Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog
Phishing

How Phishing Leads to Ransomware: The Complete Attack Chain, AI-Powered Threats, and Defenses That Stop It

AUGUST 7, 202626 MIN READ
Adaptive TeamAdaptive Team
How Phishing Leads to Ransomware: The Complete Attack Chain, AI-Powered Threats, and Defenses That Stop It

Key takeaways

  • Phishing is among the dominant delivery mechanisms for ransomware, cited as the entry point by 35% of affected organizations in 2025.
  • The attack chain runs through five stages: OSINT reconnaissance, payload delivery, loader and command-and-control installation, lateral movement with backup destruction, and encryption paired with extortion.
  • Attack timelines have compressed sharply, with median dwell time falling below 24 hours and more than half of ransomware deployments occurring within a single day of initial access.
  • Extortion has moved past encryption alone, with confirmed data theft present in 77% of ransomware intrusions.
  • Defense requires layered controls: DMARC enforcement at the inbox, macro blocking and zero-trust segmentation at the endpoint, immutable backups for recovery, and continuous security awareness training for the human layer.

Phishing leads to ransomware through a predictable attack chain. It begins the moment an employee opens a malicious email and ends with encrypted files, stolen data, and a ransom demand on the screen.

This article maps every stage of that chain, from open-source intelligence (OSINT) reconnaissance and initial access through email to lateral movement, backup destruction, and encryption execution across the domain.

It examines how AI-generated phishing, deepfake vishing, and smishing are compressing attack timelines and defeating traditional defenses.

It also explains why Initial Access Brokers and Ransomware-as-a-Service operations have industrialized the phishing-to-ransomware pipeline, and which technical and human-layer defenses disrupt the kill chain at each point.

The 2026 Verizon Data Breach Investigations Report confirms phishing remains the most common initial access vector for ransomware.

Understanding how phishing leads to ransomware at every stage, and the specific defenses that break the chain, is what separates organizations that contain incidents from those that end up on a ransomware leak site.

How phishing leads to ransomware: an employee laptop displaying a ransomware encryption warning after a malicious email click.

Why Phishing Leads to Ransomware More Often Than Any Other Vector

The question of how phishing leads to ransomware starts with a simpler one: why phishing works at all.

Phishing dominates as the ransomware infection vector because it exploits the one vulnerability no patch can fix, which is human decision-making under pressure.

The mechanism persists for three compounding reasons: irresistible economics for attackers, reliable cognitive manipulation of targets, and a technical architecture that sidesteps perimeter defenses entirely. A closer look at how phishing works shows why each factor reinforces the others.

The Statistical Case: Phishing's Dominance in Ransomware Delivery

For small and midsize businesses, the exposure is starker still. Ransomware was involved in 88% of breaches in that segment. These organizations rarely have dedicated security operations centers or advanced endpoint detection, which makes the phishing-to-ransomware pipeline especially lethal.

IBM's 2025 Cost of a Data Breach Report confirmed that phishing remained the most common initial attack vector, present in 16% of incidents and costing an average of $4.8 million per breach.

The financial damage compounds when phishing delivers ransomware.

"Ransomware has become one of the top cybersecurity threats facing organizations worldwide, spread primarily through email phishing scams and exploitation of unpatched software bugs," said Dr. Atanu Lahiri, Associate Professor of Information Systems at the Naveen Jindal School of Management, University of Texas at Dallas.

The concentration of risk in a single vector creates a policy tension. Banning ransom payments could deter attacks, yet such a ban penalizes victims who need rapid data recovery, particularly hospitals and critical infrastructure operators.

The Human Factor: Why Employees Click Phishing Emails

Phishing succeeds because it weaponizes cognitive biases that operate faster than rational analysis. Three psychological levers appear repeatedly in the most effective ransomware-delivery campaigns.

Urgency is the most reliable trigger. An email warning that an account will be deactivated within two hours, a document requiring immediate signature, or a wire transfer that must clear before close of business all activate the brain's threat-response circuitry. That reaction fires before the prefrontal cortex can evaluate the message for deception.

Authority bias compounds urgency. An email from a CFO, a call from someone claiming to be from IT, or a message appearing to come from a regulatory body all exploit the deeply ingrained human reflex to defer to hierarchical power.

Attackers now pair this with open-source intelligence (OSINT) gathered from LinkedIn, corporate earnings calls, and social media to impersonate specific executives with precise role-relevant language.

The employee does not see a generic scam. They see their actual manager asking for something that falls within normal workflow.

Fear and curiosity round out the psychological toolkit. Fake termination notices, exposed credential alerts, and "confidential" salary documents each trigger emotional responses that override security training in the moment.

A 2025 analysis published in Computers, Materials & Continua systematically catalogued how phishing emails exploit these biases. Urgency and authority were the two most frequently deployed psychological techniques across thousands of analyzed campaigns.

The researchers noted that even employees who passed simulated phishing tests remained susceptible when real-world emotional stakes were introduced, because simulations rarely replicate the visceral pressure of a genuine attack.

Employees are not negligent. Human cognition evolved for tribal-scale trust decisions rather than for evaluating whether a perfectly formatted email from a familiar name at 4:47 p.m. on a Thursday is actually a ransomware payload.

Training programs that treat every click as a failure of attention miss the point. The attacker's entire craft is designed to make the click feel like the only reasonable choice.

The Attacker's Economics: Why Phishing Offers the Highest ROI

Phishing offers attackers an economic asymmetry that no other ransomware delivery method can match. A modern phishing kit with multi-factor authentication bypass, hosting, templates, and victim tracking rents for approximately $120 for ten days on dark web marketplaces.

More advanced platforms such as EvilProxy run $150 to $600 per month. A campaign launched for a few hundred dollars can reach millions of inboxes at effectively zero marginal cost per additional target.

The return side of the ledger makes the math irresistible. The same phishing campaign that costs an attacker $120 can produce a breach costing the victim organization millions.

If that breach escalates to ransomware, the median ransom payment alone reached $115,000 while total recovery costs averaged $1.53 million. The ratio of attacker cost to victim loss spans four to five orders of magnitude. No other initial access method offers that return profile.

The economics are self-reinforcing. Phishing-as-a-service platforms have commoditized what was once skilled labor, collapsing the barrier to entry.

