What Ransomware Does

Ransomware is malicious software that encrypts files on a device — or an entire network — and then demands payment, usually in cryptocurrency, in exchange for the decryption key needed to restore access. Some variants also threaten to publish stolen data if payment isn't made, adding pressure beyond simply losing access to files.

How Ransomware Typically Spreads

  • Phishing emails with malicious attachments or links remain one of the most common entry points.
  • Exploited software vulnerabilities in outdated operating systems or applications that haven't been patched.
  • Compromised remote access, such as weakly secured remote desktop connections.
  • Malicious downloads disguised as legitimate software, cracked programs, or fake updates.

Why Paying the Ransom Is Discouraged

Law enforcement agencies and security researchers generally advise against paying ransom demands. Payment doesn't guarantee that files will actually be restored, funds fraudulent operations, and can mark the victim as willing to pay in future attacks. It's a decision ultimately made case by case, often in consultation with security professionals and law enforcement, but it isn't a guaranteed fix.

Backups: The Most Reliable Defense

Because ransomware primarily threatens access to files, having reliable backups is the single most effective way to reduce its impact. The commonly recommended approach is the '3-2-1' rule: keep at least three copies of important data, on two different types of storage media, with at least one copy stored offline or disconnected from the network so ransomware can't reach and encrypt it too.

Reducing the Risk of Infection

  • Keep operating systems and applications updated, since many ransomware attacks exploit known, already-patched vulnerabilities.
  • Use real-time security software with ransomware-specific protections, such as controlled folder access.
  • Be cautious with email attachments and links, applying the same scrutiny described in phishing-awareness guidance.
  • Use strong, unique passwords and multi-factor authentication, particularly for remote access tools.
  • Disable or tightly restrict remote desktop access unless it's actively needed.

What to Do If You're Affected

  1. Disconnect the affected device from the network immediately to prevent further spread.
  2. Do not pay the ransom before consulting security professionals or, for organizations, legal counsel.
  3. Report the incident to relevant authorities — for example, the FBI's Internet Crime Complaint Center (IC3) in the United States, or the equivalent national cybercrime reporting body elsewhere.
  4. Restore from backups where possible, after confirming the malware has been removed.
  5. Check whether a free decryption tool exists for the specific ransomware variant — some are published by security researchers through initiatives such as the No More Ransom project.