Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases?
It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast radius of their own systems.