Ransomware is a type of malicious software that can prevent you from accessing files or systems. In some cases, criminals may also steal information and threaten to release it unless a payment is made.
While ransomware can be disruptive, there are practical steps you can take to reduce your risk and improve your ability to recover.
The most important protections are straightforward:
- Keep your devices and software updated.
- Use strong, unique passwords and multi-factor authentication.
- Be cautious with unexpected emails, text messages and attachments.
- Keep reliable backups of important information.
- Know what to do if you suspect a device has been compromised.
Understanding ransomware can help you respond calmly and make informed decisions.
What Is ransomware?
Ransomware is malware designed to restrict access to files, devices or systems, typically in an attempt to extort money from the victim.
Some ransomware encrypts files so they cannot be opened. Other forms may lock a device or system. Modern ransomware incidents can also involve data theft, where criminals copy sensitive information and threaten to publish or sell it. Ransomware can affect individuals, businesses and organizations of all sizes.
It can enter a device or network through several methods, including:
- Phishing emails
- Malicious links
- Malicious attachments
- Compromised websites
- Unpatched software
- Stolen passwords or credentials
- Infected downloads
- Compromised remote-access services
Ransomware continues to evolve, which is why using multiple layers of protection is important. The Canadian Centre for Cyber Security recommends measures such as software updates, multi-factor authentication, backups and protection against phishing.
How does ransomware work?
Ransomware generally begins when malicious software gains access to a device or network.
Once inside, the malware may:
- Access files or systems.
- Encrypt or restrict access to information.
- Display a ransom demand.
- In some cases, copy sensitive information.
- Demand payment in exchange for restoring access or not releasing stolen information.
Payment does not guarantee that your files will be restored or that stolen information will be deleted. The Canadian Centre for Cyber Security notes that paying a ransom does not necessarily result in recovery and does not eliminate the possibility that copies of stolen data remain with the attacker.
What are the common types of ransomware?
Ransomware can take different forms.
Locker ransomware
Locker ransomware restricts access to a device or system. Instead of being able to use the device normally, you may see a message explaining that access has been blocked and providing instructions for payment.
Crypto ransomware
Crypto ransomware encrypts files, making them inaccessible without an appropriate decryption method. You may notice that files can no longer be opened or that their file names or extensions have changed.
Data theft and extortion
Some modern ransomware incidents involve more than file encryption. A criminal may steal information before or during an attack and then threaten to release it publicly unless a payment is made. This means that having backups remains important, but backups alone may not address every consequence of a ransomware incident.
How can you tell if you have ransomware?
Signs of a ransomware infection can include:
- Files that suddenly cannot be opened
- Unexpected file-name or file-extension changes
- A message demanding payment
- Unusual activity on your device
- Programs or files behaving unexpectedly
- Access to systems or files suddenly being restricted
- Unexpected warnings about encrypted or stolen information
Not every unusual computer problem is ransomware. If something doesn't look right, avoid interacting with suspicious messages or files and seek assistance from a qualified technology or cybersecurity professional.
How does ransomware get onto a device?
Ransomware often relies on a person clicking, opening, downloading or installing something malicious, although technical vulnerabilities can also be exploited.
Phishing emails
A fraudulent email may encourage you to:
- Open an attachment
- Click a link
- Download a file
- Sign into an account
- Enable certain software features
- Provide login information
If you're not expecting a message, pause before interacting with it.
Malicious websites and downloads
Fraudulent websites and advertisements can direct you toward malicious downloads. Download software from reputable sources and avoid installing programs simply because a pop-up tells you that your device needs an urgent update or security scan.
Outdated software
Cybercriminals can exploit known vulnerabilities in outdated operating systems, applications and other software. Installing security updates can reduce exposure to known vulnerabilities.
Compromised passwords
If a criminal obtains a password, they may use it to access another account or system. Use a unique password or passphrase for each important account and enable multi-factor authentication whenever it is available.
How to protect yourself from ransomware
There is no single security measure that eliminates every risk. Instead, use several layers of protection.
1. Keep your devices and software updated
Install operating system, browser and application updates when they become available. Updates often include security fixes that address known vulnerabilities. Turn on automatic updates where appropriate. Keeping your software current is one of the simplest ways to reduce exposure to known security weaknesses.
