A New Ransomware Strain Built for Speed

Security researchers have identified a new ransomware variant called Spirals that can encrypt an entire victim network in under 24 hours, a timeline far faster than many established ransomware families typically require. The speed comes down to a technique known as intermittent encryption, which the malware applies to any file larger than 5MB. Instead of scrambling every byte of a large file, Spirals encrypts only portions of it, cutting processing time dramatically while still rendering the data unusable without a decryption key.

This efficiency matters because ransomware operators have long faced a tradeoff: the longer an attack takes to fully encrypt a network, the more chances defenders have to detect unusual activity and shut it down before real damage occurs. By compressing that window into a single day, Spirals gives security teams far less time to respond once the malware activates inside a compromised environment.

How the Attack Unfolds

Once Spirals has encrypted files across a compromised system, it drops a ransom note named RECOVERY_SECTION.log directly on the victim's C:\ drive. The note contains instructions for negotiating payment with the attackers. Like many modern ransomware operations, Spirals follows a double extortion model: beyond locking files, the group behind it claims to have already stolen sensitive data before encryption began.

Victims are given a strict deadline of six days to pay before the attackers threaten to publish the stolen information publicly. This tactic has become standard across the ransomware ecosystem precisely because it works. Even organizations that maintain solid backups and can restore encrypted files without paying a ransom still face pressure from the threat of leaked customer records, employee data, or proprietary information appearing on a dark web leak site. This pattern mirrors what happened in the Genesis ransomware attack on United Personnel, where a staffing agency faced the prospect of hundreds of gigabytes of data being exposed alongside the encryption itself.

Why Faster Encryption Raises the Stakes for Everyone

The compressed attack window that Spirals introduces has real consequences beyond the immediate victim organization. Ransomware incidents increasingly involve theft of personal data belonging to customers, patients, or employees who have no direct role in an organization's security posture but bear the downstream risk when that data is exposed. Healthcare systems in particular have been frequent targets, as seen in incidents like the iRhythm ransomware breach that exposed cardiac patient data. When encryption happens in hours rather than days, security teams have less opportunity to isolate affected systems before attackers complete both the encryption and the data theft that fuels the extortion threat.

For everyday internet users, the practical outcome of a ransomware attack rarely differs based on how fast the malware encrypted files. What matters most is what happens to any personal data caught up in the breach. As outlined in our breakdown of what happens to your data after a breach, stolen information often circulates well beyond the initial leak site, getting bought, sold, and repackaged for phishing campaigns, identity theft, and credential stuffing attacks long after the headlines fade.

What This Means For You

If you're an individual consumer, Spirals itself is not something you need to defend against directly. This ransomware targets organizational networks, not personal devices. However, the broader trend it represents (faster, more efficient attacks with tighter extortion deadlines) means breach notifications are likely to keep arriving with less warning and potentially larger scope. If a company you do business with, or an employer, discloses a Spirals-related incident, treat it seriously and act quickly rather than waiting to see if your data surfaces somewhere.

For IT and security teams, the six-day exposure deadline effectively compresses the incident response timeline as well. Detection and containment need to happen fast, since traditional response windows measured in days may no longer be sufficient once encryption itself is complete in under 24 hours.

Actionable Takeaways

If you receive a breach notification referencing Spirals or a similar fast-acting ransomware strain, change passwords immediately for any affected accounts and enable multi-factor authentication wherever it is offered. Monitor your financial statements and credit reports for unusual activity in the weeks following any notification, since stolen data from these attacks often does not appear on the open web immediately. Consider placing a fraud alert or credit freeze if the breach involved sensitive identifiers like Social Security numbers or medical records. Organizations should prioritize network segmentation and rapid detection tools, since the speed of attacks like Spirals leaves little margin for slow incident response. Staying informed about which companies and platforms you use have disclosed incidents remains one of the simplest ways to protect yourself before problems escalate.