Ransomware is malware that encrypts your files and holds them for money. If a ransom note is on your screen right now, the next steps you take decide how much damage this attack does. Here is what it is, how it gets in, and what to do if you get hit.
What ransomware actually is
Ransomware scrambles your files with encryption so you can no longer open them. Your documents, photos, and spreadsheets suddenly become unreadable. The attackers then show a message, usually demanding payment in cryptocurrency, and promise a decryption key in return. Some variants add a second threat: your private files get published online if you do not pay.
Ransomware is not one virus. It is a criminal business whose operators only care that your data matters enough for you to pay.
How ransomware usually gets in
Most infections are not clever hacks. They happen because someone opened the wrong thing. The most common entry points are:
- Phishing attachments. A believable email arrives, posing as an invoice or a delivery notice. Opening the attached file runs the malware.
- Fake downloads. A free program, a cracked game, or a phony update from the wrong site can install ransomware silently.
- Remote access scams. A caller claims to be from tech support and asks you to install software that gives them control of your machine.
These messages are designed to look ordinary. Our guide to spotting fake payment emails shows the details scammers get wrong.
The honest truth about paying the ransom
Here is the uncomfortable part. Paying often does not give your files back. Attackers may take the money and vanish, or send a tool that does not work. When payment does succeed, you have funded a criminal operation that will simply build better ransomware.
Law enforcement and security agencies give the same advice: do not pay. Every payment finances the next victim's attack.
What to do first if you get hit
If you find a ransom message, work through these steps in order:
- Disconnect the device from the network. Unplug the cable or switch off Wi-Fi. This can stop ransomware from spreading to other computers and network drives.
- Do not pay. No payment, no negotiation, no small test amount. There is no reason to trust the attackers.
- Take a photo of the message. Photograph the screen with your phone to capture the ransom note, wallet address, and any details you need later.
- Do not try random fixes from forum posts. They can make professional recovery harder.
Keep the ransom note and the encrypted files. They are evidence, and your data may be recoverable even when the encryption looks final.
Recovering after an attack
Your way out depends on what you had before the attack, not after. The fastest recovery is a clean restore from a backup made before the infection.
- If you have a recent offline backup, wipe the device and restore your files from it.
- If you do not, call a professional. Security firms can sometimes decrypt older ransomware variants.
- Report the attack to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. Your report helps investigators track the groups behind these crimes.
The real protection is prevention
Ransomware is miserable to clean up, and prevention costs far less. The basics stop most attacks:
- Keep an offline backup. A drive disconnected from your computer and updated on a schedule is the most reliable way to get your files back. Our backup strategy guide shows you how to set one up.
- Update your software. Updates patch the holes malware uses to sneak in. Turn on automatic updates.
- Think before you click. Treat unexpected attachments, links, and download buttons with suspicion. Hover over links to see where they lead.
- Use a limited account. Do everyday work without administrator rights. Ransomware cannot change your system if it cannot get permission.
- Add a safety net. A tool like Scam Guard blocks known scam sites before your browser loads them.
Why backups are the only reliable defense
Encryption is designed to work one way. Without the attackers' key, unlocking your files is practically impossible, which is why they can charge for it. So the only defense you can fully rely on is having your data somewhere the ransomware never touched.
Backups change the math. When your data lives on a disconnected drive, the ransom note loses its power. You do not need their key because you already have your files. Paying becomes a decision you never have to make.
You cannot make malware impossible, but you can make it pointless. Set up the backup this week, test the restore, and keep the drive unplugged.
FAQ
Can ransomware spread to other computers on my network? Yes. If your devices share a network or network drives, ransomware can spread sideways to reach them, so disconnect the infected machine first.
If I pay the ransom, will I get my files back? Not reliably. Some attackers take the money and disappear, and some send tools that do not work. There is no guarantee of recovery, and the money funds more crime.
Should I delete the encrypted files and the ransom note? No. Keep both. The ransom note and the encrypted files are evidence, and security professionals may be able to recover data from them even when the encryption looks complete.
How do I know if an attachment or email is dangerous? Slow down and look closely. Check the sender's full address, watch for spelling errors, and hover over links before clicking. When in doubt, contact the sender through a known channel instead of replying.
Sources and further reading
---Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026.