Ransomware rarely begins with a single careless click. A new breakdown from Adaptive Security catalogs 20 entry paths and describes how an intrusion moves from first foothold to encryption and extortion. The most common doors are phishing, stolen credentials, exploited public-facing applications, password spraying, and exposed remote services. Understanding ransomware infection vectors and defenses is the first step to closing those doors on a home or remote-work setup.
How Ransomware Gets In: The Most Common Entry Paths
According to the report, the first foothold usually comes from one of five routes:
- Phishing: emails or messages that trick someone into opening a file, link, or login page.
- Stolen credentials: valid usernames and passwords that attackers obtained elsewhere.
- Exploited public-facing applications: unpatched software or devices reachable from the internet.
- Password spraying: trying a few common passwords against many accounts.
- Exposed remote services: remote access tools left open to the internet.
The intrusion then progresses through execution, privilege escalation, persistence, lateral movement, data theft, encryption, and extortion. The encryption step is the last stage, not the first. That matters because it means defenders often have several chances to spot and stop an attack before any file is locked.
Stolen logins deserve special attention. Our coverage of how infostealer malware fuels attacks with stolen logins explains how a credential harvested from one infected device can later be used to walk through the front door. For a wider look at non-email routes, see our piece on how ransomware spreads beyond phishing emails.
Early Warning Signs Before Files Are Encrypted
Because the attack unfolds in stages, the signs often appear well before a ransom note. The stages described in the source suggest what to watch for:
- Unexpected logins or lockouts: repeated failed sign-ins or alerts from unfamiliar locations can point to password spraying or credential reuse.
- New accounts or changed permissions: privilege escalation and persistence often involve creating or modifying accounts.
- Unfamiliar remote access tools or settings: a remote service you did not enable is a red flag.
- Security software disabled: attackers commonly try to switch off protections before encrypting.
- Unusual network activity: large outbound transfers can indicate data theft ahead of extortion.
No single sign is proof of an attack, but several together justify immediate action: change passwords, disconnect the affected device, and check your accounts for changes you did not make.
Where VPNs and Remote Access Settings Help, and Where They Don't
A VPN is often described as a security cure-all. It is not, and it is worth being precise about its role.
Where a VPN can help:
- It encrypts traffic on untrusted networks such as public Wi-Fi, which reduces the chance of interception.
- When used as a gateway to remote work resources, it can keep internal services off the open internet. Placing a remote service behind a properly configured VPN with strong authentication is generally safer than exposing it directly.
Where a VPN does not help:
- It does not stop a phishing email from delivering malware.
- It does not protect a password that has already been stolen. If an attacker has valid credentials, a VPN does nothing to block their use.
- It does not patch vulnerable software. In fact, VPN gateways and other edge devices are themselves public-facing, so an unpatched one can become the entry point.
The takeaway is that remote access tools are part of your attack surface. A VPN you rely on needs the same care as any other internet-facing system: current updates, strong unique passwords, and multi-factor authentication.
Practical Steps to Harden PCs, Routers and Home Networks
The following steps address the entry paths above without requiring specialist skills.
- Use unique passwords and a password manager. This limits the damage when one login is stolen.
- Turn on multi-factor authentication for email, cloud storage, remote access, and financial accounts.
- Patch quickly. Enable automatic updates for your operating system, browser, apps, and router firmware.
- Close what you do not use. Disable remote desktop and any router remote-management features unless you truly need them. If you do need them, put them behind a VPN or other protected gateway rather than exposing them directly.
- Change default router credentials and use strong Wi-Fi encryption.
- Keep reputable endpoint protection running and do not disable it to install software.
- Back up important files offline or in a form that cannot be overwritten from your main device, and test that you can restore them.
- Separate devices where possible, for example by keeping work equipment off the same network segment as smart-home gadgets.
What This Means For You
If you work from home, your router, remote access settings, and account logins form the perimeter that attackers test. Phishing awareness still matters, but it is only one of several doors. Most of the other paths come down to two habits: keeping software updated and protecting credentials. A VPN can be a useful layer, especially on public networks, but it cannot replace patching, multi-factor authentication, or good password hygiene.
Key Takeaways
- Audit what is reachable from the internet: remote desktop, router admin pages, and any remote access tools.
- Check your credential hygiene: unique passwords, MFA everywhere, and no reuse across work and personal accounts.
- Update routers and other edge devices, not just laptops.
- Maintain tested backups so recovery does not depend on paying a ransom.
To understand how stolen logins enable these attacks, read our guide on infostealer malware, and for deeper coverage of non-email entry paths, see how ransomware spreads beyond phishing emails. Knowing ransomware infection vectors and defenses lets you shut the most likely doors before an attacker tries them.




