How Ransomware Groups Use Phishing as Their Entry Point

Ransomware is the most financially destructive form of cybercrime on the internet. In 2026, ransomware and extortion attacks cost organisations an average of $5.08 million per breach,more than any other attack type. Governments have been paralysed. Hospitals have diverted patients. Critical infrastructure has been taken offline.
And in the majority of cases, it all started with a phishing email.
Phishing was the primary means of gaining initial access in over half of all Cisco Talos Incident Response engagements in Q2 2026; an increase from approximately a third of engagements in the previous quarter. Attackers continued to innovate their delivery methods to evade defences, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms.
Understanding exactly how ransomware groups use phishing, not just that they do, is essential for building effective defences. This article breaks down the complete attack chain, from the initial phishing email to the ransom demand, and what organisations can do to disrupt it at every stage.
The Ransomware Landscape in 2026
Before examining the phishing connection, it helps to understand the structure of the modern ransomware ecosystem.
Ransomware is no longer the domain of lone criminal hackers. It has evolved into a highly organised, commercially structured criminal industry built on specialisation and outsourcing.
Ransomware-as-a-Service (RaaS) is the dominant model. RaaS operators — groups like LockBit, Black Basta, Akira, Qilin, and Rhysida — develop and maintain the ransomware code, payment infrastructure, and victim negotiation portals. They then recruit affiliates — independent criminal operators — who handle the actual attacks. Affiliates pay a percentage of ransom proceeds (typically 20-30%) to the RaaS operator. This separation means the people writing the ransomware code are rarely the same people launching the phishing campaigns that deliver it.
95 active ransomware gangs are now tracked globally — a 40% increase year-over-year. This proliferation is driven almost entirely by the RaaS model lowering the technical barrier to entry. An affiliate does not need to write malware. They need to be good at one thing: getting initial access.
Initial Access Brokers (IABs) are a third actor in the ecosystem. IABs specialise in compromising organisations — often through phishing — and then selling that access to ransomware affiliates on dark web marketplaces rather than deploying ransomware themselves. Access broker advertisements on dark web forums increased 50% year-over-year, enabling less technical actors to purchase initial access to corporate networks.
The result is a sophisticated criminal supply chain where phishing is the foundation on which everything else is built.
Phase 1: Initial Access — The Phishing Campaign
Ransomware attacks begin long before any file is encrypted. The first phase — initial access — is almost always the quietest, and often the most consequential. The decisions made here determine everything that follows.
Reconnaissance Before Phishing
Sophisticated ransomware affiliates do not send random phishing emails. They research targets first.
Open-source intelligence (OSINT) gathering identifies key individuals — the CFO whose email is on the company website, the IT administrator whose LinkedIn profile lists the specific VPN and remote access tools the company uses, the accounts payable clerk whose name appears on an invoice posted publicly online.
80% of ransomware attacks now leverage AI tools in some capacity, including in reconnaissance, crafting phishing emails, automating vulnerability exploitation, and negotiating ransom payments. AI-powered reconnaissance tools can scrape LinkedIn, company websites, job postings, and public documents to build detailed profiles of target organisations in hours — identifying personnel, technology stack, suppliers, and communication patterns.
Job postings are particularly valuable for attacker reconnaissance. A job posting for “Microsoft Azure Administrator” reveals the cloud platform. A posting for “Cisco Meraki Network Engineer” reveals the network infrastructure. A posting for “SAP Consultant” reveals the ERP system. Every job posting an organisation publishes is a free intelligence briefing for attackers.
The Phishing Email
Armed with reconnaissance data, the attacker crafts a targeted phishing email. The most effective ransomware-enabling phishing campaigns in 2026 use several consistent approaches:
Business context lures — emails that fit naturally into the victim’s working context. An accountant receives a supplier invoice. An HR manager receives a job application. An IT administrator receives a security alert from a known vendor. The email references something plausible and expected, reducing the friction that makes people pause before clicking.
