It is the one type of attack an antivirus cannot handle on its own. What actually protects you is a backup it cannot reach.
Ransomware encrypts your files and demands payment for the key. The encryption is mathematically irreversible without that key: no software will break it. That reality governs the whole protection strategy - you do not bet on detection, you bet on being able to start again.
Most people think they are protected because they have an external disk. But ransomware does not stop at the infected machine: it methodically looks for everything within reach - connected external disks, network shares, mapped drives, and synced cloud storage.
An external disk left permanently plugged in will therefore be encrypted along with everything else. It is the most widespread mistake, and the most expensive. The rule is simple: a backup that protects against ransomware is a backup ransomware cannot reach - so unplugged, or with an unalterable version history.
OneDrive, Google Drive and business products keep earlier versions of every file. Even if the encrypted version has been synced, the clean version is often still restorable for several weeks. Many people give up before checking this, when it is frequently what saves the situation. We always look into it.
Three routes dominate, and none is very technical. The attachment on a message that looks legitimate - an invoice, a purchase order, a summons - asking you to enable macros. Software downloaded from a file-sharing site, particularly so-called “cracked” versions, which are a favored route. And badly protected remote access, in a business: a remote-control service open to the internet with a weak password is attacked automatically, continuously.
We always check that last point with business customers, because it is common and invisible to the user.
What to do changes completely. Unplug the network to stop it spreading, unplug external disks before they are hit, then switch off.
Do not pay: nothing guarantees a working key will be handed over, some victims who pay recover nothing, and paying marks you out as good for the money next time. Do not reformat anything either: the ransom message and the extension added to the files make it possible to identify the family, and free decryption tools exist for several of them, published after the networks behind them were dismantled.
Our article on encrypted files and a ransom demand sets out what to do step by step.
A scheduled backup that always overwrites the previous one poses a particular problem against ransomware: if the encryption goes unnoticed for a few days, the clean backup has been replaced by a backup of files that are already encrypted. You then discover, at the moment of restoring, that nothing usable is left.
That is why we favor arrangements that keep several generations - a rotation across several media, or an online product with history. The extra cost is small, and it is exactly what makes the difference on the day it counts.
Filing a police report is possible and advisable as soon as there is a loss: insurers often ask for one and it feeds ongoing investigations. For a business handling customers' personal data, a notification to the data protection authority may be compulsory within a short deadline - something to check quickly, and which we always flag to you.
The machine has to be cleanly reinstalled: a clean-up is not enough when an attacker has had that level of access. Then comes the real lesson, the one we insist on - the backup. See business backup and our article on how to back up your data.
No. It blocks known variants, but new ones get through. The only genuinely reliable protection is a backup the program cannot reach.
The authorities unanimously advise against it, and for practical reasons: nothing guarantees the key, paying funds the activity and marks you out as a target good for the money next time.
Not necessarily. Syncing may have propagated the encrypted versions, but version history often allows a return to a clean version. It is the first avenue to explore.
Yes, and increasingly so: the attacks are automated and do not choose their targets. A badly protected small business is easier to reach than a large group.
Can't find your question? It may be in our full FAQ.
Everything worth knowing before you hand over your equipment.
278 questions on breakdowns, security, networking and backup.
What the households and businesses we work with have to say.
Lyon, Villeurbanne, Caluire, Tassin, Écully and the whole Rhône.
Describe your problem: we reply with an initial assessment.
We test the restore in front of you: it is the only check worth anything.
Automatic assistant: it can make mistakes. Never share a password or a card number.