Ransomware is malicious software that encrypts your files and demands payment — usually in cryptocurrency — for a decryption key. In more advanced cases, attackers also steal a copy of your data before encrypting it, then threaten to publish it publicly as additional leverage, a tactic often called "double extortion." For an individual user, the result is the same either way: sudden, complete loss of access to personal files, photos, and documents, accompanied by a ransom note.
How Ransomware Typically Reaches Individual Users
- Phishing emails with malicious attachments — a document or archive that, once opened and its macros enabled, downloads and runs the actual ransomware payload.
- Malicious or compromised downloads — pirated software, cracked game installers, and "free" versions of paid tools are common delivery vehicles, since they bypass official app stores and update mechanisms.
- Exploited software vulnerabilities — outdated software with known, unpatched security flaws can be exploited without any action from the user beyond simply being connected to the internet.
- Compromised remote access — weak or reused passwords on remote desktop or file-sharing services give attackers a direct way in, particularly relevant for small businesses and users who enable remote access for convenience.
What Happens Once It Runs
Modern ransomware works fast — encryption of a typical personal computer's files can complete in minutes. Once encryption finishes, affected files usually get a new file extension, and a ransom note appears (often as a desktop wallpaper change or a text file dropped in every affected folder) with payment instructions and a deadline, frequently with an escalating price if you don't pay quickly.
Should You Pay the Ransom?
Law enforcement agencies, including the FBI and the UK's National Cyber Security Centre, generally advise against paying. The core reasons: payment doesn't guarantee you'll actually receive a working decryption key, it funds and incentivizes further criminal activity, and it doesn't remove any data the attacker may have already stolen. That said, this is ultimately a personal decision that depends on what was lost and whether any alternative recovery path exists — it isn't a decision to make quickly under pressure. Consider consulting a professional incident-response resource or reporting the incident to a national cybersecurity authority (such as CISA in the US) rather than deciding in isolation.
The Single Most Effective Defense: Backups
Because ransomware fundamentally attacks your access to your own files, the most direct countermeasure is having a copy of those files somewhere ransomware can't reach. The commonly cited "3-2-1" backup approach:
- 3 copies of important data total (the original plus two backups)
- 2 different storage media or locations (for example, an external drive and a cloud service)
- 1 copy kept offline or otherwise disconnected, since ransomware can also encrypt backup drives that stay continuously connected to an infected computer
Cloud backup services with file versioning are particularly valuable here, since they let you restore a previous, unencrypted version of a file even if a synced copy gets encrypted.
Additional Practical Defenses
A realistic ransomware risk-reduction checklist
- Keep automatic backups running, including at least one that isn't continuously connected to your main device
- Keep your operating system and applications updated, since many ransomware campaigns rely on known, already-patched vulnerabilities
- Enable Controlled Folder Access on Windows or an equivalent ransomware-specific protection feature if your security software offers one
- Be cautious with email attachments and macro-enabled documents from unfamiliar senders
- Avoid pirated software and unofficial app sources
- Use unique, strong passwords and multi-factor authentication on any remote access tools
If You're Already Infected
- Disconnect the device from the network immediately (Wi-Fi and any wired connection) to prevent the ransomware from spreading to other connected devices or shared drives.
- Do not pay immediately or panic-decide. Take time to assess what backups are available.
- Check whether a free decryptor exists. Projects like the No More Ransom initiative (a collaboration between law enforcement and security vendors) maintain a free, publicly available library of decryption tools for known ransomware families.
- Report the incident to your national cybersecurity authority and, if applicable, local law enforcement.
- Restore from a clean backup after the infected device has been fully wiped and reinstalled, not simply cleaned in place, since some ransomware leaves other malware behind.
Frequently Asked Questions
Is it ever safe to pay a ransomware demand?
Law enforcement generally advises against paying, since it doesn't guarantee file recovery and can fund further criminal activity. This is a serious decision best made with input from a professional incident-response resource rather than under time pressure.
Can ransomware infect backup drives too?
Yes, if the backup drive stays continuously connected while the ransomware runs. This is exactly why keeping at least one backup offline or disconnected is a core part of a resilient backup strategy.
Are free decryption tools for ransomware legitimate?
Yes, for specific known ransomware families where security researchers have found a flaw in the encryption implementation. The No More Ransom project, run in partnership with law enforcement and security vendors, maintains a free public library of such tools — but a decryptor generally only exists for particular ransomware variants, not all of them.