Solution Ransomware resilience

Backups restore your systems. Nothing un-steals your data.

Modern ransomware steals data before it encrypts anything, then threatens to publish it. OnData keeps sensitive data encrypted at the data layer, so what attackers take is ciphertext they can't use or leak.

  • Databases & files
  • Holds up with stolen credentials
  • Every access logged
Show the leak site
leak-site.onion/victims/example-county-hhs

Example County HHS — 412 GB

Posted by attacker · "Pay or we publish in"

Time left before publication:71:58:04

  • customers_full.sql
  • case_files/ (18,204)
  • payroll_2026.xlsx
  • intake_scans.zip
Sample of the records posted on the leak site
name ssn dob case_notes
R. Thompson Encrypted: Ma6$Wq1kY4 512-55-3390 Encrypted: u8Kd·Mn1x 1979-04-22 Encrypted: h2Wb·Dz6q Home visit 9/12 Encrypted: Gt2%Vb5jC8
J. Nguyen Encrypted: Pz3!Hd8nT0 512-55-3412 Encrypted: Rt5m·Zx2c 1990-08-15 Encrypted: e3Ns·Jh7w Income docs rec'd Encrypted: Bv9q··2Kd7
E. Washington Encrypted: Xq7#Lm9vR2 512-55-3465 Encrypted: k9F2·pQ8z 1958-09-14 Encrypted: u8Kd·Mn1x Appeal filed Encrypted: Lp4z··8Tr6

Readable PII for 18,204 citizens Extortion leverage · notification and legal exposure

Ciphertext only, keys never left OnData Nothing usable to sell or publish · access attempts logged

Click Without / With OnData to see what attackers actually get

Why ransomware is now a data problem

  • Encrypt + steal

    Double extortion is now the standard ransomware playbook, not the exception.

  • Backups don't help with theft

    Restoring systems does nothing about data already copied out.

  • Stolen credentials are the way in

    Disk and database encryption decrypt for anyone logged in, attackers included.

Double extortion

Ransomware is two attacks. Most defenses only cover one.

  • Attack 1 · Encryption

    “We locked your systems.”

    Attackers encrypt servers and endpoints to stop operations. Backups, EDR and recovery plans are built for this.

    • Covered: Immutable and offline backups
    • Covered: Endpoint detection and response
    • Covered: Tested recovery playbooks
  • Attack 2 · Exfiltration

    “We have your data. Pay or we publish.”

    Before encrypting, attackers copy databases and file shares. Restoring from backup doesn't change what they already have.

    • Not covered: Backups can't un-steal data
    • Not covered: Disk and TDE encryption decrypt for logged-in attackers
    • Not covered: Breach notification and legal exposure follow

Anatomy of an attack

Where OnData breaks the attack chain.

OnData doesn't replace your perimeter or endpoint tools. It makes the most valuable thing in your environment, the data, worthless once it's taken.

  1. Step 1

    Initial access

    Phishing, stolen credentials or an exposed service.

    Handled by identity, email and perimeter tools

  2. Step 2

    Privilege escalation

    Attackers become domain admin or a service account.

    OnData Admin rights don't include decryption rights

  3. Step 3

    Discovery

    They find the databases and shares worth stealing.

    OnData Unusual bulk access is logged and visible

  4. Step 4

    Exfiltration

    Data is copied out to attacker infrastructure.

    OnData What leaves is ciphertext, not records

  5. Step 5

    Encryption

    Systems are locked to force a ransom.

    Handled by backups and recovery

  6. Step 6

    Extortion

    “Pay, or we publish your data.”

    OnData No readable data means much less leverage

  • Where OnData acts
  • Covered by other layers of your stack

Your stack vs. ransomware

OnData fills the gap your other controls leave.

How backups, EDR, disk encryption and OnData each protect against ransomware
What it protects against Backups EDR Disk / TDE encryption OnData
Restoring locked systems Attack 1: encryption Yes Limits spread No No
Stolen drives or raw storage Physical or snapshot theft No No Yes Yes
Data stolen by a logged-in attacker Compromised user or admin credentials No If detected No Yes
Exported files and database dumps Data that's already left the system No No No Yes
Field-level record of who accessed what Investigation and notification scoping No Endpoint only No Yes

Keep your backups and EDR. OnData is the layer that protects the data itself.

Coverage

Protect the two places attackers go first.

  • Databases

    SecureDB

    Sensitive fields stay encrypted at runtime, so a stolen dump or a query from a compromised account returns ciphertext.

    Explore SecureDB
  • Files & shares

    SecureFile

    Encryption travels inside each file, so archives copied off file servers, laptops or SharePoint can't be opened.

    Explore SecureFile
  • Audit & visibility

    OnData platform

    Every decryption is tied to an identity, so you can spot bulk access early and scope an incident by record.

    Explore the platform

Incident day

What changes when data is already protected.

The hardest questions in a ransomware response are about the data. OnData gives your incident team better answers.

Many breach notification laws treat encrypted data differently when the keys weren't compromised. Whether that applies to your incident depends on your jurisdiction and facts. Consult legal counsel.

Answers to incident questions without OnData and with OnData
Question Without OnData With OnData
What did they take? Readable records, scope unknown Encrypted values, keys never left OnData
Whose data was exposed? Assume everyone in affected systems Decryption logs show exactly which records were read
Can they publish it? Yes, and they will if you don't pay Ciphertext has no value on a leak site
Do we have to pay? Extortion pressure on top of recovery Recovery decision is about systems, not secrets
  • What did they take?

    Without OnData
    Readable records, scope unknown
    With OnData
    Encrypted values, keys never left OnData
  • Whose data was exposed?

    Without OnData
    Assume everyone in affected systems
    With OnData
    Decryption logs show exactly which records were read
  • Can they publish it?

    Without OnData
    Yes, and they will if you don't pay
    With OnData
    Ciphertext has no value on a leak site
  • Do we have to pay?

    Without OnData
    Extortion pressure on top of recovery
    With OnData
    Recovery decision is about systems, not secrets

Who's targeted

Built for the sectors ransomware hits hardest.

  • Healthcare

    PHI is high-value leverage, and care can't stop.

  • Government

    Cities, counties and agencies with citizen data on file shares.

  • Education

    Districts and universities with student records and lean IT teams.

  • Financial services

    Customer and card data that attackers can sell directly.

FAQ

Ransomware questions.

Have another question? Talk to our team →

Does OnData replace backups or EDR?

No. Backups restore systems and EDR detects threats. OnData protects the data itself, so it adds the layer those tools don't cover: data that's already been stolen.

What if attackers get domain admin rights?

Admin rights don't include decryption rights. An attacker with admin access can reach the protected data, but without an OnData policy that allows it they only see ciphertext, and the attempts are logged.

Can ransomware still encrypt our OnData-protected data?

Yes. Ransomware can still lock the systems it reaches, which is why you keep your backups. What it can't do is read the protected data, so a copy taken for extortion has nothing usable in it.

Does encrypted data change our breach notification obligations?

It can. Many breach notification laws treat encrypted data differently when the keys weren't compromised. Whether that applies depends on your jurisdiction and the facts of the incident, so check with legal counsel.

How quickly can we protect our highest-risk data?

Most teams start with the databases and file shares an attacker would go after first, such as customer, case and payroll data. We'll scope that first step with you on a readiness call.