Ransomware is malicious software that encrypts your files and then demands payment for the key that unlocks them. It is one of the most damaging attacks a person or a business can face, because it doesn't just take a copy of your data: it takes the data away from you.
What ransomware does
Most malware tries to stay hidden for as long as it can, quietly stealing passwords or spying on you. Ransomware wants to be noticed. Once it runs, it works through your documents, photos, source code and databases, encrypting each one. When it is finished, it leaves a ransom note, usually a text file in every folder or a message on the desktop, saying the files are locked and explaining how to pay.
The files are still on your disk. They keep their names, sometimes with a new extension added, but their contents are scrambled. Open one and you get an error or gibberish. That is what makes ransomware feel so personal: the attacker hasn't carried your things off, they have put them behind glass, where you can see them but not use them.
Why encryption makes it hard to undo
Encryption is the same tool that protects your bank login and your messages. It turns readable data into scrambled data using a key, and only the right key turns it back. Good encryption is designed so that guessing the key would take longer than anyone could wait, and ransomware uses exactly that kind of encryption against you.
A typical design works in two layers:
- The ransomware creates a fast symmetric key and encrypts your files with it.
- It then encrypts that key with the attacker's public key, so only the matching private key can unlock it. That private key never touches your machine.
So nothing left on your computer can undo the damage. Without the attacker's key, getting the files back means restoring them from a copy kept somewhere else, or hoping this ransomware has a flaw. Some do: security researchers and police have released free decryptors for strains with weak encryption or seized keys. They are worth checking, but they are the exception, not a plan.
How it gets in
Ransomware is a payload: something else has to deliver it. The common routes are:
- Phishing emails. A link to a fake login page or a download, or an attachment dressed up as an invoice or a zipped document. One click runs the program.
- Unpatched software. Attackers scan the internet for systems with known vulnerabilities, such as an out-of-date VPN or web server, and break in without anyone clicking anything.
- Exposed remote access. Remote Desktop and similar services left open to the internet, protected by weak or reused passwords.
- Malicious downloads. Cracked software, fake updates and poisoned dependencies (the theme of Malicious Packages) can all carry it.
Each of these is part of your attack surface: every door you leave open is another chance for an attacker.
Against a business, the program that arrives first often isn't the ransomware itself. Attackers may spend days moving quietly between machines, gaining admin rights and looking for the backups, before they encrypt everything at once. That is why backups that any compromised machine can reach are so exposed.
Many attacks steal first, too
Locking files is the main act, but many ransomware groups also copy data out before encrypting it, then threaten to publish it if you don't pay. This is often called double extortion. It changes the maths: a good backup gets your files back, but it can't un-leak your customers' records. It is one more reason the defences have to start before the attack.
Why paying is a gamble
The note promises the key in exchange for payment, usually in cryptocurrency. Nothing stands behind that promise.
- The attackers may take the money and vanish.
- The decryptor they send may be slow or buggy, or fail on some files, so you lose data anyway.
- Paying marks you as someone who pays, and you may be targeted again.
- Stolen data may be leaked or sold regardless.
- The money funds the next attack.
Government security agencies, including the UK's NCSC and the US's CISA, advise against paying. Businesses can also face legal questions about paying criminals, so the choice is rarely as simple as the note makes it look. The reliable way out is to never need the key.
A worked example: sync is not backup
Picture a small design studio. Its work lives on each laptop, in a folder that syncs to a shared cloud drive. Every evening, someone copies everything to an external drive and then unplugs it.
One morning, a designer opens an email attachment that claims to be an overdue invoice. Hidden inside is ransomware, which encrypts every file in the synced folder. The sync client does exactly what it was built to do: it sees that the files have changed and uploads the new, encrypted versions over the good ones. Within minutes the cloud copy is scrambled too, and so is every other laptop that syncs the same folder.
The external drive is the only copy the ransomware never saw, because it wasn't plugged in. Here is the whole attack, from last night's backup to the restore:
Why the synced copy was lost and the offline backup survived
Step 1 of 8: Last night, the files were copied to an external drive.
The studio loses a morning's work, nothing older, and it doesn't pay. Two lessons come out of it. Sync copies your mistakes as faithfully as your work, so on its own it isn't a backup (although many sync services keep earlier versions for a while, which can help). And a backup only protects you from ransomware if the ransomware can't reach it.
The defences that work
Ransomware is far easier to prevent, and to recover from, than to reverse. The defences fall into three groups.
Updates close known holes
Most break-ins use vulnerabilities that already have a fix. Turn on automatic updates for the operating system, the browser and your apps, and patch anything facing the internet first, such as a VPN or remote access, because attackers scan for those. Remove software you no longer use: it can't be exploited if it isn't there.
Careful clicks keep bad files out
- Be wary of urgency: overdue invoices, missed deliveries and password expiry warnings are classic lures.
- Check where a link really goes before clicking, and only open attachments you were expecting.
- Never turn on macros in a document just because the document asks you to.
- Use multi-factor authentication, so a stolen password alone isn't enough.
- Use an everyday account without admin rights, so a program run by mistake can do less damage.
Backups keep copies somewhere else
The 3-2-1 rule is a good start: three copies of your data, on two different kinds of storage, with one kept off-site. For ransomware, add one more rule: at least one copy must be offline or immutable, meaning a compromised machine can't change or delete it. That can be a drive you unplug, or a backup service whose versions can't be overwritten from your laptop.
Then test your restores. A backup you have never restored from is a hope, not a plan.
Common mistakes
- Treating sync as a backup. It copies every change straight away, encryption included.
- Leaving the backup drive plugged in. Ransomware encrypts every drive it can see.
- Never testing a restore, then finding out mid-attack that the backups were broken.
- Putting off updates on systems that face the internet.
- Reading email and browsing as an administrator.
If it happens anyway
Disconnect the affected machines from the network straight away to stop it spreading, but don't wipe them yet: they may show how the attacker got in. Report it to the police or your national cyber security agency, and check the No More Ransom project for a free decryptor for that strain. Only restore from backup once the hole that let it in is closed, or the same attack can simply run again.
Key takeaways
- Ransomware encrypts your files and demands payment for the key: the files stay on disk, but you can't read them.
- Strong encryption means there is usually no way back without the key or a clean backup.
- Paying is a gamble, with no guarantee of a working key and a real chance of being targeted again.
- Updates, careful clicks and multi-factor authentication stop most infections.
- Keep at least one backup offline or immutable, and test that you can restore from it.