Reviewed by the Foxmole editorial team · 2026-07-29
On this page
Key takeaways
- Ransomware is malware that locks your files and demands payment to unlock them.
- It usually gets in through a phishing message or an unpatched device.
- Your best defence is backups, plus the same habits that stop phishing.
Ransomware is one of the most damaging kinds of malware: it encrypts your files and shows a demand for money to get them back. Paying doesn’t guarantee recovery, so prevention matters most.
How it gets in
- Phishing, you open a malicious attachment or link. (This is the most common route.)
- Unpatched software, attackers exploit a known flaw you haven’t updated.
- Weak or reused passwords on remote-access accounts.
What it does
- It runs quietly and encrypts your files (documents, photos, sometimes whole drives).
- It displays a ransom note demanding payment, often in cryptocurrency.
- It may also threaten to leak your data.
How to protect yourself
- Back up regularly to a drive or cloud that isn’t always connected, this is the single best defence. If files are locked, you restore instead of paying.
- Keep everything updated, operating system, browser, apps.
- Don’t open unexpected attachments or links. (How to spot phishing.)
- Use strong, unique passwords and two-factor authentication on important accounts.
If you’re hit
Disconnect the device from the network, don’t pay if you can avoid it, and seek help, many regions have official ransomware-response resources. Restore from a clean backup where possible.