An operator with no coding ability can subscribe to a kit, upload a target list scraped from OSINT sources, and have a campaign running within an hour. If a domain is burned or a campaign fails, the cost of rotating infrastructure is negligible.

One successful infection that deploys ransomware funds years of additional attempts. This dynamic is why phishing volumes continue to climb year over year, because no market signal tells attackers to stop.

That same economic logic reveals the defender's most viable countermeasure. Attackers depend on a success rate above a certain threshold to stay profitable.

Organizations that measurably reduce click rates through continuous, realistic phishing simulations paired with behavior-specific training attack the one number the attacker's business model cannot survive without. When phishing success rates collapse across a target base, the $120 investment stops looking like free money.

How Phishing Leads to Ransomware: The Kill Chain, Step by Step

The most direct answer to how phishing leads to ransomware is a five-stage kill chain that transforms a single deceptive email into a network-wide encryption event, often within hours.

Attackers research their targets using open-source intelligence (OSINT), then deliver a weaponized payload through a convincing lure. Next they establish command-and-control communications to retrieve the ransomware binary.

From there they move laterally across the network while destroying backups, and finally detonate the encryption routine alongside a ransom demand with deadline pressure. Understanding each stage reveals where defenders can interrupt the chain before the ransom note appears on screen.

Realistic phishing simulations that replicate these attack stages give security teams a controlled way to identify where their defenses break before an actual adversary exploits the same gaps. Teams building a broader program can also review practical steps to prevent ransomware across the full chain.

1. Target Reconnaissance and Bait Selection

Using OSINT, threat actors harvest employee details from LinkedIn profiles, corporate org charts, earnings call transcripts, and social media to map the organization's structure and identify high-value targets. Finance team members receive invoice-themed lures. IT staff see fake password-reset emails. Executive assistants receive messages that appear to come from the CEO.

The reconnaissance phase determines which template the attacker deploys. If the target organization uses Microsoft 365, the phishing page will replicate that authentication portal with pixel-level fidelity. If the target recently announced a merger, the lure will reference the deal.

This personalization is what makes modern phishing nearly indistinguishable from legitimate business communication.

Attackers also profile the organization's email security posture during this stage, checking whether DMARC is enforced, testing whether lookalike domains resolve, and identifying which email gateways are in use.

2. Payload Delivery via Malicious Attachments and Links

The phishing email lands. It might contain a password-protected ZIP file labeled "Q4BonusSummary," a macro-enabled Word document disguised as a vendor invoice, or an embedded link pointing to a credential-harvesting page hosted on a compromised but otherwise legitimate domain. The employee clicks.

What happens next depends on the payload type. Macro-enabled Office documents execute embedded VBA scripts that download a lightweight loader from an attacker-controlled server.

Credential-harvesting redirects capture the employee's username, password, and multi-factor authentication (MFA) token in real time, giving the attacker valid session material to log into the corporate environment directly. HTML attachments render spoofed login pages locally in the browser.

ZIP files unpack executables that Windows sees as legitimate PDFs or spreadsheets because the attacker has manipulated the file extension and icon. In most cases, the employee sees nothing unusual. The document opens, a loading spinner appears briefly, and the screen looks normal.

3. Malware Installation, Loaders, and C2 Communication

Seconds after execution, the loader retrieves the next stage. Loaders such as Qakbot, TrickBot, BazarLoader, and Cobalt Strike beacons are not ransomware themselves. Their job is to establish persistence, profile the compromised endpoint, and phone home for instructions.

A U.S. Department of Justice indictment unsealed in May 2025 confirmed that Qakbot operators provided network access to ransomware affiliates who deployed Prolock, Dopplepaymer, Egregor, REvil, Conti, Black Basta, and Cactus on victim systems.

Command-and-control (C2) communication hides in plain sight. HTTPS traffic blends into the organization's normal web browsing patterns. The loader abuses legitimate Windows tools to evade endpoint detection.

Certutil downloads the ransomware binary from a remote server, and the download appears in logs as a routine certificate operation. Scheduled tasks and registry run keys establish persistence so the loader survives reboots.

For the victim organization, this stage is invisible. There are no alerts, no unusual CPU spikes, and no indicators that anything is wrong.

4. Lateral Movement, Privilege Escalation, and Backup Destruction

The attacker now has a foothold on one machine. That single endpoint becomes the launchpad for domain-wide compromise.

Using credential-dumping tools such as Mimikatz, the attacker extracts cached passwords, Kerberos tickets, and NTLM hashes from the compromised host. Pass-the-hash techniques allow authentication to other systems without ever knowing the cleartext password.

Privilege escalation follows. Attackers scan for unpatched domain controllers and exploit known vulnerabilities. The Zerologon vulnerability (CVE-2020-1472), still present in unpatched environments, grants domain administrator access in a single packet.

Group Policy abuse allows the attacker to push malicious scripts to every machine in the domain simultaneously. Within hours of the initial phishing click, the attacker holds domain admin credentials.

Then comes the methodical destruction of recovery options. Shadow copies are deleted with a single command: vssadmin delete shadows /all /quiet. Windows Server Backup catalogs are purged.

Network-attached storage devices and cloud backup synchronization folders are located and encrypted or wiped. The attacker's goal is absolute. When the ransom note appears, the organization must have no path to recovery that avoids the decryption key.

5. Encryption Execution and Ransom Demand

The encryption routine fires. Files on every accessible system, file share, and connected drive scramble in real time.

Modern ransomware variants use partial encryption for speed. LockBit 3.0, for example, encrypts between 10% and 30% of each file, targeting critical headers and initial data blocks rather than the entire file. That approach dramatically reduces the time to completion, according to a Deep Instinct analysis published in March 2025.

Database servers, domain controllers, and virtual machine hosts are all targeted. File extensions change to a random string.

The ransom note appears on every affected system. It identifies the ransomware group by brand, provides a unique victim ID, and includes step-by-step payment instructions in Bitcoin or Monero. A countdown timer creates pressure: pay within 72 hours or the decryption key is destroyed. Pay within 48 hours or the price doubles.

The note also communicates the extortion strategy beyond encryption. Attackers now routinely exfiltrate sensitive data before detonating the encryption payload.

The demand warns that refusal to pay will result in the public leak of stolen files on a dedicated leak site. That tactic adds regulatory exposure, reputational damage, and potential GDPR fines to the calculus.

Some groups add a third layer, contacting the victim's customers or employees directly to apply pressure from multiple directions.

