Ransomware: What It Is and How to Protect Yourself
Ransomware encrypts your files and demands payment for the decryption key. Learn how infections spread through phishing and RDP, and how to prevent attacks.
Table of Contents
- What Is Ransomware?
- How Ransomware Spreads
- Phishing Emails
- Malicious Downloads
- Exploiting Unpatched Software
- Remote Desktop Protocol (RDP)
- Infected USB Drives
- What Happens During a Ransomware Attack
- How to Prevent Ransomware
- Maintain Offline Backups
- Keep Software Updated
- Don't Open Suspicious Attachments or Links
- Use Reputable Antivirus Software
- Disable Macros in Office Documents
- Use Standard User Accounts
- What to Do If You're Hit
What Is Ransomware?
Ransomware is a type of malicious software — malware — that encrypts your files, making them completely inaccessible. The attacker then demands a ransom payment (usually in cryptocurrency) in exchange for the decryption key. Without that key, your documents, photos, videos, and other files are permanently unreadable.
Ransomware attacks have exploded in recent years, targeting individuals, hospitals, schools, and corporations. In many cases, victims lose files permanently — either because they can't pay, don't trust the attacker to honor the deal, or pay but never receive a working key.
How Ransomware Spreads
Understanding how ransomware gets onto devices helps you avoid it.
Phishing Emails
The most common delivery method. An email arrives with a malicious attachment — disguised as an invoice, shipping notice, or document — or a link to a malicious website. Opening the attachment or clicking the link executes the ransomware.
Malicious Downloads
Pirated software, cracked apps, and files downloaded from unofficial sources frequently contain malware. Fake software updates or browser plugins are also common vectors.
Exploiting Unpatched Software
Some ransomware spreads automatically by exploiting known security vulnerabilities in operating systems or applications. The WannaCry attack in 2017 infected hundreds of thousands of computers by exploiting a vulnerability in Windows that Microsoft had already patched — but many organizations hadn't applied the update.
Remote Desktop Protocol (RDP)
Attackers frequently scan the internet for computers with Remote Desktop Protocol exposed and protected only by weak passwords. Once they gain access, they manually deploy ransomware. This is common in attacks targeting businesses.
Infected USB Drives
Physical devices left in parking lots or mailed to targets have been used to spread malware — people plug them in out of curiosity, and the malware installs itself automatically.
What Happens During a Ransomware Attack
Once ransomware executes, it typically:
- Connects to the attacker's server to retrieve an encryption key
- Silently scans your drive for valuable files — documents, images, databases, backups
- Encrypts each file, often appending a new extension (like
.lockedor.encrypted) - Deletes the originals and any local backups it can find
- Displays a ransom note with payment instructions and a deadline, after which the price increases or the key is destroyed
The entire process can complete in minutes, leaving you with a system full of encrypted files you cannot open.
How to Prevent Ransomware
Maintain Offline Backups
This is the single most important defense. If you have a clean, recent backup of your data stored somewhere that isn't connected to your computer, ransomware cannot touch it. Follow the 3-2-1 backup rule: keep 3 copies of your data, on 2 different media types, with 1 copy stored offsite or offline.
Keep Software Updated
Most ransomware exploits known vulnerabilities that already have patches available. Keeping your operating system, browser, and all applications up to date closes these doors before attackers can use them.
Don't Open Suspicious Attachments or Links
Be extremely cautious with email attachments, even from people you know — their accounts may be compromised. When in doubt, contact the sender through a separate channel to verify they intended to send the file.
Use Reputable Antivirus Software
Modern antivirus and endpoint protection software can detect and block many ransomware strains before they execute. Keep your antivirus definitions updated and run regular scans.
Disable Macros in Office Documents
Microsoft Office macros — small programs that automate tasks — are frequently abused to deliver malware. Unless you specifically need macros for your work, disable them in your Office settings.
Use Standard User Accounts
Ransomware can only do what your user account is permitted to do. If you browse the web using an account with full administrator privileges, malware gets those privileges too. Create a standard (non-admin) account for everyday use, and only use your administrator account when needed.
What to Do If You're Hit
- Disconnect from the internet immediately. Unplug the Ethernet cable or turn off Wi-Fi. This may stop the ransomware from encrypting more files or communicating with the attacker's server.
- Don't pay the ransom — paying funds criminal operations and doesn't guarantee you'll get your files back.
- Report the attack to your local cybercrime authority (e.g., the FBI's IC3 in the US, Action Fraud in the UK).
- Check No More Ransom (nomoreransom.org) — a free resource that provides decryption tools for some known ransomware families.
- Restore from your backup. Wipe the infected system and restore your files from a clean, offline backup.
- Have a professional help if you're unsure — don't try to decrypt or repair while the malware may still be active.
The hard reality is that without a backup, there may be no good options. Prevention, especially regular offline backups, is by far the most effective strategy.