Ransomware is a type of malware that encrypts your files and demands payment for the decryption key. It has evolved from a nuisance into one of the most destructive threats facing individuals and organizations. Attackers have shifted from indiscriminate spray attacks to targeted operations against businesses, hospitals, schools, and local governments, where the pressure to restore operations quickly makes victims more likely to pay.
The ransom demands have escalated dramatically. What was once a few hundred dollars in Bitcoin is now routinely six and seven-figure demands against organizations. For individuals, ransom demands typically range from $300 to $1,000. This guide covers practical steps to prevent ransomware infections, detect them early, and recover your data if the worst happens.
Ransomware Prevention: The Three Most Effective Controls
1. Maintain Reliable, Tested Backups
Backups are your single most powerful defense against ransomware. If you can restore your data from a clean backup, a ransomware attack becomes an inconvenience rather than a disaster. But backups only work if they are properly configured:
- Use the 3-2-1 rule: Three copies of your data, on two different types of storage, with one copy stored offsite.
- Ensure backups are not continuously connected to your system. Many ransomware variants specifically target connected backup drives and cloud-synced folders. Use backup solutions that support versioning and cannot be overwritten by the ransomware process.
- Test your ability to restore. A backup you cannot restore from provides nothing but false confidence. Run a full restore test at least quarterly.
- Consider immutable backups. Cloud storage services like AWS S3 Object Lock and Backblaze B2 offer immutability features that prevent any file from being modified or deleted for a set period, even by someone with full account access.
2. Filter Email and Block Malicious Attachments
Email remains the primary delivery mechanism for ransomware. Most infections start with a phishing email containing a malicious attachment or a link to a compromised website. Effective email filtering can stop these threats before they reach users:
- Block executable attachments and script files at the email gateway. Common file types to block include .exe, .js, .vbs, .scr, .bat, .ps1, and .hta.
- Enable scanning of compressed archives like .zip and .rar files, which attackers use to bypass simple attachment filters.
- Use an email filtering service with sandboxing, which opens attachments in an isolated virtual environment to detect malicious behavior before delivering the email.
- Configure DMARC, DKIM, and SPF records for your domain to prevent attackers from spoofing your email address to target your contacts.
3. Keep Software Patched and Updated
Ransomware operators actively scan the internet for systems running unpatched software with known vulnerabilities. When a critical vulnerability is announced, attackers often have working exploit code within hours. Keeping all software updated closes these entry points:
- Enable automatic updates for operating systems, web browsers, and browser plugins.
- Pay special attention to remote access tools like Remote Desktop Protocol (RDP). If RDP must be exposed to the internet, place it behind a VPN and require multi-factor authentication. Better yet, do not expose RDP to the public internet at all.
- Maintain an inventory of all software running on your systems so you can quickly identify which systems need patching when a vulnerability is announced.
Key Point: There is no single product or technique that guarantees protection against ransomware. Defense in depth -- layering multiple protective controls so that the failure of any single control does not result in a successful attack -- is the only reliable approach.
Additional Prevention Measures
Use Reputable Antivirus with Ransomware-Specific Protection
Many antivirus products now include dedicated ransomware protection modules that monitor for the characteristic behavior of ransomware: rapid encryption of many files in a short period. When this behavior is detected, the module blocks the process and can often roll back any files that were encrypted before detection kicked in.
Restrict User Privileges
Ransomware runs with the permissions of the user who triggered it. If that user has administrative privileges, the ransomware can encrypt system files and spread more easily. Use standard user accounts for everyday work and administrative accounts only when necessary. On Windows, User Account Control (UAC) should remain enabled at its default setting.
Disable Macros in Office Documents
Malicious macros embedded in Word and Excel documents remain a common ransomware delivery mechanism. Configure Microsoft Office to block macros from the internet by default. If macros are necessary for business processes, only allow digitally signed macros from trusted publishers.
Detecting a Ransomware Attack
Ransomware does not always announce itself immediately. Modern variants often spend time moving laterally through a network, identifying and exfiltrating valuable data before beginning the encryption process. Early detection can significantly limit the damage. Watch for these warning signs:
- Unusual file activity: A sudden spike in file rename or modification operations, especially affecting many files in rapid succession.