Brand impersonation — emails impersonating Microsoft (particularly Microsoft 365 security alerts and SharePoint notifications), DocuSign, delivery companies, and financial institutions. These lures work because they trigger familiar workflows — logging in to review a document, signing a delivery notice, verifying a payment.
Thread hijacking — one of the most dangerous techniques. Attackers who have already compromised one account in a supply chain use that account to reply to existing legitimate email threads. The phishing content arrives inside a genuine conversation between known parties, with full email history visible. Defenders have very little to trigger on — the sender is real, the domain is real, the context is real.
QR code delivery — attackers continued to innovate their delivery methods, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. QR codes bypass URL scanning entirely. The malicious URL is encoded in an image that email security gateways cannot parse.
Malicious attachments — despite email gateways becoming more sophisticated, malicious attachments remain effective through:
- Password-protected ZIP files (content not scanned by most gateways)
- OneNote files with embedded scripts (a surge in 2023-2024 that continues)
- PDF files with embedded links or QR codes
- HTML files using smuggling techniques to assemble malicious payloads in the browser
What the Link or Attachment Does
The initial click typically achieves one of three things:
1. Credential harvesting — the victim is taken to a convincing fake login page (often an AiTM proxy of the real Microsoft 365 or VPN login page) that captures their username, password, and session token. The attacker now has authenticated access to the organisation’s environment.
2. Malware delivery — the click or attachment execution installs a dropper or loader on the victim’s device. Common loaders used in pre-ransomware campaigns include QakBot (Qbot), IcedID, Emotet, and Gootloader. Rhysida ransomware commonly leverages Gootloader during initial access. These loaders establish persistence on the device and communicate back to the attacker’s command-and-control infrastructure, awaiting further instructions.
3. Direct code execution — macros in Office documents, scripts in OneNote files, or LNK files in archives execute code directly. Modern defences have reduced macro effectiveness, but attackers have adapted with ClickFix attacks — convincing users to manually paste and execute PowerShell commands under the guise of “fixing” a display error or completing a CAPTCHA.
Phase 2: Establishing Persistence
Immediately after gaining initial access, the attacker’s priority is ensuring they maintain that access even if the initially compromised account is discovered and locked.
Persistence mechanisms commonly observed in ransomware pre-deployment phases include:
Creating new privileged accounts — adding a new local administrator or domain administrator account with an innocuous-sounding name.
Installing remote access tools — legitimate remote management tools like AnyDesk, TeamViewer, or Splashtop are frequently deployed by ransomware affiliates because they blend in with legitimate IT activity and are rarely flagged by endpoint security.
Registering new MFA devices — once inside a Microsoft 365 environment, attackers register a new authentication device to their compromised account, ensuring continued access even if the victim changes their password.
Setting up OAuth applications — malicious OAuth apps registered in the victim’s Azure AD tenant maintain persistent access through application permissions that survive password resets.
63% of attackers go undetected for up to 6 months before deploying ransomware, using the dwell time to map networks, exfiltrate data, and disable security controls.
Phase 3: Reconnaissance and Lateral Movement
With persistence established, the attacker enters the network reconnaissance phase — silently mapping the environment they now have access to.
Active Directory enumeration is almost universal in ransomware incidents. Tools like BloodHound and SharpHound automatically map the Active Directory structure, identifying privileged accounts, trust relationships, and the shortest path to domain administrator access. This phase often takes days or weeks as the attacker patiently builds their understanding of the network.
Credential harvesting from memory — tools like Mimikatz extract credential material from Windows memory, including NTLM hashes and Kerberos tickets that can be used for lateral movement without needing plaintext passwords.
