Threat Guide
Ransomware
What is Ransomware?
Ransomware is malicious software that encrypts your files and demands payment (usually in cryptocurrency) for the decryption key. It can affect individuals, businesses, hospitals, and even critical infrastructure. Paying the ransom doesn't guarantee you'll get your files back, and it funds criminal operations.
How Ransomware Attacks Work
Ransomware typically enters through phishing emails, malicious downloads, or exploiting vulnerabilities
Once executed, it silently scans your system for valuable files (documents, photos, databases)
The malware encrypts these files using strong encryption that's virtually impossible to break
A ransom note appears demanding payment (often $500-$50,000+ for individuals, millions for businesses)
Attackers may threaten to delete files or publish sensitive data if you don't pay
Some ransomware spreads across networks, encrypting connected devices and servers
Warning Signs
- Files have strange extensions added (.encrypted, .locked, .crypto)
- Files won't open and appear corrupted
- A ransom note appears on your screen or in folders
- Your computer is unusually slow (encryption in progress)
- Security software is disabled
- Desktop wallpaper changed to ransom message
- Network drives are inaccessible
How to Protect Yourself
- Keep regular, offline backups of important data (follow the 3-2-1 rule: 3 copies, 2 different media, 1 offsite)
- Keep all software and operating systems updated with security patches
- Use reputable antivirus/anti-malware software
- Be extremely cautious with email attachments and links
- Disable macros in Microsoft Office documents from unknown sources
- Use a VPN on public Wi-Fi to prevent initial infection vectors
- Implement least-privilege access in organizations
- Train employees to recognize phishing attempts
How a VPN Helps Protect You
A VPN helps prevent ransomware by encrypting your connection on public Wi-Fi, where malicious downloads can occur. It blocks your ISP from injecting ads that might contain malware. Some VPN providers include malware blocking that can prevent connections to known ransomware distribution sites.
Frequently Asked Questions
Should I pay the ransomware demand?
Security experts and law enforcement generally advise against paying. Only about 65% of paying victims recover their data. Payment encourages more attacks and funds criminal operations. Instead, restore from backups if possible, or consult with cybersecurity professionals.
Can ransomware be removed without paying?
Sometimes. If you have clean backups, you can restore after removing the malware. Some ransomware has been cracked—check nomoreransom.org for free decryption tools. However, modern ransomware uses strong encryption that can't be broken. Prevention and backups are your best defense.
Can ransomware spread to cloud storage?
Yes, if your cloud storage syncs automatically with infected files. However, most cloud services keep file versions, so you may be able to restore previous, unencrypted versions. Disconnect syncing immediately if you suspect infection.
Learn About Other Threats
Understand the full landscape of cyber threats to protect yourself online.