At this moment, the organization faces a decision with no good options: pay a criminal enterprise and fund future attacks, or refuse and rebuild from nothing. The entire chain, from that first phishing email to the ransom demand, may have taken less than 48 hours.

Common Phishing Lures and Evasion Techniques That Lead to Ransomware

Every explanation of how phishing leads to ransomware eventually returns to the lure itself. Ransomware operators rarely rely on a single tactic to breach an organization.

They layer psychological manipulation with technical evasion methods designed to slip past email filters, sandboxes, and endpoint detection.

The phishing email that delivers a ransomware payload is the product of careful engineering. The right lure reaches the right target through a channel that security tools struggle to inspect, wrapped in techniques that make the payload invisible until it executes.

Understanding these tactics is the first step toward training employees to recognize them before a single encrypted file appears on the network. A broader survey of the types of phishing attacks in circulation gives security teams a useful baseline.

What Psychological Triggers Do the Most Effective Phishing Lures Exploit?

The most effective phishing lures exploit emotional triggers that override rational analysis. Invoice fraud messages arrive with subject lines such as "Past Due Invoice. Immediate Payment Required" and target accounts payable teams during quarter-end, when pressure to close books is highest.

The psychological hook is urgency paired with fear of financial error. The attachment, disguised as a PDF invoice, contains a macro-laced document or an embedded link that launches the ransomware download.

Package delivery notifications exploit curiosity and the fear of missing something important. These lures spike during holiday shopping seasons and mimic branding from FedEx, UPS, and DHL with near-perfect fidelity.

The victim clicks to "track a package" or "reschedule a delivery" and instead triggers a malware download from a compromised but otherwise legitimate-looking site.

Legal summons and tax document lures weaponize institutional authority. A message claiming to be from a court, regulatory agency, or tax authority, often with convincing case numbers, filing deadlines, and official seals, activates compliance instincts so powerfully that recipients bypass normal verification steps.

These lures peak during tax filing seasons and around regulatory deadlines that the target organization publicly discloses.

Executive impersonation, the hallmark of business email compromise (BEC) and whaling attacks, exploits hierarchical deference. An email appearing to come from the CEO or CFO instructs a finance employee to process an urgent wire transfer or review an attached "contract."

Because the request appears to originate from the highest authority in the organization, the victim's training to follow chain-of-command works against them.

When these emails carry ransomware-laced attachments rather than wire instructions, the breach impact can surpass a single fraudulent payment. The result can be encryption of the entire organization.

How Do Attackers Abuse Trusted Platforms Like Google Docs and SharePoint?

Ransomware operators have abandoned the approach of hosting payloads on questionable domains that URL reputation filters flag instantly. Instead, they host malicious files on Google Docs, Dropbox, GitHub, SharePoint, and other trusted productivity platforms whose domains appear on every corporate allow list.

A phishing email containing a link to a Google Drive file or a SharePoint document does not trigger the same suspicion as a link to an unknown domain, because employees interact with these platforms dozens of times each day.

The technique becomes more sophisticated with redirect chains. An attacker sends a link that lands on a legitimate Google Doc containing nothing more than a "Click here to view the secured document" link.

That second link redirects through multiple intermediary pages, sometimes through compromised WordPress sites or abused URL shorteners, before delivering the payload.

Each hop in the chain defeats a different layer of inspection. The initial Google domain passes URL reputation checks, and the intermediary pages evade static link analysis.

By the time a sandbox attempts to follow the full chain, the session has expired or the payload is served only to the specific target's browser fingerprint. This multi-stage delivery architecture is purpose-built to defeat proxy-based and sandbox-based inspection simultaneously.

What Technical Evasion Methods Allow Ransomware Payloads to Go Undetected?

Password-protected ZIP files represent one of the simplest and most effective evasion techniques available to ransomware operators. Encryption renders the archive's contents opaque to signature-based scanners.

Security teams also cannot reasonably block all password-protected attachments without disrupting legitimate business workflows, so these files pass through email gateways uninspected. The attacker supplies the password in the email body, and the victim's act of unzipping the file triggers the infection.

Successor groups to disrupted botnets such as Qakbot, including Pikabot and DarkGate, continue to weaponize encrypted delivery because it remains the most reliable method for landing payloads directly on the endpoint.

Compressed attachments serve a parallel purpose. They evade size-based detection thresholds that flag unusually large files.

By splitting a ransomware payload across multiple compressed archives, or by nesting archives within archives, attackers keep each individual attachment below the scanner's inspection threshold while reassembling the full payload after extraction.

Living-off-the-land techniques take evasion further by removing the need for traditional malware files entirely. Attackers abuse legitimate Microsoft binaries, including Certutil, BITSAdmin, Mshta, and PowerShell, to download and execute ransomware payloads directly in memory.

Certutil, a command-line tool built into Windows for certificate management, can be instructed to fetch a remote file via URL and decode it from Base64, effectively functioning as a stealth download cradle.

No executable file touches the disk, and the activity blends into the background noise of legitimate system administration. That combination defeats both signature-based antivirus and behavioral endpoint detection tuned for unknown binaries.

Browser-in-the-Browser (BitB) attacks add another layer to the ransomware kill chain by harvesting credentials that grant attackers the access needed to manually deploy payloads.

A BitB attack renders a convincing fake browser window, complete with a legitimate-looking URL bar, padlock icon, and login form, entirely within HTML and CSS overlaid on a malicious webpage. The fake window is indistinguishable from a real pop-up to the human eye.

Phishing-as-a-service kits like Sneaky2FA have added BitB functionality that lowers the technical barrier for attackers. Once credentials are harvested, operators gain authenticated access to corporate environments, where they move laterally, escalate privileges, and deploy ransomware without ever needing to trick an employee into opening an attachment.

That access, obtained through a fake window that looked real for three seconds, is what turns a phishing click into a full-scale encryption event.

Spear Phishing, Bulk Campaigns, and the Ransomware Criminal Ecosystem

Not all phishing is equal in the ransomware kill chain. Bulk campaigns and spear phishing occupy distinct roles within a sophisticated criminal supply chain that turns compromised credentials into encrypted networks and ransom demands.

The primary difference is targeting, and that choice shapes how phishing leads to ransomware in any given campaign.