- File extensions changing: Your documents suddenly have unfamiliar file extensions like .encrypted, .locked, or random character strings.
- Performance degradation: Systems become unexpectedly slow as encryption processes consume CPU and disk resources.
- Antivirus alerts: Your security software reports detecting and blocking suspicious behavior. Take these alerts seriously and investigate.
- Unauthorized account activity: Login attempts from unusual locations or at unusual times, especially for administrative accounts.
- Ransom note appearance: Text files or HTML files with names like README.txt or HOW_TO_DECRYPT.html appearing in multiple directories containing payment instructions.
What to Do If You Are Infected: Step-by-Step Recovery
-
Isolate Infected Systems Immediately
Disconnect the infected computer from the network by unplugging the Ethernet cable or disabling Wi-Fi. Do not shut down the computer yet, as forensic information in memory may help with recovery. If the infection is on a business network, isolate the affected network segment to prevent lateral spread.
-
Identify the Ransomware Variant
Take a photo of the ransom note with your phone. Note the file extension used for encrypted files and any email address or website listed in the note. Use a resource like ID Ransomware or the No More Ransom project to identify the specific variant. Some older ransomware variants have free decryption tools available.
-
Report the Attack
Report the incident to your local law enforcement agency. In the United States, report to the FBI's Internet Crime Complaint Center (IC3) or your local FBI field office. In the UK, report to Action Fraud. Law enforcement may not be able to recover your data, but reporting helps them track attacker groups and develop decryption tools.
-
Assess Backup Availability
Check whether your backups are intact and not also encrypted. If you have clean backups, you can proceed directly to restoration. If your backups are also compromised, you face the difficult decision of whether to pay the ransom or accept the data loss.
-
Restore from Backups or Rebuild
If clean backups exist, wipe the infected systems completely and reinstall the operating system from scratch before restoring data. Do not simply remove the ransomware and continue using the infected system, as attackers may have installed additional backdoors. If no backups exist, you may need to rebuild from scratch and accept the data loss.
-
Investigate Root Cause
Determine how the ransomware entered your system to prevent reinfection. Was it a phishing email? An unpatched vulnerability? A compromised remote desktop connection? Address the root cause before returning the system to normal use.
Should You Pay the Ransom?
The short answer is no. Law enforcement agencies and cybersecurity experts universally advise against paying ransoms. Here is why:
- No guarantee of data recovery. Attackers are criminals. Some take the money and disappear without providing a working decryption key. Others provide a key that partially works but corrupts some files. A 2022 survey found that only 61 percent of paying victims recovered all of their data.
- You fund further attacks. Every ransom payment funds the development of more sophisticated ransomware and encourages attackers to continue their operations.
- You mark yourself as a paying target. Organizations that pay are often targeted again by the same or different attacker groups, who share information about willing payers.
- Decryption may still be slow. Even with a working key, decrypting terabytes of data can take days or weeks, during which business operations remain disrupted.
- Legal and regulatory issues. In some jurisdictions, paying a ransom to sanctioned entities may violate laws and regulations. Check with legal counsel before considering payment.
Key Point: The No More Ransom project (nomoreransom.org), a collaboration between law enforcement and security companies, provides free decryption tools for many ransomware variants. Check their database before considering any payment.
If you have exhausted all alternatives and believe paying is the only option, engage a professional incident response firm. They can handle communication with the attackers and verify whether a working decryption tool is actually provided. Do not attempt to negotiate with ransomware operators directly unless you have experience in this area.
Creating a Ransomware Response Plan
Do not wait until an attack occurs to figure out your response. Create a simple ransomware response plan that answers these questions:
- Who is responsible for leading the response?
- Who needs to be notified and in what order?
- How do you isolate an infected system from the network?
- Where are your backups stored, and who has access to them?
- What is the step-by-step process for restoring from backups?
- What are your legal and regulatory obligations for reporting the incident?
- What is your communication plan for customers, partners, and employees?
Test this plan at least annually with a tabletop exercise, and update it as your systems and processes change.
Defend Against Ransomware
Explore our reviews of antivirus products with dedicated ransomware protection features to add another layer of defense.
Compare Antivirus with Ransomware Protection