Ransomware encrypts your files and makes them unreadable until you pay the attacker
Ransomware is malware that scrambles your files using encryption so you cannot open them. The attacker then demands payment—usually in cryptocurrency like Bitcoin—in exchange for a decryption key that would restore your files. You cannot unlock the files yourself, and paying does not may provide the attacker will actually send the key or that your files will work afterward.
Ransomware spreads through email attachments that look legitimate, links in phishing messages, compromised websites, or unpatched security holes in software you use every day. Once it runs, it finds documents, photos, spreadsheets, and databases on your computer or network and encrypts them. The attacker leaves a note—usually a text file or pop-up window—with instructions on how to pay and threats about what happens if you do not.
The damage is real. You lose access to your own files immediately. If this happens on a work computer, your entire organization may grind to a halt. Hospitals have had to turn away patients. Schools have cancelled classes. Small businesses have closed permanently because they could not recover their data.
Key Takeaways
- Ransomware encrypts your files and makes them unreadable; the attacker demands payment for the decryption key, which may or may not work.
- Most ransomware arrives through email attachments, phishing links, or security holes in software that has not been updated.
- Paying the ransom funds criminal operations, does not may provide file recovery, and often leads to repeated attacks on the same victim.
- The best protection is keeping backups offline, updating software regularly, and being cautious about email attachments and links from unknown senders.
- If you are infected, disconnect from the internet immediately and contact law enforcement or a cybersecurity professional before considering any payment.
How ransomware gets onto your computer
Email is the most common entry point. You receive a message that appears to come from your bank, a delivery service, or a coworker. The message includes an attachment—a PDF, Word document, or spreadsheet—that actually contains malware. When you open it, the ransomware installs itself and begins encrypting files in the background.
Phishing links work the same way. A message tells you to click a link to "verify your account" or "confirm your password." The link takes you to a fake website or triggers a download that installs ransomware. You may not notice anything wrong until your files are already locked.
Unpatched software is another common route. If your operating system, web browser, or applications have known security holes and you have not installed the latest updates, attackers can exploit those holes to install ransomware without you clicking anything. This is why security updates matter even when they seem inconvenient.
Some ransomware spreads through compromised websites or malicious ads on legitimate sites. Others arrive through USB drives left in parking lots or public places—a tactic that works surprisingly often in offices where people are curious about unknown devices.
What happens after ransomware encrypts your files
Once the encryption is complete, you see a message on your screen. It usually includes a countdown timer, a demand for payment in Bitcoin or another cryptocurrency, and threats about what will happen if you do not pay. Some messages claim your files will be deleted. Others threaten to publish your personal data online. These threats are sometimes real and sometimes bluffs.
The attacker has no incentive to help you after you pay. Some victims who pay receive a working decryption key. Others receive a key that does not work, or they receive nothing at all. Even if the key works, it may be slow or corrupt some files. There is no recourse—you cannot sue the attacker or report the transaction to your bank the way you could with a credit card.
Paying also marks you as a victim willing to pay, which makes you a target for future attacks. Attackers sell lists of paying victims to other criminal groups. Your organization may be hit again weeks or months later by a different attacker.
Ransomware variants that target specific industries
Some ransomware is designed to cause maximum disruption in hospitals, schools, or government agencies. WannaCry spread globally in 2017 by exploiting a Windows security hole and affected hospitals, banks, and manufacturers. Ryuk targets large organizations and demands payments in the hundreds of thousands of dollars. Conti has hit hospitals, police departments, and city governments.
Other variants are more indiscriminate. LockBit and BlackCat encrypt files on any computer they reach and have affected thousands of victims across industries. The attackers behind these variants often steal data before encrypting it, then threaten to publish the data if you do not pay—a tactic called "double extortion."
Knowing the name of the ransomware that infected you can help. Security researchers sometimes release free decryption tools for older variants. The No More Ransom Project (nomoreransom.org) maintains a database of free decryption tools for dozens of ransomware families. If you can identify which variant infected you, you may be able to recover your files without paying.
Steps to take if your files are encrypted
Disconnect from the internet immediately. Unplug your ethernet cable or turn off Wi-Fi. This stops the ransomware from spreading to other computers on your network or uploading your data to the attacker's servers. Do not shut down your computer—that may trigger additional malicious actions.
