VPN Guide
What Is Ransomware?
Ransomware is malware that encrypts your files (or locks your screen) and demands payment — usually in cryptocurrency — for the decryption key. It has evolved from a nuisance against home users in the early 2010s into one of the most damaging cyber threats targeting hospitals, schools, municipalities, and businesses. Knowing how it spreads and how to recover without paying is essential.
Editorial shortlist
Need a VPN recommendation now?
Skip the theory — compare our top-rated VPNs for US users, with pricing, privacy notes, and setup guides.
See all VPN reviewsCompare providersHow Ransomware Works
A typical ransomware attack follows this pattern:
- Initial access — usually phishing email, exploited remote-desktop service, or compromised software supply chain.
- Privilege escalation — the malware gains admin rights.
- Lateral movement — on networks, it spreads to other machines and file shares.
- Data exfiltration (modern variants) — sensitive data is copied off before encryption, used as additional extortion leverage ('double extortion').
- Encryption — files are encrypted with a strong cipher; only the attacker has the decryption key.
- Ransom note — a text file or full-screen message demanding payment.
In 2024–2025, double extortion became the norm. Even if you restore from backup, attackers threaten to publish stolen data.
Famous Ransomware Examples
WannaCry (2017) — exploited a Windows SMB vulnerability, affected 200,000+ machines including the UK's NHS.
NotPetya (2017) — initially looked like ransomware but was actually destructive wiper malware; estimated billions of dollars in damages.
Colonial Pipeline (2021) — DarkSide ransomware shut down the largest fuel pipeline on the U.S. East Coast for six days.
LockBit, BlackCat/ALPHV, Royal — major ransomware-as-a-service operations active through 2024–2025; multiple have been disrupted by international law enforcement actions but successors continue to emerge.
What to Do If You're Hit
- Isolate the device — disconnect from Wi-Fi, Ethernet, and any external drives immediately.
- Don't pay the ransom yet — payment doesn't refund policy recovery, funds criminal operations, and may violate U.S. OFAC sanctions if the actor is on the sanctions list.
- Check for a free decryptor at No More Ransom — a joint project by Europol and security vendors. Many ransomware families have free decryption tools available.
- Restore from backup if you have one (the only reliable path).
- Report it — file a report with the FBI's IC3 and your local law enforcement.
- Wipe and reinstall the affected device. Don't trust 'cleaning' a previously-infected machine.
Backup Strategy: The 3-2-1 Rule
The single best ransomware defense is good backups. Follow the 3-2-1 rule:
- 3 copies of your data (the original plus two backups)
- 2 different media (e.g., external drive + cloud)
- 1 off-site copy that's not always connected
The 'not always connected' part is critical — modern ransomware looks for backup volumes and network shares to encrypt those too. Use a cloud backup service with versioning (Backblaze, iDrive) or rotate offline external drives. Test restores periodically; an untested backup is no backup at all.
How to Reduce Your Risk
- Apply OS and browser updates promptly — most ransomware exploits patched vulnerabilities.
- Don't click suspicious links or attachments — see our phishing guide.
- Run a reputable antivirus with ransomware behavior detection (Bitdefender, Defender, Norton — see best antivirus for Windows).
- Disable Office macros unless you specifically need them.
- Use a password manager and 2FA to prevent account takeovers.
- For remote work: use a VPN with strong encryption when connecting to corporate resources, and disable RDP exposed to the internet.
Frequently Asked Questions
Continue comparing
Full reviews
Reviewed Sep 2026 · Public-source research · First-party tests appear on review pages when dated results are published · Verify details on provider sites. Editorial policy & scoring