Reviewed by the Foxmole editorial team · 2026-07-29

Key takeaways

  • Ransomware is malware that locks your files and demands payment to unlock them.
  • It usually gets in through a phishing message or an unpatched device.
  • Your best defence is backups, plus the same habits that stop phishing.

Ransomware is one of the most damaging kinds of malware: it encrypts your files and shows a demand for money to get them back. Paying doesn’t guarantee recovery, so prevention matters most.

How it gets in

  • Phishing, you open a malicious attachment or link. (This is the most common route.)
  • Unpatched software, attackers exploit a known flaw you haven’t updated.
  • Weak or reused passwords on remote-access accounts.

What it does

  • It runs quietly and encrypts your files (documents, photos, sometimes whole drives).
  • It displays a ransom note demanding payment, often in cryptocurrency.
  • It may also threaten to leak your data.

How to protect yourself

  • Back up regularly to a drive or cloud that isn’t always connected, this is the single best defence. If files are locked, you restore instead of paying.
  • Keep everything updated, operating system, browser, apps.
  • Don’t open unexpected attachments or links. (How to spot phishing.)
  • Use strong, unique passwords and two-factor authentication on important accounts.

If you’re hit

Disconnect the device from the network, don’t pay if you can avoid it, and seek help, many regions have official ransomware-response resources. Restore from a clean backup where possible.

Keep going