Bulk phishing blasts generic lures to thousands of recipients hoping for a statistical hit. Spear phishing uses meticulous open-source intelligence (OSINT) reconnaissance to craft personalized attacks against specific individuals whose access holds outsized value.

Bulk campaigns prioritize volume, flooding inboxes with credential-harvesting pages that yield a low per-target success rate but reliably produce enough compromised accounts to sell onward.

Spear phishing achieves far higher conversion by weaponizing context, referencing real projects, impersonating known executives, and exploiting established trust relationships that make the target less likely to question the request.

Both methods feed the same ransomware pipeline. The approach an attacker selects depends entirely on whether the goal is quantity of access or quality of entry point.

Phishing to ransomware supply chain: initial access brokers selling network access on a dark web marketplace to RaaS affiliates.

Bulk Phishing vs. Spear Phishing: Different Approaches for Different Targets

Bulk phishing operates on industrial scale. Attackers deploy pre-built phishing kits, commoditized packages sold on dark web forums that contain templated login pages for Microsoft 365, Google Workspace, and other popular services.

These campaigns hit tens of thousands of inboxes with urgent but generic lures: password expiration notices, shared document links, or fake invoice attachments. The per-target conversion rate is low, often under 1%, but the volume guarantees a steady stream of harvested credentials.

Those credentials become inventory, sold to Initial Access Brokers (IABs) or used directly in credential-stuffing attacks against corporate VPNs and remote desktop infrastructure.

Spear phishing inverts this ratio. An attacker may spend days or weeks researching a single finance director or IT administrator before sending one email.

The lure references a real vendor relationship, mirrors internal communication patterns, and often arrives from a domain spoofed to look nearly identical to a trusted partner's.

In the ransomware context, spear phishing is the precision instrument, used when the target organization is worth the effort. A single successful spear-phishing compromise of an administrator account can provide the domain-level access that makes ransomware deployment possible without further lateral movement.

The Role of OSINT in Pre-Attack Reconnaissance

OSINT is the reconnaissance engine that transforms generic phishing into precision strikes. Attackers harvest freely available data from LinkedIn profiles, corporate "About Us" pages, earnings call transcripts, conference speaker videos, and social media activity to build detailed target profiles.

A finance team member who posted about implementing a new ERP system has told attackers which vendor impersonation will feel most credible. An executive whose travel schedule is public provides the perfect timing window for a wire-transfer request.

This reconnaissance directly shapes spear-phishing lures. Instead of a generic prompt to view a shared document, the target sees an email referencing an actual project, from a spoofed address resembling an actual colleague, with urgency tied to a real deadline.

Cisco Talos confirmed in a 2025 analysis that attackers now combine OSINT with adversary-in-the-middle (AiTM) toolkits to bypass multi-factor authentication, making reconnaissance-informed lures even more dangerous.

When the phishing page is a reverse proxy that mirrors the legitimate login experience in real time, the victim has almost no visual cues to detect the fraud.

Initial Access Brokers and the Ransomware-as-a-Service Supply Chain

The ransomware ecosystem has industrialized. IABs are specialized operators who focus exclusively on gaining initial network access, often through phishing, and then sell that access on dark web forums.

An April 2025 analysis by The Hacker News found IAB pricing typically ranges from $500 to $3,000 per access listing, with 58% of deals in 2024 priced under $1,000. This low barrier means organizations of any size can become a target.

IABs feed directly into the Ransomware-as-a-Service (RaaS) model, where ransomware developers license their payloads to affiliates who handle deployment and negotiation.

The IAB eliminates the hardest part of the attack, gaining entry, allowing RaaS affiliates to focus purely on encryption, exfiltration, and extortion. Alongside IABs and RaaS sits the phishing kit economy: pre-built, turnkey phishing pages tailored for specific ransomware delivery chains, sold as commodity products.

MFA bypass tools such as Evilginx are increasingly central to this supply chain. Evilginx functions as a reverse-proxy framework that sits between the victim and the legitimate login page, intercepting both credentials and session tokens in real time.

The victim completes the full authentication flow, including the MFA challenge, and the attacker captures the resulting session cookie. That cookie grants authenticated access without ever needing the user's password again.

This neutralizes multi-factor authentication as a defensive control. Organizations must train employees to recognize the phishing lure itself rather than rely solely on technical barriers.

Phishing simulations that replicate multi-channel, MFA-bypassing attack patterns give security teams the data to close these gaps before the access broker turns a single click into a network-wide intrusion.

The Evolution of Ransomware: From Encryption to Multi-Extortion

Ransomware has transformed from a straightforward encryption-for-bitcoin scheme into a sophisticated extortion ecosystem where stolen data is weaponized against victims, their customers, and their regulators.

A Google Threat Intelligence Group analysis found that confirmed data theft now occurs in 77% of ransomware intrusions, up from 57% the prior year.

Meanwhile, data-theft-only extortion, meaning attacks that skip encryption entirely, grew from roughly 2% of financially motivated incidents in 2020 to more than 15% in 2025. Wider ransomware trends confirm the same trajectory across 2025 and 2026.

The attack chain that enables this evolution has remained remarkably consistent. It almost always begins with a single phishing email, which is the clearest illustration of how phishing leads to ransomware even as the payoff model changes.

Single Extortion: The Original Ransomware Model

Single extortion ransomware follows a simple but devastating formula. An employee opens a phishing attachment or clicks a malicious link, the payload downloads and executes, and within minutes files across the organization are encrypted.

The victim receives a ransom note demanding payment, typically in cryptocurrency, in exchange for the decryption key. Refusal means the data is lost permanently.

This model reached industrial scale through the Necurs botnet, which at its peak was the largest spam botnet in the world and served as the primary distribution engine for the Locky ransomware family.

Organizations that invested in reliable backups could recover from single extortion relatively cleanly. That widespread backup adoption is precisely what forced ransomware groups to adapt.

Double and Triple Extortion: Encryption Plus Data Theft and Third-Party Pressure

Attackers responded to backup defenses by adding a second layer: exfiltrate sensitive data before encrypting it.

Even if the victim restores from backups, the attackers possess a copy of the organization's confidential files and threaten to publish them on leak sites. This double extortion model eliminates the backup defense entirely.

Triple extortion pushes further. Attackers identify customers, business partners, patients, or employees whose personal data was stolen and contact them directly, threatening to expose their information unless the original victim pays.