Take a photo or screenshot of the ransom message. It contains information that will help identify which ransomware infected you. Save this image to a USB drive or another device.
Contact law enforcement. In the United States, report the attack to the FBI's Internet Crime Complaint Center (ic3.gov) or your local FBI field office. In other countries, contact your national cybercrime agency. Law enforcement cannot decrypt your files, but they track ransomware attacks and may have information about whether a decryption tool exists.
Do not pay without consulting a professional. Contact a cybersecurity firm that specializes in ransomware recovery. They can identify the variant, check whether a free decryption tool exists, and advise you on whether paying makes sense in your specific situation. Many organizations have cyber insurance that covers ransomware attacks and includes access to these professionals.
How to reduce your risk of ransomware infection
Keep backups of important files on a device that is not connected to your computer or network. If ransomware encrypts your files, you can restore them from the backup without paying. Backups should be offline—not in cloud storage that syncs automatically, because ransomware can encrypt those files too. An external hard drive kept in a drawer or a second computer that you connect only occasionally works well.
Update your software regularly. Enable automatic updates for your operating system, web browser, and applications. Security holes get patched constantly, and attackers exploit the ones that are not patched. Updates are the fastest way to close those holes.
Be cautious with email attachments and links. Do not open attachments from senders you do not recognize. Even if an email appears to come from someone you know, verify it by calling them or sending a separate message if the attachment seems unexpected. Hover over links before clicking them to see where they actually go.
Use antivirus software and keep it updated. Antivirus programs cannot catch every ransomware variant, but they catch many. Windows Defender (built into Windows) and Malwarebytes are both effective. They are not a complete solution, but they are better than nothing.
Use a password manager and enable two-factor authentication on important accounts. If an attacker gains access to your email or cloud storage account, they can install ransomware remotely. Strong, unique passwords and two-factor authentication make that much harder.
What organizations should do to prepare
Businesses and schools should maintain offline backups that are tested regularly. A backup that has never been restored is a backup that might not work when you need it. Test the restoration process at least once a year.
Segment your network so that if one computer is infected, the ransomware cannot spread to all your files at once. This means separating critical systems, using different user accounts with limited permissions, and restricting which computers can access which data.
Train employees to recognize phishing emails and report suspicious messages. Most ransomware attacks start with an employee opening an attachment or clicking a link. Regular training reduces that risk significantly.
Consider cyber insurance. It covers recovery costs, forensic investigation, and sometimes ransom payments. Insurance companies often require certain security practices in place before they will cover you, which pushes organizations toward better security overall.
Frequently Asked Questions
Should I pay the ransom if my files are encrypted?
Paying does not may provide recovery, funds criminal operations, and marks you as a target for future attacks. Consult law enforcement and a cybersecurity professional first. Check the No More Ransom Project for free decryption tools. If you have backups, restore from those instead. Paying should be a last resort only after exploring all other options.
Can antivirus software remove ransomware after it encrypts my files?
Antivirus can remove the ransomware program itself, but it cannot decrypt files that have already been encrypted. Removing the malware stops it from spreading further, but your files remain locked. This is why backups are so important—they let you restore your data even after the malware is gone.
What is the difference between ransomware and other malware?
Ransomware specifically encrypts your files and demands payment. Other malware might steal your passwords, monitor your activity, or use your computer to attack other systems without you knowing. Ransomware is obvious—you know immediately that something is wrong because you cannot access your files.
If I pay in Bitcoin, can the attacker be traced?
Bitcoin transactions are recorded on a public ledger, but the person behind a Bitcoin address is not always obvious. Law enforcement can sometimes trace payments, especially if the attacker converts Bitcoin to regular currency. However, tracing takes time, and most victims never recover their money. This is another reason not to pay.
Can ransomware infect my phone or tablet?
Yes, but it is less common. Android phones can be infected through malicious apps, and iPhones can be infected if they are jailbroken. The same rules apply: keep your device updated, be cautious about what you download, and maintain backups. Most ransomware still targets computers and networks because that is where the valuable data is.