Security

Ransomware

Malware that can encrypt or block access to data and demand payment; some attackers also steal data. An independent, tested backup supports recovery, but paying does not guarantee that data or access will be restored.

How it works

Ransomware attempts to deny access to a device or data and demands something in return for restoration. Some incidents also involve stolen information and threats of disclosure. File encryption is one mechanism, but a ransom message does not establish exactly what was changed or taken.

A practical example

Consider a shared folder that suddenly contains unreadable documents and a payment note. A connected backup may also be affected, while an isolated tested copy could support recovery. This example illustrates why a normal synchronized copy and an independently recoverable backup have different roles.

What to check

If an incident is suspected, stop ordinary use, preserve the warning and notify the responsible administrator or incident specialist. Follow their containment instructions before reconnecting devices or restoring files. Identify trusted backup versions and test recovery in a clean environment. Account compromise and possible data theft need their own assessment.

Limits and safe use

Payment does not guarantee restored access or removal of the infection. Do not experiment with unknown decryptors or erase the only evidence in haste. A recovery plan should cover essential services, clean equipment and verified backups; restoring a few files does not establish that the underlying intrusion has been resolved.

Technical sources

← All glossary terms