The Evil Corp group exemplifies this progression. The Russian cybercriminal organization evolved from distributing the Dridex banking trojan via phishing to deploying BitPaymer ransomware, and later WastedLocker, with each iteration adding more sophisticated extortion mechanisms.

LockBit, which became the most deployed ransomware variant globally during its peak, built its ransomware-as-a-service empire on phishing-delivered access combined with double extortion leak sites. Those sites published victim data in real time, creating countdown clocks that maximized psychological pressure on targets.

Infostealer Malware: The Encryption-Free Extortion Alternative

The latest evolutionary branch bypasses encryption altogether. Infostealer malware, designed to harvest credentials, session tokens, browser-stored passwords, and authentication cookies, allows attackers to monetize compromised networks without the operational overhead of deploying encryption payloads.

Once an employee falls for a phishing email and the infostealer executes, attackers gain persistent access to SaaS platforms, cloud environments, and internal systems without triggering the alarm bells that file encryption generates.

This shift has profound implications for phishing defense. Infostealers are harder to detect than ransomware payloads because they operate silently, with no ransom notes, no encrypted file extensions, and no system-wide disruption.

By the time the organization discovers the breach, attackers may have been inside for months, harvesting credentials and monetizing access through dark web sales or direct extortion.

The phishing email that delivers the infostealer looks identical to the one that once delivered Locky. Only the payload has changed, and it has grown far more patient.

Real-World Case Studies: How Phishing Led to Major Ransomware Breaches

In each of the cases below, a single phishing or social engineering moment opened the door to a full ransomware event.

The Locky campaign demonstrated that phishing could deliver ransomware at industrial scale. The Kido Nurseries breach showed how a single compromised system can expose the most sensitive personal data imaginable. The 2025 Marks & Spencer attack proved the pattern holds even when attackers sidestep employees entirely and target the helpdesk itself.

The Locky Campaign and the Necurs Botnet: Phishing at Unprecedented Scale

The Locky ransomware campaign, distributed through the Necurs botnet, remains one of the largest phishing-to-ransomware operations ever recorded.

Cisco Talos researchers documented the botnet drawing from nearly 1.2 million distinct sending IP addresses across more than 200 countries and territories during its peak. On August 28, 2017, researchers at AppRiver recorded 23 million Locky-laced messages in a single 24-hour window, timed to land in American workers' inboxes on Monday morning.

The phishing mechanism was deceptively simple. Emails carried subject lines such as "please print," "documents," and "scans," with a ZIP attachment containing a Visual Basic Script file.

One click triggered the download of the Locky payload, which encrypted all files on the infected machine and displayed a ransom note demanding 0.5 bitcoin.

The Necurs botnet's infrastructure allowed operators to cycle through sender addresses, subject lines, and payload variants faster than email filters could adapt. What made Locky especially destructive was pure volume rather than technical sophistication.

Attackers understood that even a minuscule click-through rate across 23 million messages translated into thousands of paying victims. This campaign transformed phishing from a targeted tactic into an industrial-scale ransomware distribution pipeline.

Kido Nurseries: When Ransomware Exposes Children's Data

In September 2025, the Kido nursery chain disclosed a ransomware attack that exposed the personal data of approximately 8,000 children across its 18 London locations and international sites in the U.S. and India.

The group responsible, calling itself Radiant, published samples of children's profiles on its darknet site and contacted parents directly by phone to pressure the nursery into paying the ransom.

Once inside, the attackers exfiltrated years of sensitive child and family records before encrypting systems.

Jonathon Ellison of the UK's National Cyber Security Centre described the breach as "deeply distressing," adding that "cyber criminals will target anyone if they think there is money to be made, and going after those who look after children is a particularly egregious act."

The compromised data included names, photographs, home addresses, dates of birth, and safeguarding notes.

The Kido case exposed a hard truth. Organizations handling sensitive data carry a disproportionate burden when ransomware hits, and a single breach placed affected families into an extortion cycle that continues long after the encryption key is paid or refused.

M&S and Scattered Spider: Social Engineering the IT Helpdesk

The April 2025 ransomware attack on Marks & Spencer rewrote what a phishing-to-ransomware attack looks like. Rather than targeting a typical employee, the Scattered Spider group impersonated an M&S staff member and called a third-party IT helpdesk, convincing support personnel to reset account credentials.

That single social engineering call handed attackers the initial foothold. They escalated it into full network access, data exfiltration, and deployment of ransomware that scrambled M&S servers and forced the retailer to suspend online orders for weeks.

The financial impact was staggering: M&S projected a £300 million hit to operating profit for the 2025/26 fiscal year, roughly a third of its annual profit, from lost sales, recovery costs, and operational disruption.

The National Crime Agency confirmed Scattered Spider as a focus of its investigation, noting the group's hallmark tactic of targeting IT service desks with fluent, native-English social engineering.

The M&S breach proves that phishing is no longer confined to email. When attackers target the very people paid to grant access, the blast radius can erase hundreds of millions in market value from a single well-placed phone call.

The lesson for security leaders is direct. Every inbound communication channel that can grant system access is now a vector that must be defended with realistic, multi-channel simulation training.

Technical Defenses That Disrupt the Phishing-to-Ransomware Kill Chain

Breaking the chain requires understanding how phishing leads to ransomware stage by stage, then mapping a technical control to each stage.

The first step is hardening email authentication with DMARC, SPF, and DKIM at enforced rejection levels to stop spoofed messages before they reach inboxes.

The second is locking down endpoints with macro blocking, application control, and zero-trust architecture to contain any threat that slips through.

The third is building an immutable, air-gapped backup architecture as the final backstop, paired with a rehearsed ransomware incident response playbook. Together they make recovery swift and the ransom demand irrelevant when a phishing email succeeds despite every upstream defense.

Stopping phishing before ransomware: security team monitoring email authentication and endpoint controls in a security operations center.

1. Email Authentication, DMARC, SPF, and DKIM to Stop Phishing at the Inbox

Every phishing-to-ransomware attack begins with a message that reaches a human being. Intercepting that message at the inbox is the single highest-leverage defense available.

It starts with three protocols: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance).

SPF verifies that the sending server is authorized to send on behalf of the domain. DKIM attaches a cryptographic signature that confirms the message was not altered in transit.

DMARC ties them together by telling receiving mail servers what to do when authentication fails, and by providing visibility through aggregate reports.