2. Use strong, unique passwords
Don't reuse passwords across important accounts. If a password is compromised on one service, criminals may try the same credentials elsewhere. Use long, unique passwords or passphrases and consider using a reputable password manager.
3. Turn on multi-factor authentication
Multi-factor authentication adds another layer of protection beyond your password. If a criminal obtains your password, MFA can make it more difficult for them to access your account. Enable MFA on important accounts whenever it is available.
4. Be careful with emails and text messages
Before clicking a link or opening an attachment, consider:
Was I expecting this message?
Do I recognize the sender?
Does the request make sense?
Is the message creating unnecessary urgency?
Can I verify the request another way?
When in doubt, don't use the link or contact information provided in the suspicious message. Navigate to the organization's official website or app yourself.
5. Use security software
Keep reputable antivirus and anti-malware software enabled and up to date. Security software can provide another layer of protection against malicious files and programs. It should complement—not replace—good security habits.
6. Back up important information
Backups are one of the most important protections against ransomware. A backup is a separate copy of your files that can be restored if the originals become inaccessible.
Consider backing up important:
- Photos
- Documents
- Financial records
- Tax records
- School or work files
- Other information that would be difficult to replace
The Canadian Centre for Cyber Security recommends maintaining reliable backups and emphasizes that backups should be protected from ransomware. Offline backups can help prevent ransomware from accessing or encrypting the backup itself.
Test your backups
Having a backup isn't enough if you can't restore it. Periodically check that your important files have been backed up and that you can recover them. For especially important information, consider maintaining more than one backup and storing at least one copy separately from your primary device or network.
What should I do if I suspect ransomware?
If you think your device may have ransomware, don't panic and don't immediately start interacting with the ransom message. Your first priority should be limiting the spread and getting appropriate assistance.
1. Isolate the affected device
Disconnect the affected device from the internet and other networks. This can help prevent ransomware from spreading to other connected devices or systems. The Canadian Centre for Cyber Security recommends isolating affected devices and, where possible, avoiding powering them down immediately so evidence can be preserved for investigation. If you're unsure what to do, contact a qualified IT or cybersecurity professional.
2. Don't connect other devices
Avoid connecting external hard drives, USB drives, phones or other storage devices to a potentially infected computer. You don't want to risk transferring malware to another device or compromising a backup.
3. Don't delete evidence
If you believe you've experienced a cybercrime, keep relevant messages, ransom notes, suspicious emails and other information. This information may help cybersecurity professionals or authorities understand what happened.
4. Contact the appropriate professionals
Depending on the situation, contact:
- Your financial institution if banking or payment information may be involved
- A qualified IT or cybersecurity professional
- Your employer's IT or security team, if it's a work device
- Local law enforcement
- The Canadian Anti-Fraud Centre
The Canadian Centre for Cyber Security recommends reporting ransomware incidents to local police and the Canadian Anti-Fraud Centre.
5. Change passwords when appropriate
If your device or accounts may have been compromised, change affected passwords using a device you believe is secure. Don't reuse compromised passwords on other accounts. If you're working with a cybersecurity professional, follow their guidance about when and how to reset credentials.
6. Restore from a clean backup
If a reliable backup is available, it may allow you to restore your files without relying on the attacker to provide access. Before restoring data, make sure the device has been properly cleaned and secured. The Canadian Centre for Cyber Security recommends ensuring backups are clean and free of malware before using them to restore systems.
Should you pay a ransom?
There is no simple answer that applies to every situation.
Paying a ransom does not guarantee that you will regain access to your files or that stolen information will be deleted.
The Canadian Centre for Cyber Security notes that even when files are recovered, a data breach may still have occurred and copies of information may remain with the attackers. If you are affected by ransomware, consider getting professional cybersecurity advice before making decisions about payment.
For individuals, the priority should generally be to isolate the affected device, preserve information that may be useful for an investigation, seek professional assistance and determine whether clean backups can be used for recovery.
The PREVENT ransomware checklist
The original article's PREVENT acronym is worth keeping, but we can update it so each letter represents a practical action.
P — Patch regularly
Install operating system, application and security updates promptly.
