Ransomware is a type of malicious software that can prevent you from accessing files or systems. In some cases, criminals may also steal information and threaten to release it unless a payment is made.
While ransomware can be disruptive, there are practical steps you can take to reduce your risk and improve your ability to recover.
The most important protections are straightforward:
Understanding ransomware can help you respond calmly and make informed decisions.
Ransomware is malware designed to restrict access to files, devices or systems, typically in an attempt to extort money from the victim.
Some ransomware encrypts files so they cannot be opened. Other forms may lock a device or system. Modern ransomware incidents can also involve data theft, where criminals copy sensitive information and threaten to publish or sell it. Ransomware can affect individuals, businesses and organizations of all sizes.
It can enter a device or network through several methods, including:
Ransomware continues to evolve, which is why using multiple layers of protection is important. The Canadian Centre for Cyber Security recommends measures such as software updates, multi-factor authentication, backups and protection against phishing.
Ransomware generally begins when malicious software gains access to a device or network.
Once inside, the malware may:
Payment does not guarantee that your files will be restored or that stolen information will be deleted. The Canadian Centre for Cyber Security notes that paying a ransom does not necessarily result in recovery and does not eliminate the possibility that copies of stolen data remain with the attacker.
Ransomware can take different forms.
Locker ransomware restricts access to a device or system. Instead of being able to use the device normally, you may see a message explaining that access has been blocked and providing instructions for payment.
Crypto ransomware encrypts files, making them inaccessible without an appropriate decryption method. You may notice that files can no longer be opened or that their file names or extensions have changed.
Some modern ransomware incidents involve more than file encryption. A criminal may steal information before or during an attack and then threaten to release it publicly unless a payment is made. This means that having backups remains important, but backups alone may not address every consequence of a ransomware incident.
Signs of a ransomware infection can include:
Not every unusual computer problem is ransomware. If something doesn't look right, avoid interacting with suspicious messages or files and seek assistance from a qualified technology or cybersecurity professional.
Ransomware often relies on a person clicking, opening, downloading or installing something malicious, although technical vulnerabilities can also be exploited.
A fraudulent email may encourage you to:
If you're not expecting a message, pause before interacting with it.
Fraudulent websites and advertisements can direct you toward malicious downloads. Download software from reputable sources and avoid installing programs simply because a pop-up tells you that your device needs an urgent update or security scan.
Cybercriminals can exploit known vulnerabilities in outdated operating systems, applications and other software. Installing security updates can reduce exposure to known vulnerabilities.
If a criminal obtains a password, they may use it to access another account or system. Use a unique password or passphrase for each important account and enable multi-factor authentication whenever it is available.
There is no single security measure that eliminates every risk. Instead, use several layers of protection.
Install operating system, browser and application updates when they become available. Updates often include security fixes that address known vulnerabilities. Turn on automatic updates where appropriate. Keeping your software current is one of the simplest ways to reduce exposure to known security weaknesses.
Don't reuse passwords across important accounts. If a password is compromised on one service, criminals may try the same credentials elsewhere. Use long, unique passwords or passphrases and consider using a reputable password manager.
Multi-factor authentication adds another layer of protection beyond your password. If a criminal obtains your password, MFA can make it more difficult for them to access your account. Enable MFA on important accounts whenever it is available.
Before clicking a link or opening an attachment, consider:
Was I expecting this message?
Do I recognize the sender?
Does the request make sense?
Is the message creating unnecessary urgency?
Can I verify the request another way?
When in doubt, don't use the link or contact information provided in the suspicious message. Navigate to the organization's official website or app yourself.
Keep reputable antivirus and anti-malware software enabled and up to date. Security software can provide another layer of protection against malicious files and programs. It should complement—not replace—good security habits.
Backups are one of the most important protections against ransomware. A backup is a separate copy of your files that can be restored if the originals become inaccessible.
Consider backing up important:
The Canadian Centre for Cyber Security recommends maintaining reliable backups and emphasizes that backups should be protected from ransomware. Offline backups can help prevent ransomware from accessing or encrypting the backup itself.
Having a backup isn't enough if you can't restore it. Periodically check that your important files have been backed up and that you can recover them. For especially important information, consider maintaining more than one backup and storing at least one copy separately from your primary device or network.
If you think your device may have ransomware, don't panic and don't immediately start interacting with the ransom message. Your first priority should be limiting the spread and getting appropriate assistance.
Disconnect the affected device from the internet and other networks. This can help prevent ransomware from spreading to other connected devices or systems. The Canadian Centre for Cyber Security recommends isolating affected devices and, where possible, avoiding powering them down immediately so evidence can be preserved for investigation. If you're unsure what to do, contact a qualified IT or cybersecurity professional.
Avoid connecting external hard drives, USB drives, phones or other storage devices to a potentially infected computer. You don't want to risk transferring malware to another device or compromising a backup.
