Ransomware has changed a great deal since CryptoLocker made file-encrypting malware a household worry. A recent 2026 explainer tracing that history describes a line that runs through NotPetya, which was designed purely to destroy and caused an estimated $10 billion USD in damages, to today's Ransomware-as-a-Service (RaaS) groups such as LockBit, Akira and Qilin. For anyone thinking about ransomware protection for home users and small businesses, the history matters because each generation added a tactic that today's attackers still use.

From CryptoLocker to Akira and Qilin: how ransomware evolved

Early ransomware like CryptoLocker had a simple pitch: encrypt your files, then demand payment to unlock them. The victim's main question was whether they had a usable backup.

NotPetya changed the picture. According to the source article, its ransom mechanism was deliberately broken. It looked like extortion but was built to destroy, so paying could never have brought data back. That is a useful reminder that a ransom note does not guarantee a working decryption key.

Modern RaaS groups combine elements from all their predecessors. The source describes a familiar playbook for the 2020 to 2026 period:

  • Phishing as a delivery method
  • Credential theft to gain initial access
  • Lateral movement across a network before ransomware is deployed
  • Double extortion, meaning data is both encrypted and stolen

The RaaS model matters too. Groups like LockBit, Akira and Qilin operate as services, so the same proven techniques reach many more targets than a single criminal crew could manage. The takeaway for ordinary users is that the attacks often begin with something mundane: an email, a reused password, or a login that was never protected.

How double extortion turns stolen data into leverage

Double extortion is the biggest practical shift since the CryptoLocker era. If attackers copy your data before encrypting it, restoring from a backup solves only half the problem. The other half is the threat of publication or sale.

That is why lateral movement is significant. Attackers who spend time inside a network before triggering encryption have time to find and copy valuable files. By the time a ransom note appears, the theft may already be finished.

Data theft can have serious consequences even without any ransomware. The ChipSoft breach is a real-world example: the electronic health record provider confirmed on April 20, 2026 that sensitive patient data was exfiltrated. It shows why protecting data itself, and not only the ability to restore it, is part of any sensible defense. Encrypting sensitive files and limiting what is stored where can reduce what a thief walks away with.

Where a VPN helps and where it doesn't

VPNs come up often in ransomware conversations, so it is worth being precise about their role. A VPN encrypts your traffic between your device and the VPN server. That can help on untrusted networks such as public Wi-Fi, where it makes eavesdropping harder and may reduce one avenue for credential interception.

But a VPN does not stop the main routes described in the source article. It will not:

  • Stop you from opening a phishing attachment or clicking a malicious link
  • Protect a password you have reused on several sites
  • Remove malware already on your device
  • Restore files that have been encrypted

Think of a VPN as a modest layer that covers network exposure, not a ransomware shield. For small businesses, the same logic applies to remote access: a secured connection is helpful, but a stolen credential without multi-factor authentication can still let an attacker in.

Offline backups and habits that limit the damage

Because modern attacks involve phishing, credential theft and quiet movement through a network, the most realistic defenses are habits that limit each step.

Keep backups offline. A backup that stays connected to your computer can be encrypted along with everything else. Keep at least one copy disconnected or otherwise separated, and test that you can actually restore from it. Backups address encryption, but not data theft, so they are one part of the plan rather than the whole plan.

Treat email with suspicion. Since phishing is a leading delivery method, pause before opening unexpected attachments or links, even when a message appears to come from someone you know.

Protect your logins. Use a unique password for every account, a password manager, and multi-factor authentication wherever it is offered. Credential theft only works well when a single stolen password opens many doors.

Keep software updated. Patching operating systems, browsers and apps closes gaps that attackers rely on.

Limit what you store. Data that is not on your device or network cannot be stolen from it. Delete old files you no longer need and keep sensitive documents in encrypted storage.

What This Means For You

The history from CryptoLocker to Akira and Qilin points to one conclusion: no single tool covers everything. Backups protect against lost files, strong authentication makes stolen credentials less useful, careful email habits reduce the chance of infection, and a VPN adds a small but real layer on untrusted networks. The threat of leaked data means you should also think about what an attacker could take, not just what they could lock.

Small businesses face the same problems on a larger scale, especially when staff share credentials or remote access is loosely managed. Even a basic policy of unique passwords, multi-factor authentication and offline backups puts you ahead of many easy targets.

Key Takeaways

Good ransomware protection for home users comes down to a short list of repeatable steps: keep an offline, tested backup; use unique passwords with multi-factor authentication; be wary of unexpected emails; update your software; and store less sensitive data than you think you need. Use a VPN on public networks, but do not rely on it to stop ransomware.

For a practical step-by-step list, read our piece on why UK consumers need a 2026 ransomware defense plan too. To see why protecting data itself matters, revisit the ChipSoft breach and what it shows about encryption.