What Is Ransomware? How It Locks Files and Spreads

September 30, 2026

Metal chain and padlock wrapped around a light gray computer keyboard

Photo: pixabay · PIXABAY

Published 4 min read

Ransomware is malicious software that encrypts the files on a computer or network so they cannot be opened, then demands a payment in exchange for the key that unlocks them. Many attackers also copy the data before locking it and threaten to leak it, which adds a second kind of pressure.

How ransomware turns your files into gibberish

Encryption scrambles data so that only someone holding the right key can turn it back into a readable document, photo or database. It is the same technology that protects online banking, turned against the owner. The federal Cybersecurity and Infrastructure Security Agency (CISA) describes ransomware as malware designed to encrypt files on a device, making those files and the systems that rely on them unusable.

Once it runs, the program works through documents, spreadsheets, photos and sometimes whole servers, locking each one. Filenames may change, and a ransom note appears on screen or in every folder with payment instructions, usually in cryptocurrency and often with a deadline. The attacker holds the only copy of the key. Without it, or without a clean backup, the files stay locked.

Opened hard drive showing the silver platter and read arm on a pale green background
Photo by JasonPinaster via Pixabay (PIXABAY)

Stolen data as a second threat

Early ransomware only locked files. Victims who had good backups could restore their data and ignore the demand, so criminal groups changed tactics. CISA notes that attackers now often threaten to sell or leak stolen data or login details if the ransom is not paid.

This is sometimes called double extortion. The attackers quietly copy sensitive files, such as customer records, tax documents or medical information, before they trigger the encryption. A backup can bring the files back, but it cannot undo the theft. That shift is why ransomware now hits businesses, hospitals, schools and local governments so hard, and why a home user’s scanned IDs and financial paperwork deserve protecting too.

Common ways ransomware gets onto a computer

  1. Phishing emails with a harmful attachment or a link to a fake login page.
  2. Software and devices that have not been updated, leaving known security holes open to the internet.
  3. Weak, reused or stolen passwords for remote access tools and online accounts.
  4. Pirated software, fake updates and downloads from untrustworthy sites.
  5. An earlier infection by other malware that opens the door for ransomware later.

Most of these need a person to click, open or reuse something, which is why caution and updates stop so many attacks before they start.

Backups and habits that blunt a ransomware attack

Defense What it protects against How to do it at home
Offline backups Losing locked files for good Copy files to an external drive and unplug it afterward
Testing backups Discovering too late that the backup failed Restore a few files now and then to check
Automatic updates Attacks through known security holes Turn on updates for the operating system, browser and apps
Two factor sign in Stolen or guessed passwords Enable it on email, banking and cloud storage
Care with attachments Phishing Verify unexpected files with the sender another way

CISA’s guidance stresses offline, encrypted backups that are tested regularly. A backup drive that stays plugged in can be encrypted right along with everything else. Cloud storage that keeps older versions of files can also help, because you may be able to roll a document back to the copy saved before the attack.

What to do if a ransom note appears

Disconnect the affected computer from the internet and from any shared network right away, to stop the malware from reaching other machines or backups. Do not delete the note or wipe the computer yet, since investigators may need details from it. Take photos of the screen and write down what happened.

Report the attack. CISA advises victims to report ransomware to federal law enforcement through the FBI’s Internet Crime Complaint Center, known as IC3, or to a Secret Service field office. Paying is risky. Nothing obliges a criminal to hand over a working key or delete stolen data. If business or client data is involved, bring in an IT security professional and check with a lawyer about any notification duties.

Frequently asked questions

Can ransomware infect a phone?

Yes, although it is less common than on computers. Phone ransomware usually arrives through apps installed from outside official app stores or through malicious links. Some versions lock the screen rather than encrypting files. Installing apps only from official stores and keeping the phone updated lowers the risk considerably.

Can you remove ransomware without paying?

Security software can often remove the ransomware program itself, but that does not unlock files it already encrypted. Recovery usually depends on restoring from a clean backup. For some older strains, security researchers have released free decryption tools, so an IT professional may be able to check whether one exists.

Does antivirus stop ransomware?

Up to date security software catches many known ransomware strains and suspicious behavior, so it helps. It is not a complete defense, because new variants appear and many attacks start with stolen passwords or unpatched devices. Combine it with updates, two factor sign in and offline backups for real protection.

How does ransomware spread through a network?

After one computer is infected, attackers look for other machines and shared folders they can reach. CISA says ransomware actors often use stolen passwords, Windows file sharing known as SMB and Remote Desktop to move from system to system. Unpatched software and a network with no segmentation make that spread easier.

How did the WannaCry ransomware attack spread?

It spread through a flaw in SMBv1, an older version of Windows file sharing. According to CISA, WannaCry surfaced on May 12, 2017 and moved rapidly by exploiting that weakness, which Microsoft had patched on March 14, 2017. Computers that had not installed the update were the ones exposed.

Related reading