R — Review before you click
Verify unexpected emails, texts, links and attachments before interacting with them.
E — Enable MFA
Turn on multi-factor authentication for important accounts.
V — Verify software and downloads
Only install software from reputable sources and be cautious with unexpected downloads or pop-ups.
E — Ensure you have backups
Regularly back up important information and keep at least one backup protected from your primary device or network.
N — Never reuse important passwords
Use unique passwords or passphrases for important accounts.
T — Take action if something seems wrong
If your device behaves unexpectedly or you believe you've encountered ransomware, stop and seek appropriate assistance.
Why backups matter
A good backup strategy can make a significant difference if ransomware affects your files. Think of your backup as a spare copy that you can use when the original is unavailable. For important information, consider the following approach:
Back up regularly.
Keep multiple copies when practical.
Store at least one copy separately from your primary device or network.
Protect your backups with appropriate security controls.
Test that your backups can actually be restored.
The Canadian Centre for Cyber Security recommends protecting backups from ransomware by keeping copies offline and testing backup and recovery processes regularly.
Ransomware doesn't have to be a mystery
Ransomware can be disruptive, but understanding how it works can help you prepare. You don't need to predict every type of cyberattack. Focus on the basics:
Keep your software updated.
Use unique passwords.
Enable multi-factor authentication.
Be cautious with unexpected messages and downloads.
Back up important information.
Know who to contact if something goes wrong.
Good cybersecurity is about building layers of protection and having a plan for recovery—not trying to achieve perfect security.
Frequently asked questions about ransomware
What is ransomware?
Ransomware is a type of malware that can restrict access to files, devices or systems. Criminals may demand payment to restore access or, in some cases, threaten to release stolen information.
How does ransomware get onto a computer?
Ransomware can reach a computer through phishing emails, malicious links or attachments, infected downloads, compromised websites, stolen credentials and vulnerabilities in outdated software.
Can ransomware affect a phone?
Yes. Ransomware and other forms of malware can affect mobile devices, although the specific risks and methods vary depending on the device and operating system. Keeping your phone updated, downloading apps from reputable sources and using strong authentication can help reduce risk.
How can I prevent ransomware?
Use multiple layers of protection. Keep software updated, use unique passwords, enable multi-factor authentication, use reputable security software, be cautious with unexpected messages and maintain reliable backups.
Are backups enough to protect against ransomware?
Backups can significantly improve your ability to recover, but they aren't a complete security solution. Backups should be protected from ransomware and tested regularly to make sure they can be restored.
Should I pay a ransomware demand?
Paying a ransom does not guarantee that you'll regain access to your files or that stolen information will be deleted. If you experience ransomware, consider seeking professional cybersecurity assistance before making decisions about payment.
What should I do if I think my computer has ransomware?
Disconnect the affected device from networks to help prevent the ransomware from spreading. Avoid connecting other devices or storage media, preserve relevant information and seek assistance from a qualified IT or cybersecurity professional. Current Canadian Cyber Centre guidance recommends isolating the affected device and, where possible, not immediately powering it down so evidence can be preserved.
Can I recover files after a ransomware attack?
Possibly. Recovery depends on the type of ransomware, whether a decryption method is available and whether you have a clean, usable backup. A reliable backup can provide an alternative way to recover files without relying on the attacker.
Does antivirus software prevent ransomware?
Security software can help detect and block some malicious software, but it isn't a complete solution. Use security software alongside software updates, MFA, strong passwords, careful browsing and reliable backups.
Who should I contact if I experience ransomware in Canada?
Depending on the circumstances, contact your financial institution if financial information is involved, a qualified cybersecurity professional or IT team, local law enforcement and the Canadian Anti-Fraud Centre.
YNCU members: We're here to help
If you are a YNCU member and believe your banking information, credentials or account may have been compromised as part of a ransomware incident or another cyber scam, contact YNCU as soon as possible.
YNCU Service Excellence Centre:
1-888-413-YNCU (9628)
You can also report suspected fraud to the Canadian Anti-Fraud Centre. The goal of good online security isn't to live in fear of every message, download or website. It's to build a few reliable habits that make it easier to prevent problems and recover when something unexpected happens.
Stay informed. Stay prepared. Back up what matters.