If you believe you've experienced a cybercrime, keep relevant messages, ransom notes, suspicious emails and other information. This information may help cybersecurity professionals or authorities understand what happened.
Depending on the situation, contact:
The Canadian Centre for Cyber Security recommends reporting ransomware incidents to local police and the Canadian Anti-Fraud Centre.
If your device or accounts may have been compromised, change affected passwords using a device you believe is secure. Don't reuse compromised passwords on other accounts. If you're working with a cybersecurity professional, follow their guidance about when and how to reset credentials.
If a reliable backup is available, it may allow you to restore your files without relying on the attacker to provide access. Before restoring data, make sure the device has been properly cleaned and secured. The Canadian Centre for Cyber Security recommends ensuring backups are clean and free of malware before using them to restore systems.
There is no simple answer that applies to every situation.
Paying a ransom does not guarantee that you will regain access to your files or that stolen information will be deleted.
The Canadian Centre for Cyber Security notes that even when files are recovered, a data breach may still have occurred and copies of information may remain with the attackers. If you are affected by ransomware, consider getting professional cybersecurity advice before making decisions about payment.
For individuals, the priority should generally be to isolate the affected device, preserve information that may be useful for an investigation, seek professional assistance and determine whether clean backups can be used for recovery.
The original article's PREVENT acronym is worth keeping, but we can update it so each letter represents a practical action.
Install operating system, application and security updates promptly.
Verify unexpected emails, texts, links and attachments before interacting with them.
Turn on multi-factor authentication for important accounts.
Only install software from reputable sources and be cautious with unexpected downloads or pop-ups.
Regularly back up important information and keep at least one backup protected from your primary device or network.
Use unique passwords or passphrases for important accounts.
If your device behaves unexpectedly or you believe you've encountered ransomware, stop and seek appropriate assistance.
A good backup strategy can make a significant difference if ransomware affects your files. Think of your backup as a spare copy that you can use when the original is unavailable. For important information, consider the following approach:
Back up regularly.
Keep multiple copies when practical.
Store at least one copy separately from your primary device or network.
Protect your backups with appropriate security controls.
Test that your backups can actually be restored.
The Canadian Centre for Cyber Security recommends protecting backups from ransomware by keeping copies offline and testing backup and recovery processes regularly.
Ransomware can be disruptive, but understanding how it works can help you prepare. You don't need to predict every type of cyberattack. Focus on the basics:
Keep your software updated.
Use unique passwords.
Enable multi-factor authentication.
Be cautious with unexpected messages and downloads.
Back up important information.
Know who to contact if something goes wrong.
Good cybersecurity is about building layers of protection and having a plan for recovery—not trying to achieve perfect security.
Ransomware is a type of malware that can restrict access to files, devices or systems. Criminals may demand payment to restore access or, in some cases, threaten to release stolen information.
Ransomware can reach a computer through phishing emails, malicious links or attachments, infected downloads, compromised websites, stolen credentials and vulnerabilities in outdated software.
Yes. Ransomware and other forms of malware can affect mobile devices, although the specific risks and methods vary depending on the device and operating system. Keeping your phone updated, downloading apps from reputable sources and using strong authentication can help reduce risk.
Use multiple layers of protection. Keep software updated, use unique passwords, enable multi-factor authentication, use reputable security software, be cautious with unexpected messages and maintain reliable backups.
Backups can significantly improve your ability to recover, but they aren't a complete security solution. Backups should be protected from ransomware and tested regularly to make sure they can be restored.
Paying a ransom does not guarantee that you'll regain access to your files or that stolen information will be deleted. If you experience ransomware, consider seeking professional cybersecurity assistance before making decisions about payment.
Disconnect the affected device from networks to help prevent the ransomware from spreading. Avoid connecting other devices or storage media, preserve relevant information and seek assistance from a qualified IT or cybersecurity professional. Current Canadian Cyber Centre guidance recommends isolating the affected device and, where possible, not immediately powering it down so evidence can be preserved.
Possibly. Recovery depends on the type of ransomware, whether a decryption method is available and whether you have a clean, usable backup. A reliable backup can provide an alternative way to recover files without relying on the attacker.
Security software can help detect and block some malicious software, but it isn't a complete solution. Use security software alongside software updates, MFA, strong passwords, careful browsing and reliable backups.
Depending on the circumstances, contact your financial institution if financial information is involved, a qualified cybersecurity professional or IT team, local law enforcement and the Canadian Anti-Fraud Centre.
If you are a YNCU member and believe your banking information, credentials or account may have been compromised as part of a ransomware incident or another cyber scam, contact YNCU as soon as possible.
YNCU Service Excellence Centre:
1-888-413-YNCU (9628)
You can also report suspected fraud to the Canadian Anti-Fraud Centre. The goal of good online security isn't to live in fear of every message, download or website. It's to build a few reliable habits that make it easier to prevent problems and recover when something unexpected happens.
Stay informed. Stay prepared. Back up what matters.