Ransomware basics: how it works, how to prevent it and what to do first
Malware / security. Updated 2026-09-13. About 5 minutes to read.
Keep at least one backup disconnected from your computer and the internet, because it is the only thing that reliably turns a ransomware attack into an inconvenience.
Ransomware locks your files or your whole device and demands payment for the key. Most modern gangs also copy your data before locking it and threaten to publish it, so a backup alone no longer ends the problem. Homes, sole traders and small offices get hit because they rarely have offline backups or anyone watching for warning signs.
Official agencies agree on the core advice. Australia's ACSC says never pay a ransom, because there is no guarantee you will get your files back or that stolen data will not be leaked. This guide explains how ransomware gets in, the backups that defeat it and the exact steps to take in the first hour.
How ransomware gets in
Phishing emails with attachments or links to fake login pages that steal passwords.
Pirated software, game cracks and fake app downloads carrying hidden malware.
Remote access tools left open to the internet with weak or reused passwords.
Unpatched devices, including network storage boxes and routers.
Stolen passwords bought from earlier breaches and tried against email and remote access accounts.
Not every scary lock screen is ransomware. Fake warnings in a browser that claim police have locked your computer are scareware. Closing the browser, or restarting if needed, usually ends them. Real ransomware leaves files you cannot open.
Warning signs an attack is under way
Act on these signs even before a ransom note appears. Encryption can take minutes or hours, and turning the device off early can save files that have not been reached yet.
Files suddenly have a new or strange extension and will not open.
A text or HTML file with a name like README or HOW TO DECRYPT appears in many folders.
Your security software has been switched off and will not turn back on.
The computer or network storage is busy for a long time with the fan running hard while you are not using it.
Security alerts about new sign-ins, new admin accounts or changed passwords that you did not make.
The first hour: what to do if you see a ransom note
Photograph the ransom note and the screen with your phone. Do not click links or contact the criminals.
Turn off the infected device by holding the power button or unplugging it. The ACSC says this is the best way for most people to stop ransomware spreading.
Disconnect and turn off your other devices too, starting with network storage, external backup drives and computers that hold important files.
From a device you trust, change the passwords for your email, banking and password manager, and sign out other sessions. Some ransomware steals passwords as well.
If you use OneDrive, Dropbox or similar, stop syncing on other devices so encrypted copies do not overwrite good cloud versions.
Report it: ReportCyber at cyber.gov.au or the ACSC hotline on 1300 CYBER1 (1300 292 371) in Australia, Report Fraud in the UK at reportfraud.police.uk or 0300 123 2040, and ic3.gov in the US.
Businesses with an IT provider or cyber insurance should call them before powering servers down. Responders sometimes prefer a machine isolated from the network but left on, to preserve evidence.
Recovering after the first hour
Check the No More Ransom project at nomoreransom.org, run by Europol, Dutch police and security companies. Its Crypto Sheriff tool identifies the ransomware and links to a free decryptor if one exists.
If no decryptor exists, wipe the infected drives and reinstall the operating system. The ACSC says this is the most reliable way for most people to remove ransomware.
Restore files from a backup made before the infection, and scan restored files before opening them.
For cloud storage, use version history or a full restore. OneDrive lets Microsoft 365 subscribers restore their whole OneDrive to a point in the last 30 days.
If stolen data included customer or staff details, check your breach notification duties, such as the Notifiable Data Breaches scheme in Australia or reporting to the ICO in the UK.
Why paying the ransom rarely ends it
Paying does not guarantee a working key, and it does not delete copies of your data. Criminals may come back for a second payment or sell the data anyway. In the US, paying a group on a sanctions list can also create legal problems for the payer.
If you are a business considering payment, get professional incident response and legal advice first. The NCSC publishes guidance for organisations facing that decision.
Prevention that works at home and in small offices
Keep an offline backup: a drive you connect only while backing up, or a second drive rotated off-site. Test a restore every few months, because a backup you have never restored is a guess.
Turn on automatic updates for your operating system, browser, apps, router and network storage.
Use a password manager and add a passkey or authenticator app to email and remote access accounts.
Never install cracked software or tools from unofficial download sites.
Turn off remote desktop and remote access features you do not use, and never expose them directly to the internet.
Keep built-in protection such as Microsoft Defender turned on, and turn on ransomware protection features where offered.
Frequently asked questions
Can antivirus remove ransomware and unlock my files?
Security software can often remove the ransomware program, but it cannot usually decrypt files that are already locked. That needs a decryptor, a backup or professional help.
Should I pay the ransom?
Official agencies advise against it. There is no guarantee of recovery, data may still be leaked, and you may be targeted again. Report the attack and explore decryptors and backups first.
Can ransomware spread to my cloud storage and backups?
Yes. Synced folders copy encrypted files to the cloud, and backup drives left plugged in can be encrypted too. Version history and an offline backup are what save you.
Can phones get ransomware?
It is rare on iPhones and more common on Android phones that install apps from outside the Play Store. Keep phones updated and install apps only from official stores.
How do I know if my data was stolen as well as locked?
Often you cannot tell straight away. Many gangs copy data first and say so in the ransom note. Businesses should assume data was taken until an investigation shows otherwise, and warn customers and staff to expect phishing.