The critical distinction is between DMARC monitoring and DMARC enforcement. A policy of p=none generates reports but allows spoofed messages to sail through untouched. Only p=quarantine or p=reject actually blocks them.

When Google and Yahoo tightened sender requirements in early 2024 for bulk senders, Gmail alone saw a 65% reduction in unauthenticated messages reaching user inboxes. Adoption without enforcement leaves the door open.

Beyond authentication, advanced email security layers detect threats that native Google Workspace and Microsoft 365 filtering miss. These include API-based tools that scan for QR code phishing, AI-generated spear phishing with zero-day lure patterns, and credential-harvesting pages.

All are attack vectors that pass SPF and DKIM checks because they originate from legitimate, compromised accounts rather than spoofed domains. Deploying this defense at the delivery stage neutralizes the kill chain before any employee sees a malicious message. Further guidance on how to prevent phishing attacks covers the full control set.

2. Endpoint and Network Controls, GPO Macro Blocking, Application Control, and Zero-Trust Architecture

When a phishing email breaches the inbox, and some always will, the kill chain moves to execution. The user clicks, the attachment opens, and the ransomware payload attempts to run. This is where endpoint controls either contain the threat or allow it to propagate.

The first and most neglected control is blocking macros in Office documents that originate from the internet. A Group Policy Object (GPO) configured to "Block macros from running in Office files from the Internet" eliminates the most common initial execution vector for ransomware.

This single GPO setting, universally applied with no per-user exceptions, addresses the execution stage of the kill chain directly. It is free, built into every Windows domain, and yet absent from a staggering number of environments.

Application control policies take containment further by preventing unauthorized executables from launching at all. Windows Defender Application Control (WDAC) or AppLocker can restrict execution to known, signed binaries, blocking the dropped executable or script that a macro would otherwise unleash.

Equally important is disabling LOLBins, the living-off-the-land binaries such as Certutil, Mshta, and Regsvr32 that attackers abuse to download payloads and bypass allowlisting.

Certutil, for example, is a legitimate certificate management tool that ransomware operators routinely weaponize to fetch encrypted payloads from remote servers. Disabling it via GPO, or removing it from systems where it is not operationally necessary, shuts down one of the most abused delivery channels in the ransomware playbook.

Zero-trust architecture then addresses what happens if execution succeeds: lateral movement. By eliminating implicit trust between network segments, zero trust ensures that compromising one endpoint does not grant access to every other system on a flat network.

Microsegmentation isolates critical assets from general user workstations, disrupting the kill chain at the propagation stage. Identity-based access policies require re-authentication at every boundary, so stolen credentials from a phished workstation cannot unlock adjacent segments.

The principle maps cleanly to kill chain stages. "Never trust, always verify" neutralizes credential theft by making stolen credentials insufficient for movement.

Least-privilege access prevents the domain-wide escalation that turns a single phishing click into an organization-wide encryption event.

3. Backup Strategy and Incident Response: The Last Line of Defense

No technical stack catches every phishing email. When an attack reaches the encryption stage, the only question that matters is whether the data is recoverable.

The 3-2-1 backup rule provides the framework: three copies of every critical dataset, stored on two different media types, with one copy offsite.

The rule alone is insufficient against modern ransomware, which actively hunts for backup files, deletes Volume Shadow Copies, and encrypts connected repositories. An Enterprise Strategy Group study of 200 IT executives found that 96% of organizations reported their backup data was specifically targeted during ransomware attacks.

This is why immutability is the defining requirement. Immutable backups, stored using write-once-read-many (WORM) technology or object-lock features available in cloud storage platforms, cannot be encrypted, altered, or deleted by ransomware, even if the attacker holds domain administrator credentials.

Combined with air-gapped or offline copies that have no persistent network connection, immutability ensures the attacker cannot reach the last copy of the data no matter how completely the production environment is compromised.

The same ESG research found that 81% of respondents identified immutable backup storage as the last line of defense in any ransomware strategy.

The incident response playbook activates when phishing succeeds despite all upstream controls. The first step is to isolate affected systems immediately by disconnecting them from the network.

Affected systems should not be shut down, because volatile memory and forensic artifacts may be lost. Disk images, memory dumps, and firewall logs should be preserved before any remediation action overwrites them.

The cyber insurance carrier should be notified, and external incident response counsel engaged if the scope is uncertain.

On the question of ransom payment, the decision framework should be established before an incident occurs. It should define in advance which scenarios warrant negotiation, which regulator notifications are mandatory, and who holds decision authority.

Organizations with a rehearsed playbook restore operations in hours. Every hour of preparation on the backup and response front pays for itself the moment a phishing email clears the other two defensive layers.

Security Awareness Training: The Human Layer Defense Against Phishing

Anyone tracing how phishing leads to ransomware arrives eventually at the same place: an employee inbox. Security awareness training remains one of the most debated line items in the cybersecurity budget, but the data is unambiguous.

Phishing is the primary delivery mechanism for ransomware, and no technical control stops every phish before it reaches an employee. No email gateway and no endpoint detection system closes that gap completely.

Security awareness training is the last active defense layer. When done well, it transforms employees from targets into sensors who recognize and report threats before they become incidents.

The real question is whether the training program in place actually changes behavior or merely satisfies an audit requirement. Evidence on the role of security awareness in preventing ransomware points to program design as the deciding factor.

Why Legacy Training Falls Short

Legacy security awareness programs center on annual compliance modules: a one-hour video, a multiple-choice quiz, a certificate for the HR file. Employees click through them the way they click through terms-of-service agreements. Completion rates are reported to the board. Actual phishing resilience does not improve.

Meanwhile, an academic study of nearly 20,000 employees at UC San Diego Health published in 2025 found little evidence that annual training alone decreased phishing simulation failures.The researchers observed that training effects decayed rapidly. What stuck was the context in which the lesson was learned rather than the content of the module.

The gap between knowing a phish exists and recognizing one under time pressure, on a mobile device, at the end of a long workday is where legacy programs collapse.

Phishing Simulations as Behavioral Measurement and Intervention Tools

A phishing simulation that only measures click rates is a test. A simulation that changes behavior is a training intervention, and the difference lies in what happens the moment after an employee fails.

Real-time teachable moments, where a short, context-specific microlearning module triggers immediately upon a simulated click, anchor the lesson to an emotional and cognitive experience.

The employee just made a mistake and knows it. That vulnerability creates a learning window that a generic annual module cannot replicate.

