups run hourly, are copied off-site daily, are immutable so an attacker can’t change or delete them, and are verified with screenshots. That is the core of our backup and business continuity service. Our ransomware prevention guide goes deeper, and our list of types of malware to watch for covers the quieter threats.

Whichever one you are worried about, the fix starts with knowing what would happen on your network tonight. Book an intro call and we will walk through it with you.

FAQ

Frequently asked questions

What is ransomware?

Ransomware is malware built to extort a payment, usually by encrypting your files, servers or backups and demanding money for the key. Most attacks today also copy sensitive data first and threaten to publish it, which is called double extortion. Ransomware was involved in 48% of breaches in Verizon’s 2026 Data Breach Investigations Report.

How do you prevent ransomware?

Patch quickly, especially firewalls and VPNs, put MFA on every account, and use application control so unknown programs can’t run. Add staff training that makes reporting easy and endpoint detection and response watched around the clock. Keep immutable backups that ransomware can’t change or delete, and test your restores.

Is ransomware a type of malware?

Yes. Malware is any software installed to harm you or steal from you, and ransomware is the type built to extort a payment. Ransomware attacks often start with quieter malware, such as an infostealer or trojan, that gives the attacker a foothold.

Sources: FTC: How to recognize, remove and avoid malware; Verizon: 2026 Data Breach Investigations Report news release, May 2026; Verizon: 2026 DBIR Executive Summary; FBI: Ransomware; U.S. Treasury OFAC: Updated advisory on sanctions risks for facilitating ransomware payments, 2021; HHS: Fact sheet, ransomware and HIPAA.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.