Ransomware is malicious software that encrypts your files and demands payment, typically in cryptocurrency, for a decryption key. More advanced variants also steal a copy of your data before encrypting it and threaten to publish it publicly for extra leverage, a tactic known as "double extortion." For an individual user, the practical result is the same either way: sudden loss of access to personal files, accompanied by a ransom note.

How It Typically Reaches Individual Users

  • Phishing emails with malicious attachments, where opening a document and enabling macros downloads and runs the actual payload
  • Malicious or pirated downloads, since cracked software and unofficial "free" versions of paid tools bypass official update and review mechanisms
  • Exploited software vulnerabilities, where outdated, unpatched software can be exploited with no action needed from the user beyond simply being connected to the internet
  • Compromised remote access, where weak or reused passwords on remote desktop tools give attackers a direct path in

What Happens Once It Runs

Modern ransomware moves fast — encryption of a typical personal computer's files can finish in minutes. Affected files usually get a new extension, and a ransom note appears, often as a desktop wallpaper change or a text file dropped in every affected folder, with payment instructions and a deadline that frequently escalates the price if you delay.

Should You Pay?

Law enforcement agencies generally advise against it: payment doesn't guarantee a working decryption key, it funds further criminal activity, and it doesn't undo any data already stolen. That said, this is ultimately a personal decision shaped by what was lost and what alternatives exist — not one to make hastily under pressure. A professional incident-response resource, or reporting to a national cybersecurity authority, is generally a better first step than deciding in isolation.

The Single Most Effective Defense: Backups

Since ransomware fundamentally attacks your access to your own files, having a copy it can't reach is the most direct countermeasure. The commonly cited "3-2-1" approach:

  • 3 total copies of important data (the original plus two backups)
  • 2 different storage media or locations
  • 1 copy kept offline or disconnected, since ransomware can also encrypt continuously connected backup drives

Cloud backup services with file versioning are especially useful here, letting you restore a prior, unencrypted version of a file even if a synced copy gets hit.

A realistic ransomware risk-reduction checklist

  • Keep automatic backups running, including at least one not continuously connected to your main device
  • Keep your OS and applications updated, since many campaigns rely on already-patched vulnerabilities
  • Enable Controlled Folder Access on Windows, or an equivalent feature if your security software offers one
  • Be cautious with email attachments and macro-enabled documents from unfamiliar senders
  • Avoid pirated software and unofficial app sources
  • Use unique, strong passwords and multi-factor authentication on any remote access tools

If You're Already Infected

  1. Disconnect the device from the network immediately to prevent spread to other connected devices or shared drives
  2. Don't pay immediately or panic-decide — take time to assess what backups are available
  3. Check for a free decryptor. The No More Ransom initiative, a collaboration between law enforcement and security vendors, maintains a free public library of decryption tools for known ransomware families
  4. Report the incident to your national cybersecurity authority and, where applicable, local law enforcement
  5. Restore from a clean backup only after the infected device has been fully wiped and reinstalled, not simply cleaned in place, since some ransomware leaves other malware behind

Frequently Asked Questions

Is it ever safe to pay a ransomware demand?

Law enforcement generally advises against it, since payment doesn't guarantee recovery and can fund further criminal activity. This is a serious decision best made with input from a professional incident-response resource rather than under time pressure.

Can ransomware infect backup drives too?

Yes, if the drive stays continuously connected while the ransomware runs. This is exactly why keeping at least one backup offline or disconnected is a core part of a resilient backup strategy.

Are free ransomware decryption tools legitimate?

Yes, for specific known ransomware families where researchers have found a flaw in the encryption implementation. The No More Ransom project maintains a free public library of such tools, though a decryptor generally only exists for particular variants, not all of them.

mygurd Editorial Team

Our editorial team writes explanatory technology and security guides for general readers, independent of any software vendor.