What Is Ransomware? How It Works and How to Protect Yourself

Ransomware is malware that locks or encrypts your files, then demands payment for the key to restore them. It is disruptive because the damage is obvious: photos, documents, and business files may stop opening all at once.

Does this affect you?

Use this for Windows PCs, Macs, and other devices. Businesses are common targets, but home users can still be hit through the same malware routes.

How ransomware works

It is a criminal business model based on denying access to your own data.

  1. It usually enters through a phishing attachment, malicious link, fake software update, compromised download, infected USB drive, or pirated software.
  2. Once running, it encrypts files in the background, sometimes thousands of them before you notice.
  3. A ransom note appears as a text file, popup, or changed wallpaper demanding payment, often in cryptocurrency.
  4. The note may include a countdown, price increase, threat to delete the key, or threat to leak stolen data.
  5. Paying does not guarantee recovery. Some victims receive a working key, others get nothing, and payment can mark you as willing to pay.

Protect yourself before it happens

Backups matter because removing ransomware does not automatically decrypt files.

  1. Keep offline backups of important files. An external drive should be disconnected when not actively backing up.
  2. Use cloud backup with file versioning so encrypted copies can be rolled back.
  3. Keep the operating system, browser, and apps updated. Many attacks use vulnerabilities already fixed by patches.
  4. Be careful with unexpected attachments, even from known contacts. Do not enable Office macros unless you are certain the file is legitimate.
  5. Use reputable antivirus with real-time protection, such as Microsoft Defender on Windows or a trusted security product.
  6. Avoid cracked software, keygens, and unofficial downloads because they are common malware delivery paths.

More control

If ransomware appears

Disconnect Wi-Fi or Ethernet immediately to reduce spread to network drives, other devices, or syncing services.

Check for decryptors before paying

StopRansomware.gov and the No More Ransom project list free decryptors for some older or weaker ransomware strains.

Reinstall and restore carefully

After removal, a clean operating-system reinstall is often safest. Restore files from an offline or versioned backup after the device is clean.

Sources

  • CISA – StopRansomware.gov (2025)
  • FBI – Ransomware (2025)
  • Microsoft Security – What Is Ransomware? (2025)
Disclosure: This post may contain affiliate links which means I may receive a commission for purchases made through links. I will only recommend products that I have personally used! Learn more on my Private Policy page.
A thoughtful woman reads a newspaper while enjoying coffee at an indoor workspace.

DEALWEEK

SUBSCRIBE AND GET 20% OFF YOUR NEXT ORDER! OFFER ENDS SOON - DON’T MISS OUT!

We don’t spam! Read our privacy policy for more info.

Shopping Cart