Picture the standard ransomware playbook. Attacker breaches the network, encrypts the data, posts the ransom note. Victim pays, gets the decryption key, restores, files the insurance claim, moves on. That last part is the part that is breaking. A growing share of attackers are taking the ransom and refusing to hand over the key. The whole point was never the negotiation. It was the destruction. The shape has a name. Wipers.
Lineage worth knowing. Shamoon hit Saudi Aramco in 2012. NotPetya burned across Ukraine and the rest of the world in 2017. WhisperGate landed in 2022. Three different actors, the same shape, which is to make the systems unusable rather than extract a payment. The criminals have learned the lesson. A wiper disguised as a standard ransomware play extracts more from the threat of irrecoverable loss than it ever would from a working decryption tool. So now the same trick is being run against companies that do not normally get caught in geopolitical crossfire.
What the attacks actually look like
Most of these start life looking like normal ransomware. Attacker uses the standard playbook up to the moment of payment, then refuses to negotiate. Victim finds out there is no decryption coming only when it is too late to matter. Some of them come in through the supply chain instead. Attacker compromises a software vendor, slips the payload into a routine update, and the wiper activates on a target date across every customer at once. SolarWinds, 3CX, the xz utils near miss, all the same shape, just different payloads. A smaller number arrive via an insider, which is rare but the most damaging variant because the access is legitimate and the wiper lands without tripping the usual alerts.
Who is doing it, and why
State actors, criminals, and hacktivists all reach for wipers, and the reason is different in each case. State actors are making a point. Timing tied to a geopolitical event, target usually in energy, finance, defence supply, or critical infrastructure, goal is visibility rather than profit. Criminal groups are extracting a ransom through the threat of destruction, having realised that the credible threat of irrecoverable loss is worth more than any working decryption tool. Hacktivists just want the message out. No ransom demand, no decryption promise, just the political statement in the wreckage.
What to do about it
Start with the backup. Immutable, off the wiper’s reach, tested and restored on a regular cadence. Offline, a separate cloud account, or true immutable storage, all of them work. Difference between a wiper being a recoverable incident and an existential one almost always comes down to whether the backup exists at all, full stop.
Then a documented IR plan for the wiper scenario specifically. Communication, the decision to pay or not, the recovery sequence, the legal hold on evidence. All of it written down, all of it run through a tabletop exercise.
Threat intelligence that connects a geopolitical signal to a technical defence is the third piece. If a state actor is signalling toward your industry, the supply chain side and the credential rotation side should be tightening before the next update cycle, not after.

The bottom line
Immutable backup, tested IR plan, threat intelligence worth a damn. Wipers are not going away, and the defender who treats them as a normal ransomware problem is the one who will lose the data when the negotiation fails.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