Lateral movement — using harvested credentials, the attacker moves through the network, compromising additional systems. Common techniques include:
- Pass-the-Hash — using NTLM hashes to authenticate without knowing the password
- Pass-the-Ticket — using stolen Kerberos tickets to access resources
- Remote service exploitation — using compromised credentials to authenticate to RDP, SMB, or WMI on other systems
- Living-off-the-land — using built-in Windows tools (PsExec, WMI, PowerShell Remoting) to avoid deploying detectable malware
Data exfiltration — modern ransomware operations almost universally exfiltrate data before encrypting it, enabling double extortion: if the victim refuses to pay for decryption, the attacker threatens to publish the stolen data on their leak site. Exfiltration tools commonly observed include Rclone (for cloud storage exfiltration), MEGAsync, and WinSCP. Data volumes exfiltrated before ransomware deployment often reach terabytes.
Phase 4: Pre-Ransomware Actions
In the days or hours before encryption begins, the attacker takes steps to maximise the impact of the attack:
Disabling security tools — endpoint detection and response (EDR) tools, antivirus software, and backup agents are targeted for deletion or disablement. Tools like GMER and Process Hacker are used to terminate security processes. Windows Defender is disabled through registry modifications or Group Policy.
Destroying or encrypting backups — the attacker identifies and targets backup solutions. Volume Shadow Copies (Windows’ built-in backup mechanism) are deleted using vssadmin. Network-connected backup systems are encrypted or deleted. Cloud backup synchronisation may be corrupted.
Compromising domain controllers — ransomware deployment typically happens from domain controllers, which have administrative access to every machine in the domain. Compromising domain controllers is therefore the key objective in most ransomware attacks.
Staging ransomware — the ransomware binary is distributed to target systems through legitimate administrative tools, scripted deployment, or Group Policy.
Phase 5: Ransomware Deployment
The encryption phase is deliberately timed. Most ransomware is deployed outside business hours — late at night, over weekends, or on public holidays — to maximise the number of systems encrypted before anyone notices and to delay the response.
The encryption is fast. Modern ransomware uses sophisticated hybrid encryption (asymmetric key exchange + symmetric file encryption) and partial-file encryption to maximise speed. A well-configured ransomware deployment can encrypt an entire enterprise network in minutes.
The ransom note is displayed prominently on encrypted systems, directing victims to a Tor-based negotiation portal where the ransom demand — typically ranging from hundreds of thousands to tens of millions of pounds — is presented with a countdown timer.
The Major Ransomware Groups and Their Phishing Techniques
Black Basta
Black Basta emerged in early 2022 and quickly became one of the most prolific ransomware groups, targeting critical infrastructure, healthcare, and manufacturing. Their initial access methods have evolved significantly.
Black Basta is strongly associated with QakBot (Qbot) for initial access — a banking trojan repurposed as a loader that is almost exclusively delivered through phishing campaigns. In 2025 and 2026, Black Basta adopted email bombing as a precursor to phishing: flooding a target’s inbox with thousands of spam emails to overwhelm them, then calling the victim posing as IT support to offer help — and using the call to social-engineer the installation of remote access tools.
Akira
Akira ransomware has been particularly active targeting UK organisations in 2025-2026. Their initial access vectors combine phishing for credential theft with exploitation of VPN vulnerabilities — particularly Cisco ASA and Fortinet VPN vulnerabilities. Phishing campaigns targeting IT administrators with fake Cisco support communications have been observed as a precursor to Akira attacks.
Qilin
Qilin is a RaaS operation that specifically targets healthcare and educational institutions. Their phishing campaigns are notable for sophisticated spearphishing that uses detailed personal and organisational information gathered through OSINT, combined with healthcare-specific lures — NHS system notifications, CQRS alerts, and NHS Digital communications.
Rhysida
Talos IR responded to a ransomware incident where the adversary attempted to deploy Rhysida ransomware, attributing the activity with moderate confidence based on the use of Gootloader, which is commonly leveraged in Rhysida attacks during initial access. Rhysida has targeted local government, educational institutions, and healthcare providers in the UK specifically.
What Defenders Must Do
Understanding the attack chain reveals where defences can be most effectively deployed.
Stop Phishing from Reaching Inboxes
DMARC at enforcement (p=reject) — prevents your domain from being spoofed in delivered email. Every organisation should be at p=reject as a baseline.
