Ransomware is malware that blocks access to data or systems, often through encryption, and demands payment. Some operators also steal data and threaten to publish it. Paying does not guarantee a working decryption key, deletion of stolen information, or protection from another demand.

How ransomware spreads

Common routes include phishing attachments, exposed remote services, stolen credentials, vulnerable software, and compromised suppliers. On personal devices, fake software and malicious downloads can also introduce ransomware or related extortion.

What to do during an incident

Disconnect affected devices from networks and shared storage to limit spread. Do not erase them before the organization’s security team or a qualified responder preserves evidence. Report work incidents immediately through the established channel.

Restore from clean, tested backups only after the entry point and malicious access have been addressed. Change compromised credentials and patch the affected systems.

U.S. victims can report incidents to the FBI Internet Crime Complaint Center and CISA. Organizations should also follow legal, insurance, contractual, and regulatory notification requirements that apply to them.

Reduce ransomware risk

Maintain offline or otherwise protected backups, update software, use multifactor authentication, restrict administrative access, and test recovery. Train staff to report suspicious messages without punishing quick disclosure.

Ransomware and a screen-lock scam are different

A browser pop-up may claim that a device is locked and demand a call or payment without encrypting files. Close the browser and seek trusted support. Real ransomware affects data or system access beyond a deceptive webpage.