Ransomware encrypts your files and holds them hostage until you pay
Ransomware is malware that scrambles your files using encryption so you cannot open them, then displays a message demanding payment to unscramble them. Unlike other malware that steals data or slows your computer, ransomware makes your own files unusable on purpose. The attacker keeps the decryption key — the digital password needed to unlock your files — and will only give it to you if you pay.
The files stay on your computer. You can see them. But they are locked in a form you cannot read. A photo file becomes gibberish. A Word document will not open. A spreadsheet is useless. The attacker is betting you will pay rather than lose the files entirely.
Ransomware typically arrives through email attachments that look legitimate, downloads from compromised websites, or by exploiting unpatched security holes in your operating system or software. Once it runs, it spreads through your computer and any network drives connected to it — including cloud storage, external hard drives, and shared folders on your home network.
Key Takeaways
- Ransomware encrypts your files and makes them unreadable until you pay the attacker, who holds the decryption key.
- The malware often arrives through email attachments, fake downloads, or security holes in software you have not updated.
- Paying does not may provide you will get your files back, and it funds criminal operations that target others.
- Your best defense is keeping backups offline, updating your software regularly, and not opening attachments from unknown senders.
- If infected, disconnect from the internet when ready to stop the malware from spreading to other devices and storage.
How ransomware spreads through your computer and network
Once ransomware runs on your machine, it does not stop at your personal files. It looks for anything it can encrypt — documents, photos, videos, databases. If your computer is connected to a home network, it will try to reach other computers, printers, and storage devices on that network. If you use cloud storage like Google Drive, OneDrive, or Dropbox, the malware will encrypt the files synced to your computer, which then syncs the encrypted versions to the cloud, potentially destroying your backups.
This is why ransomware is so damaging: it can wipe out years of files in minutes. A single infected email attachment can lock up your entire household's digital life if multiple computers share the same network or cloud account.
The ransom demand and why paying is risky
After encryption finishes, ransomware displays a message — sometimes a full-screen popup, sometimes a text file left on your desktop — with instructions on how to pay. The demand usually ranges from a few hundred to thousands of dollars. Payment is requested in cryptocurrency like Bitcoin, which is harder to trace than a credit card or bank transfer.
Paying does not may provide you will recover your files. Some attackers take the money and disappear. Others provide a decryption tool that does not work or works only partially. There is no contract, no refund policy, and no way to force them to hold up their end. You are trusting criminals to be honest.
Paying also funds the operation. Your money goes directly to the people running the attack, making it profitable for them to target more victims. Law enforcement agencies and cybersecurity experts consistently advise against paying, both because it does not reliably work and because it perpetuates the crime.
Common types of ransomware and what they target
WannaCry spread globally in 2017 by exploiting a Windows security hole. It encrypted files on hundreds of thousands of computers, including hospital systems in the UK that had to turn away patients. Ryuk is ransomware that attackers deploy after breaking into a network manually — they spend time inside your system first, learning what files matter most to you, then encrypt them strategically to maximize pressure to pay. Lockbit is one of the most active ransomware operations today; it spreads through phishing emails and unpatched vulnerabilities.
Some ransomware targets individuals and small businesses. Other variants are designed to hit hospitals, schools, and government agencies — organizations that cannot afford downtime and may be more likely to pay. Ransomware-as-a-service operations even rent out their malware to other criminals, the way legitimate software companies offer subscriptions.
What to do if your computer is infected
If you see a ransom message or notice that files have strange extensions or will not open, disconnect your computer from the internet when ready. Unplug the ethernet cable or turn off Wi-Fi. This stops the malware from spreading to other devices and prevents it from communicating with the attacker's servers.
Do not restart your computer unless you have to. Shutting down and restarting can sometimes trigger the malware to encrypt more files or delete recovery options. Leave it powered on but offline.
Next, contact your local law enforcement agency or the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. Report what happened, including the ransom message, the date, and any details about how the infection started. This helps authorities track ransomware campaigns.
Then consult a cybersecurity professional or your computer manufacturer's support line. Some ransomware has known weaknesses, and security researchers have released free decryption tools for older variants. Your antivirus software may also have a recovery option. Do not attempt to decrypt files yourself — you can make the situation worse.
Protecting yourself before infection happens
The most important defense is offline backups. Back up your important files to an external hard drive that you physically disconnect and store away from your computer when not in use. Cloud backups alone are not enough because ransomware can encrypt those too. An offline drive cannot be reached by malware on your computer.
Keep your operating system and software updated. Ransomware often exploits security holes that vendors have already patched. Windows Update, macOS updates, and security patches for programs like Adobe Reader and Java close these holes. Set updates to install automatically so you do not have to remember.
Be cautious with email attachments and downloads. Do not open attachments from people you do not know, and be skeptical of unexpected attachments from people you do know — their email account may have been compromised. Avoid downloading files from unfamiliar websites, especially executable files (.exe, .msi, .scr).
Use antivirus or anti-malware software. Windows Defender (built into Windows) and Malwarebytes both detect and block many ransomware variants. They are not perfect — new variants emerge constantly — but they catch the majority of threats.
The difference between ransomware and other file-threatening malware
Ransomware is not the only malware that damages files. Wiper malware straightforward deletes files without asking for payment — it is designed to destroy data, not extort money. Trojan horses can read and install ransomware, but the trojan itself might steal passwords or create a backdoor for attackers instead. Cryptojacking malware uses your computer's processing power to mine cryptocurrency but does not touch your files.
The defining feature of ransomware is the combination: encryption plus a ransom demand. If your files are locked and someone is asking for money, you are dealing with ransomware. If files are straightforward deleted or your computer is slow, it is a different threat that requires a different response.
Frequently Asked Questions
Can antivirus software remove ransomware after it has already encrypted my files?
Antivirus can remove the ransomware program itself and stop it from spreading further, but it cannot decrypt files that are already locked. Decryption requires the key that only the attacker has. Removing the malware is still important because it prevents new files from being encrypted and stops the malware from communicating with the attacker's servers.
If I pay the ransom, will I definitely get my files back?
No. Some attackers provide working decryption tools, but many do not. You have no way to verify they will help before you pay, and no recourse if they take your money and disappear. Law enforcement and cybersecurity experts recommend against paying for this reason, even though the pressure to do so is intense.
Does ransomware only affect Windows computers?
Ransomware primarily targets Windows because it is the most common operating system, but macOS and Linux systems can be infected too. The principles of protection are the same across all systems: keep software updated, maintain offline backups, and be cautious with downloads and email attachments.
What should I do if ransomware encrypted files on my external hard drive?
Disconnect the drive when ready and do not reconnect it to an infected computer. If the drive was connected when the infection happened, the files may be encrypted. A cybersecurity professional can assess whether recovery is possible. Some encrypted files can be recovered if the malware did not overwrite the original data, but this requires specialized tools.
Is paying in cryptocurrency safer than paying by credit card?
Cryptocurrency is harder to trace, which is why attackers prefer it, but that does not make it safer for you. Paying in any form funds criminal activity and does not may provide file recovery. The method of payment does not change the core problem: you are trusting criminals to keep their word.