Frequency matters equally. Monthly simulations for the general employee population, with more frequent cadences for high-risk roles such as finance and IT, keep detection instincts sharp. Quarterly or annual simulations allow the skill to decay between exposures.

Role-specific simulation design further amplifies the training effect. A payroll specialist faces vendor impersonation and invoice fraud. An executive faces whaling and deepfake vishing.

A new hire in customer support faces credential harvesting disguised as IT onboarding. When the simulation mirrors the threat the employee is most likely to encounter, the lesson transfers directly to real-world behavior.

Generic phishing templates produce generic results. Published security awareness training best practices point to the same conclusion.

From Compliance Checkbox to Behavioral Change

Email is where phishing began, but it is no longer where phishing ends. Modern ransomware campaigns use multi-channel attack chains: a smishing text with a malicious link, followed by a vishing call from an AI-cloned executive voice, capped with a deepfake video on a Teams call.

Training employees exclusively on email phishing leaves them blind to the vectors attackers now use routinely.

The $25 million Arup wire fraud executed through a deepfake CFO video call proved these attacks work against sophisticated multinational firms. An employee trained only to inspect email headers and hover over links has no frame of reference for recognizing a synthetic voice impersonating a CFO on a phone call.

Multi-channel phishing simulations across email, voice, SMS, and deepfake video build detection instincts across the full attack surface that ransomware operators exploit. Guidance on deepfake social engineering covers the detection cues that transfer to live calls.

What separates an effective awareness program from a compliance checkbox is behavioral architecture rather than content volume.

Effective programs measure outcomes such as simulation click rates, reporting rates, and remediation speed, treating completions as a secondary signal.

They deliver training in context, meaning role-specific, channel-specific, and triggered at the moment of maximum receptivity. They test employees against the actual attack vectors used in current ransomware campaigns rather than the threats of a decade ago.

They also operate continuously, because threat actors do not wait for the annual training refresh to launch their next campaign. Organizations ready to move beyond the compliance model should evaluate security awareness training platforms that unify simulation, training, and risk measurement into a single behavioral change engine.

Regulatory, Insurance, and Human Consequences of Phishing-Led Ransomware

The consequences of how phishing leads to ransomware extend far beyond encrypted files and ransom payments.

Organizations face mandatory breach reporting under multiple regulatory frameworks. Insurers scrutinize whether basic human-layer defenses were in place before deciding to pay a claim, and the employees who clicked carry a psychological burden that can outlast the technical recovery by months.

A 2025 Object First survey of 500 IT and security professionals found that 84% report feeling uncomfortably stressed at work due to security risks, and 78% fear being personally blamed for incidents.

The human cost of phishing-led ransomware is a core business continuity concern rather than a side effect.

Regulatory Fallout: GDPR, HIPAA, and CIRCIA Reporting Requirements

A phishing-based ransomware breach triggers the same reporting obligations as any other attack vector, and the clock starts the moment an organization reasonably believes a covered incident has occurred.

Under GDPR, organizations processing EU personal data must notify the relevant data protection authority within 72 hours of becoming aware of a breach involving personal data.

They must also communicate directly with affected data subjects when the breach poses a high risk to their rights and freedoms. Failure to meet that deadline carries fines of up to 4% of annual global turnover.

HIPAA's Breach Notification Rule imposes parallel obligations on covered entities and business associates in the U.S. healthcare sector.

Breaches affecting 500 or more individuals require simultaneous notification to the Department of Health and Human Services' Office for Civil Rights (OCR), affected individuals, and prominent media outlets. The OCR can investigate and levy civil monetary penalties reaching millions of dollars depending on the level of negligence.

For critical infrastructure operators, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) introduces the most aggressive federal timeline yet.

Covered entities across 16 sectors must report substantial cyber incidents to CISA within 72 hours and disclose ransomware payments within 24 hours of disbursement. The proposed rule captures more than 300,000 entities, and liability for non-compliance includes referral to the Department of Justice.

A phishing email that exfiltrates personal data and leads to ransomware triggers all of these frameworks simultaneously. The reporting obligations begin long before the forensics are complete.

Cyber Insurance: Changing Requirements and Rising Premiums After Phishing-Based Breaches

Cyber insurers have moved decisively from passive underwriting to active gatekeeping. Carriers now routinely mandate phishing-resistant multi-factor authentication, documented security awareness training programs, regular phishing simulations, and DMARC enforcement as minimum conditions of coverage.

Organizations that cannot produce evidence of these controls face premium increases, sub-limits on ransomware coverage, or outright denial at renewal.

Phishing remains the most common initial access vector for ransomware, and insurers are no longer willing to absorb the cost of breaches that basic human-layer defenses could have intercepted.

A growing number of applications now require attestation to quarterly phishing simulation cadences and specific training completion rates. Security teams that treat these as checkbox exercises rather than evidence-generating programs risk finding their organizations uninsurable.

Comprehensive security awareness training and documented simulation history have become as essential to insurability as firewalls and endpoint detection.

The Psychological Toll on Employees and Security Teams

The employee who clicked the phishing link often carries guilt, shame, and fear of career consequences long after the incident is technically contained. Within security teams, the toll is more severe.

"We've worked with organizations where workers have recurrent nightmares even eighteen months after a breach," said Peter Coroneos, founder of Cybermindz, a nonprofit focused on cybersecurity professional mental health, in a 2025 CSO Online report.

Nearly half of IT professionals (47%) in the Object First survey reported feeling pressure from leadership to "fix everything" in the aftermath of an incident, and 59% had considered or begun looking for new jobs due to work-related stress.

Mission-driven security professionals experience these breaches as personal failures, even when the root cause sits with a single employee operating without adequate training.

The resulting burnout and attrition hollow out precisely the teams organizations need to rebuild their security posture. Coroneos noted that after major breaches, resignations follow because professionals "never want to encounter a situation like that again."

Organizations that ignore the human aftermath of phishing-led ransomware create a talent retention crisis that leaves them more vulnerable to the next attack.

How Phishing Defense Connects to Modern Human Risk Management

Any serious answer to how phishing leads to ransomware ends at employee behavior rather than at a single email. Phishing defense treated as a standalone training exercise fails, because the human behaviors attackers exploit do not respect channel boundaries.

An employee who clicks a phishing link in email is often the same person who trusts an AI-cloned voice on a phone call or pastes sensitive data into an unauthorized AI tool.

