Ransomware is malware that encrypts your files and displays a message demanding payment to unlock them
Ransomware is a type of malicious software that locks or encrypts your files so you cannot access them, then displays a message on your screen demanding you pay money (usually in cryptocurrency) to restore access. The attacker claims they will provide a decryption key once payment arrives, but there is no may provide they will follow through—and many do not.
The malware typically enters your computer through phishing emails with infected attachments, compromised websites, unpatched software vulnerabilities, or weak passwords on remote access tools. Once installed, it spreads through your system and encrypts files with extensions like .docx, .xlsx, .jpg, and .pdf, making them unreadable. Some variants also threaten to publish your data publicly unless you pay.
Ransomware attacks have targeted hospitals, schools, government agencies, and small businesses. The payments demanded range from hundreds to millions of dollars depending on the target and the attacker's assessment of what they think you can pay.
Key Takeaways
- Ransomware encrypts your files and demands payment; paying does not may provide you will recover your data and may fund future attacks.
- The FBI and CISA (Cybersecurity and Infrastructure Security Agency) recommend not paying ransoms, though some organizations do so when backups are unavailable.
- Disconnecting the infected device from the network when ready can prevent the malware from spreading to other computers or cloud storage.
- Restoring from a backup made before the infection is the most reliable way to recover your files without paying.
- Reporting the attack to the FBI's Internet Crime Complaint Center (IC3) and your local law enforcement helps track attackers and may lead to recovery of funds.
How ransomware spreads and what happens after infection
Ransomware most often arrives through phishing emails—messages that look like they come from a trusted sender but contain a malicious attachment or link. Opening the attachment or clicking the link downloads the malware. Other entry points include visiting a compromised website, using outdated software with known security holes, or using weak passwords on services like Remote Desktop Protocol (RDP) that attackers can brute-force their way into.
Once the malware runs, it begins encrypting files on your computer and any network drives or cloud storage you are connected to. This can happen in minutes or hours. You will see a message (called a "ransom note") appear on your screen with instructions on how to pay, usually demanding Bitcoin or another cryptocurrency. The message typically includes a countdown timer to create pressure and may claim your data will be deleted or sold if you do not pay by a certain date.
Some ransomware variants also steal your files before encrypting them, then threaten to publish them unless you pay extra. This is called double extortion and makes recovery harder because paying only decrypts your files—it does not prevent the attacker from releasing them later.
Why paying the ransom is risky and often does not work
The FBI, CISA, and the U.S. Department of Treasury all recommend against paying ransoms. The main reasons are straightforward: there is no legal obligation for the attacker to send you a working decryption key after you pay, and many victims report that they paid but never received one or received a key that only partially restored their files.
Paying also funds the attacker's next campaign and encourages more ransomware attacks. When organizations pay, attackers know the tactic works and target more victims. Additionally, paying a ransom may violate U.S. sanctions laws if the attacker is based in a country under economic sanctions (such as North Korea or Iran), which could expose you to legal liability.
If you do pay, you are also sending money to criminals with no recourse if they disappear. Some law enforcement agencies have recovered cryptocurrency payments after the fact, but this is rare and requires the attacker to use an exchange that cooperates with authorities.
when ready steps to take if your files are locked
The first action is to disconnect the infected computer from the network and the internet as soon as you notice the ransom message. Unplug the ethernet cable or turn off Wi-Fi. This stops the malware from spreading to other devices, network drives, or cloud storage accounts you are logged into. Do not shut down the computer yet—that can make recovery harder.
Next, do not pay and do not contact the attacker. Instead, take a photo or screenshot of the ransom message (it contains information that can help identify the malware variant) and report the attack to the FBI's Internet Crime Complaint Center at ic3.gov. You can also report it to your state's attorney general office and to CISA at central@cisa.dhs.gov.
If you have a recent backup of your files made before the infection occurred, you can restore from that backup after you have removed the malware. If you do not have a backup, you will need to decide whether to attempt recovery using specialized tools, hire a data recovery service, or accept the loss of the files.
Identifying the ransomware variant and finding a decryption tool
Different ransomware variants use different encryption methods. Some older variants have known weaknesses, and security researchers have released free decryption tools for them. To identify which variant infected your system, you can use the ransom note itself—it often contains the malware's name or a unique identifier.
Websites like ID Ransomware (idransomware.com) and Ransomware.org allow you to upload a sample of the ransom note or an encrypted file, and they will tell you which variant it is and whether a free decryption tool exists. If a tool is available, you can read it and use it to decrypt your files without paying.
However, most newer ransomware variants use encryption that cannot be broken without the attacker's private key. In those cases, your only options are to restore from a backup, accept the loss, or pay (which is not recommended).
Removing the malware and preventing future infections
After you have disconnected the computer and reported the attack, you will need to remove the malware. This usually requires either running antivirus or anti-malware software in safe mode, or wiping the computer entirely and reinstalling the operating system from a clean source. If you are not comfortable doing this yourself, take the computer to a professional IT technician or managed security service.
To prevent ransomware infections in the future, keep your operating system and all software up to date with the latest security patches. Use strong, unique passwords for all accounts, especially those with remote access. Enable multi-factor authentication wherever it is offered. Back up your important files regularly to a location that is not connected to your main network (such as an external hard drive you disconnect after each backup, or a cloud service that does not sync in real time). Train yourself and anyone else who uses your computer to recognize phishing emails and avoid opening attachments from unknown senders.
What to expect if you report the attack to law enforcement
When you report a ransomware attack to the FBI or local law enforcement, they will document the incident and add it to their database of attacks. This information helps them identify patterns, track organized criminal groups, and sometimes recover cryptocurrency payments if the attacker uses an exchange that cooperates with authorities.
However, law enforcement cannot may provide recovery of your files or your money. Their primary goal is to gather intelligence and pursue the attackers, which can take months or years. If you paid a ransom and reported it, the FBI may be able to work with cryptocurrency exchanges to freeze the funds, but only if the attacker has not already moved the money to an untraceable wallet.
Reporting is still worth doing even if you do not expect when ready results, because it contributes to the overall effort to disrupt ransomware operations and may help other victims.
Frequently Asked Questions
Can I recover my files without paying or having a backup?
Possibly, depending on the ransomware variant. Check ID Ransomware or Ransomware.org to see if a free decryption tool exists for your variant. If not, a data recovery specialist may be able to help, though this is expensive and success is not may provide. Some variants have weaknesses that researchers discover over time, so tools may become available later.
What if the ransom message says my data will be deleted in 24 hours?
This is a pressure tactic and is almost never true. Attackers want you to panic and pay quickly, but they have no incentive to delete data they might sell or use for extortion later. Ignore the timer and focus on reporting the attack and exploring recovery options.
Is it illegal to pay a ransom?
Paying a ransom to a criminal is not inherently illegal, but it may violate U.S. sanctions laws if the attacker is based in a sanctioned country. The Treasury Department's Office of Foreign Assets Control (OFAC) has issued guidance warning that ransomware payments to certain groups could expose you to legal liability. Consult a lawyer before paying.
Will my antivirus software protect me from ransomware?
Antivirus software can catch some ransomware, especially older variants, but it is not foolproof. The best protection is a combination of keeping software updated, using strong passwords, enabling multi-factor authentication, and maintaining regular backups that are not connected to your network.
What should I do if ransomware infects my business?
Disconnect all infected devices when ready, notify your IT team or managed security provider, report to the FBI and CISA, and notify your customers and business partners if their data may have been compromised. Do not pay without consulting legal counsel and your insurance company, as some cyber insurance policies cover ransomware attacks and may have specific requirements about reporting and payment.