Enter your email address and password below to gain access.
To login to the Online Training Series, please click here.
Risk
10/07/2026
Insights Report: Surviving a Ransomware Attack
A ransomware incident can be devastating to a bank. But implementing a few preventative measures can ensure an institution is prepared to respond if targeted by cybercriminals.
Naomi Snyder is the editor-in-chief for Bank Director.
Emily McCormick is the vice president of editorial and research for Bank Director.
Jackie Stewart is the executive editor for Bank Director.
John Engen is a contributing writer for Bank Director.
Bank Director Research Group
SHARE THIS ARTICLE
*This article appears in the fourth quarter 2026 issue of Bank Director magazine.
Ransomware attacks are a significant risk to banks. Could your institution be caught off guard?
There are different types of ransomware attacks, but fundamentally, ransomware is a type of malicious software that encrypts its target’s data until a ransom is paid, usually in the form of cryptocurrency. Responding appropriately to such an attack starts long before the bank’s defenses are ever breached. By understanding what ransomware can look like and practicing the organization’s response, banks can limit expenses, risk and reputational damage.
“Prepare as if these attacks are going to occur, because they are of consequence,” says Patrick Ringsred, chief strategy officer with Navanta, a technology and services partner that provides cybersecurity and other services to community banks. “It’s not a good thing to develop a plan reactively given the consequential dynamics of this. It’s a high stress, difficult moment for a bank.”
Reported ransomware payments made over the blockchain hit an all-time high of $1.23 billion in 2023 then fell to $892 million the following year, according to a study by the blockchain research firm Chainalysis. Chainalysis found that ransomware actors nabbed $820 million in 2025, but the firm expects that number to grow as it continues to gather data. Financial services, manufacturing and healthcare were the top three industries targeted in ransomware attacks, according to a December 2025 analysis from the Financial Crimes Enforcement Network.
A few dynamics are influencing the way ransomware attacks are perpetrated today, according to Stephen Moss, chief operating officer with Navanta. Federal and international authorities have aggressively pursued some of the larger threat actors, leaving many others to continue to perpetrate attacks at a smaller scale. By demanding smaller dollar amounts, the attackers have a better chance of flying under authorities’ radar, Moss says.
Some ransomware attackers have recently begun attacking victims in a “smash and grab” style, meaning they get a little bit of their target’s data and try to convince their victim they’ve actually captured much more of it. In some cases, the criminal will use a screenshot or create an image using generative AI to act as proof that they’ve taken the data hostage. As with any type of fraud, the perpetrator is hoping the victim will panic and react before pausing to think about their next steps.
“If I can’t find evidence that it’s been done, maybe it was fabricated outright,” Moss says. “In the age of AI, so many things can be faked and forged.”
To learn more about surviving a ransomware attack, download the report, sponsored by Navanta, here.