Human risk management addresses this by creating a unified measurement framework that tracks behavioral risk across every channel where employees interact with threats. That framework produces actionable data that training completion rates alone can never surface.

Beyond Training Completion Rates: Measuring Real Behavioral Change Through Risk Scoring

Most organizations still measure security awareness in terms of training completion percentages, and that metric is practically meaningless. An employee can complete every assigned module and still click a malicious link the same afternoon.

What signals real behavioral change is how individuals perform under actual threat conditions: phishing simulation click rates and reporting velocity when suspicious emails arrive.

It also includes whether employees pause before acting on urgent requests delivered through voice or video channels.

Human risk scoring aggregates these disparate signals into a single, comparable metric. When an employee fails a vishing simulation, that event registers alongside their email phishing performance, credential exposure from public data breaches, and training engagement patterns.

The result is a dynamic score that reflects real-world susceptibility rather than a pass-fail grade. Practical models for human risk scoring weight each signal differently.

The IBM 2025 Cost of a Data Breach Report identified phishing as the most common initial attack vector, present in 16% of breaches at an average cost of $4.8 million.

Employee training ranked among the most effective cost mitigators in that same report, helping organizations reduce breach containment time. Risk scoring turns phishing defense from an annual event into a continuous improvement cycle.

Multi-Channel Risk Visibility: Email, Voice, SMS, and AI Tools as a Unified Surface

Attackers have expanded beyond email, and phishing defense must follow. The same threat actor who sends a spear-phishing email can follow up with a vishing call using a cloned executive voice, then reinforce the scam with a smishing text directing the target to a credential-harvesting page.

Each channel is a distinct attack surface, but the target is the same employee, and each successful manipulation across any channel feeds the same ransomware deployment sequence.

The 2026 Verizon Data Breach Investigations Report confirmed that the human element was present in 62% of breaches across all vectors rather than email alone.

Treating email phishing, voice scams, SMS-based attacks, and risky AI tool usage as separate problems creates dangerous blind spots. An employee who never clicks email phishing links but routinely shares proprietary data with public AI models represents a measurable human risk that email-only metrics cannot detect.

Unified visibility means scoring every channel together, so that a spike in smishing susceptibility triggers the same risk response as a spike in email click rates.

The Data Layer CISOs Need: From Phishing Clicks to Board-Ready Risk Metrics

CISOs face a persistent translation problem. Boards ask about risk, and security teams respond with training completion rates and phishing click percentages. Those numbers describe activity rather than exposure.

Human risk management provides the missing data layer that converts operational phishing defense signals into business outcomes leadership can act on.

Risk scores aggregated by department, role, and individual create trend lines that show whether the organization's human-layer defenses are improving or deteriorating over time.

When the finance team's aggregate risk score drops after a targeted BEC simulation campaign, the CISO can report actual risk reduction rather than training throughput.

Benchmark comparisons against industry peers answer the question boards actually care about, which is how exposed the organization is relative to others. These metrics translate phishing defense investment into the language of enterprise risk, the same language used to evaluate every other business function.

The phishing-to-ransomware pipeline depends on human decisions at every stage, and the only way to manage that dependency is continuous measurement rather than annual review.

Phishing-to-Ransomware FAQs

Can multi-factor authentication (MFA) stop phishing-based ransomware attacks?

Multi-factor authentication (MFA) significantly reduces credential-based compromise risk but cannot fully stop phishing-based ransomware attacks. Modern phishing toolkits such as Evilginx use adversary-in-the-middle reverse-proxy techniques to intercept both passwords and session tokens in real time, bypassing MFA protections entirely.

Cisco Talos documented this in a 2025 analysis, noting that phishing-as-a-service platforms now make MFA bypass accessible to attackers at every skill level. Once session tokens are captured, attackers gain authenticated access without ever triggering an MFA prompt.

Organizations should deploy phishing-resistant MFA (FIDO2/WebAuthn) alongside security awareness training that teaches employees to recognize credential-harvesting pages. MFA is an essential defense layer rather than a standalone solution against determined adversaries.

What is the difference between phishing and ransomware?

Phishing is a social engineering attack that uses deceptive communications to trick individuals into revealing credentials, downloading malware, or transferring funds. Ransomware is a type of malicious software that encrypts files or systems and demands payment for their release.

The critical distinction is that phishing is the delivery mechanism and ransomware is the payload.

In a typical attack chain, a phishing email delivers a malicious link or attachment. When the recipient clicks, a loader such as QakBot or TrickBot retrieves the ransomware payload, which then encrypts files across the network.

An organization can experience phishing without ransomware, but ransomware operators depend on phishing because it provides the most reliable path past perimeter defenses.

Defending against phishing requires behavioral training and email filtering. Defending against ransomware requires endpoint controls, backup strategy, and incident response planning.

How long does it take for ransomware to deploy after a successful phishing click?

Ransomware can deploy within hours of a successful phishing click. More than half of all ransomware deployments now occur within a single day of initial access, and in some cases attackers using automated tooling trigger encryption within five hours.

This compressed timeline leaves security teams an extremely narrow window between detecting the phishing compromise and preventing encryption. Organizations must test incident response plans against sub-24-hour ransomware scenarios and prioritize detection speed over perimeter-only prevention.

How much does a phishing-based ransomware attack cost an organization on average?

The average cost of a ransomware attack reached $5.13 million in 2024, encompassing ransom payments, recovery costs, downtime, reputational damage, and regulatory penalties.

Beyond direct financial impact, phishing-led ransomware breaches trigger regulatory fines under GDPR and HIPAA, cyber insurance premium increases, and long-term erosion of customer trust. Achieving full operational recovery takes more than 100 days on average, making proactive phishing defense the most cost-effective strategy an organization can adopt.

See How Adaptive Reduces Phishing Risk Across the Organization

Phishing attacks that lead to ransomware are accelerating. Dwell times now measure in hours rather than weeks, and recovery costs routinely exceed a million dollars.

Adaptive Security's AI-powered platform transforms employees from a targeted vulnerability into a trained human defense layer through continuous, multi-channel security awareness training and phishing simulations that mirror real-world attack patterns.

Take a self-guided tour to see how Adaptive builds behavioral resilience against phishing across email, voice, SMS, and deepfake channels.

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Get started

Human security for the AI era.