Ransomware attacks work by locking or encrypting the files on your computer, then demanding payment to restore access. Even if you pay, there’s no guarantee you’ll get your files back — and by the time a ransom note appears on screen, the damage is often already done. The best defense is preparing before an attack happens, not reacting after one.
Security experts recommend starting by identifying what you’d be most upset to lose: family photos and videos, tax returns, medical and insurance records, passports or scanned IDs, mortgage or lease documents, wills, and financial statements. These are often scattered across Downloads, Desktop and Documents folders. Organizing them into clearly labeled folders — such as “Taxes,” “Medical,” “Home” and “Family Photos” — makes both backing them up and finding them later much easier.
The 3-2-1 Rule
A widely recommended backup strategy, known as 3-2-1, calls for keeping three copies of important data on two different types of storage, with at least one copy kept somewhere separate from your main device. For most households, that might mean the files on your computer, a regularly updated external hard drive, and a trusted cloud backup service.
One important caution: keep an external backup drive disconnected when it’s not in use. If it stays plugged into an infected computer, ransomware can spread to it as well. It’s also worth noting that cloud storage and cloud backup aren’t the same thing — a storage service may simply sync changes across devices, while a true backup service keeps separate copies or previous versions that can aid recovery.
Automatic backups are convenient, but they’re only useful if you can actually restore files from them. Periodically test your setup by restoring a few files to a different folder to catch problems before an emergency. Backup and cloud accounts should also be protected with strong, unique passwords and multifactor authentication, which requires a second form of verification beyond your password.
Check the date of your most recent successful backup — one that hasn’t run in months may be missing your newest photos or records — and review whether your service retains version history, which can help if files are accidentally deleted, overwritten or encrypted.
If Ransomware Strikes
Ransomware often arrives through a deceptive email, text, website, attachment or download. If files suddenly won’t open, extensions change, or a ransom message appears, act quickly:
- Disconnect the computer from Wi-Fi and unplug any Ethernet cable, and disconnect external drives if you safely can. Disconnecting is preferable to shutting the computer down, since powering off can erase information in memory that could help an investigation.
- Do not delete encrypted files or the ransom note — they may help identify the ransomware involved. Photograph any ransom message with another device.
- Do not open suspicious files, install recovery programs, or follow instructions in the ransom note without professional guidance.
The FBI does not support paying ransomware demands and recommends victims report incidents instead. For a personal computer, contact a security provider or a reputable computer-repair or cybersecurity professional, and report the incident to the FBI through the Internet Crime Complaint Center at IC3.gov or a local FBI field office. If the affected computer belongs to an employer, stop using it immediately and contact IT or security staff rather than attempting to fix it yourself.
Do not reconnect an external backup drive to an infected computer until it has been evaluated, cleaned or rebuilt — otherwise you risk exposing a good backup to the same ransomware. Once the computer is clean, you can restore from a backup made before the infection. Without a usable backup, recovery can be far more difficult; some ransomware variants have free decryption tools, but no universal tool recovers every encrypted file.
Security software with real-time protection, a firewall, and tools like password managers can add further layers of defense, but no product guarantees every threat will be stopped. That’s why experts recommend pairing software protection with safer online habits and a separate, tested backup.
Setting aside a few minutes each month to check backups, updates and account security can make a significant difference if ransomware ever strikes.