Email security gateway with QR code scanning — as QR code phishing has become a primary delivery mechanism, ensure your email security platform has QR code URL extraction enabled.
User awareness training — specifically covering the phishing lures used in ransomware campaigns: fake invoice emails, Microsoft security alerts, IT support calls, and thread hijacking. Run simulations that mirror real ransomware precursor campaigns, not generic phishing test emails.
Stop the Loader from Executing
Disable macros in Office applications — enforce this through Group Policy. Office macros should be disabled for all users except those with a documented business need.
Attack surface reduction rules — Microsoft Defender’s Attack Surface Reduction (ASR) rules block specific techniques commonly used in ransomware precursor campaigns, including blocking Office applications from creating child processes, blocking JavaScript and VBScript from launching executables, and blocking credential stealing from Windows local security authority.
Application control — prevent execution of unsigned or untrusted executables through Windows Defender Application Control (WDAC) or AppLocker.
Detect Lateral Movement Early
Privileged Identity Management — implement just-in-time privileged access. Domain administrator accounts should not exist as always-active accounts that are constantly available for attackers to target.
Honey accounts and honeypots — create decoy administrator accounts that should never be used legitimately. Any authentication attempt against these accounts is an immediate high-confidence indicator of compromise.
Network segmentation — limit lateral movement by segmenting the network so that a compromise in one zone cannot easily spread to others. Domain controllers should be isolated in a dedicated network segment.
Monitor for lateral movement indicators — configure SIEM alerts for: mass authentication attempts, BloodHound-associated LDAP queries, unusual use of administrative tools (PsExec, WMI, PowerShell Remoting), and Mimikatz signatures.
Protect Backups
Immutable backups — ensure backups cannot be modified or deleted by ransomware. Cloud backup services with object lock, tape backups kept offline, or backup solutions with separate credentials that are never exposed to the main network.
Test your backups — knowing you have backups is not the same as being able to restore from them under pressure. Test restoration quarterly at minimum.
3-2-1 backup rule — three copies of data, on two different media types, with one copy off-site or offline.
Prepare for Incidents
Incident response plan — document exactly what to do in the first hour of a ransomware incident. Who has authority to isolate systems? Who calls law enforcement? Who contacts legal and PR? This plan should be tested through tabletop exercises before you need it.
Cyber incident reporting — if your organisation is in a regulated sector or falls under the UK’s expanded NIS framework, you have obligations to report significant incidents. Know your reporting obligations before an incident occurs.
Do not pay without professional advice — paying a ransom does not guarantee decryption, may violate sanctions regulations if the attacker is on a sanctions list, and may fund further criminal activity. Engage a specialist cyber incident response firm before making any payment decision.
Conclusion
When you account for BEC, data breaches, and ransomware that originate with a phishing email, phishing’s total loss enablement exceeds $4.3 billion conservatively — making it the highest-ROI initial attack investment in the criminal toolkit.
Ransomware is a phishing problem first. The encryption that makes ransomware so devastating is the final step in a multi-week attack chain that almost always begins with a targeted email. Stopping ransomware means stopping the phishing campaigns, loader executions, credential thefts, and lateral movement techniques that precede it — not just the ransomware binary itself.
Every layer of the ransomware attack chain is disrupted by controls that should be deployed regardless: DMARC, phishing-resistant MFA, endpoint protection, network segmentation, privileged access management, and immutable backups. None of these are novel or expensive. All of them work.
The organisations that get hit with ransomware are not the ones that lack sophisticated technology. They are the ones that left the phishing email in the inbox, the MFA SMS-based, the backup connected to the network, and the domain administrator password unchanged for three years.
Submit ransomware-related phishing emails and IOCs to PhishScout at phishscout.net Sources: Cisco Talos IR Q1 and Q2 2026 · IBM Cost of a Data Breach 2025 · Verizon DBIR 2026 · CrowdStrike Global Threat Report 2025 · Microsoft Digital Defense Report 2025