What Is Ransomware and How to Protect Yourself
Ransomware is malware that encrypts your files (and sometimes steals a copy) and demands payment for a key or silence. Protect yourself with offline / immutable backups, fast patching, MFA, careful email and macros, least privilege, and a written restore drill — not with payment as plan A.
Friends, files locked, wallpaper changed, "Pay Bitcoin" — that is ransomware. Do not panic, but you need a plan. Paying often still fails to get a key — recovery is unreliable. Today we learn the protection checklist in vertical order.
मित्रांनो, laptop वर फायली कुलूपबंद, वॉलपेपर बदलला, "Pay Bitcoin" – हे ransomware. घाबरू नका, पण योजना हवी. पैसे पाठवले तरी चावी मिळेलच असे नाही – आकडेवारीत पुनर्प्राप्ती अविश्वसनीय. आज संरक्षण यादी उभ्या क्रमाने शिकूया.
मित्रों, कंप्यूटर पर फ़ाइलें ताला बंद, वॉलपेपर बदला, "Pay Bitcoin" – यह ransomware. घबराओ मत, पर योजना ज़रूरी है. पैसे भेजने पर भी चाबी मिले यह तय नहीं – आँकड़ों में वापसी अविश्वसनीय. आज सुरक्षा सूची ऊर्ध्व क्रम में सीखेंगे.
Quick answer
Defence in layers (do these in order):
- Keep an offline or immutable backup you have restored at least once.
- Turn on automatic OS and browser updates; patch VPN and remote-access tools quickly.
- Enable MFA on email, VPN, Microsoft 365 / Google Workspace and cloud consoles.
- Do not enable macros or run unexpected installers from email.
- Use a standard (non-admin) account for daily work.
- Segment backups and admin work from everyday browsing where you can.
- If hit: disconnect, keep evidence, restore from clean backup — do not pay as the default plan.
Personal / small-team baseline:
Backup: 3 copies, 2 media, 1 offline (3-2-1 idea)
Update: OS + browser + office suite weekly (auto is fine)
Identity: MFA on mail + cloud + banking
Habit: no mystery macros / cracked software
Drill: restore one folder from backup this month
What do I need before this guide?
- A device you control (Windows, macOS or Linux).
- Somewhere to store backups (external drive, reputable cloud backup with versioning).
- Optional: read What is phishing and how to spot it first — email is still a top delivery path.
How does ransomware usually arrive?
Backups, updates, MFA and email caution stack as layers. If one control fails, another still helps you restore without paying.
बॅकअप, update, MFA आणि ईमेल सावधगिरी थर थर बसतात. एक उपाय अपयशी झाला तरी दुसरा पैसे न देता फायली परत आणायला मदत करतो.
बैकअप, अपडेट, MFA और ईमेल सावधानी परत दर परत हैं. एक उपाय असफल हो तो भी दूसरा बिना पैसे दिए फ़ाइलें वापस लाने में मदद करता है.
Common delivery paths (high level, for defence):
- Phishing email with a malicious attachment or link.
- Stolen remote-desktop or VPN credentials without MFA.
- Unpatched public service (old VPN appliance, gateway, CMS plugin).
- Infected USB or pirated software installer.
- Secondary spread inside a network from one compromised PC.
You do not need exploit details to defend — you need to cut delivery and survive encryption with backups.
How do I protect myself step by step?
Step 1 — Backups you can actually restore
- Pick what matters (Documents, photos, mail export, project repos).
- Keep at least one copy that ransomware cannot reach online (external drive unplugged after backup, or immutable / object-lock cloud versioning).
- Turn on version history where available.
- This month, restore one test folder and open a file — an untested backup is a wish, not a control.
Step 2 — Updates and remote access
- Enable automatic updates for the OS and browser.
- Patch office suites and PDF readers promptly.
- If you use remote desktop or VPN, put MFA in front and keep the gateway patched.
- Disable remote desktop on machines that do not need it.
Step 3 — Identity and least privilege
- Enable MFA on email and cloud (see MFA guide).
- Daily work on a standard user account; use admin only when installing software.
- Unique passwords in a password manager — reused passwords turn one breach into many.
Step 4 — Email and macros
- Treat unexpected invoices and “enable content” prompts as hostile until proven otherwise.
- Prefer official share links over random attachments when a vendor asks you to review a file.
- Report phishing; do not forward the lure to friends “for fun”.
Step 5 — If you suspect ransomware right now
- Disconnect the device from Wi-Fi / cable (contain).
- Do not wipe yet if you need evidence for insurance / law enforcement / IT.
- From a clean device, change important passwords (email first).
- Call your IT / provider / a trusted professional; for US personal cases, CISA and local FBI IC3 guidance are public starting points.
- Restore from a backup taken before infection; verify the backup is clean.
- Paying the ransom is discouraged by most public agencies — it funds crime and often fails.
Ravindra Bagale's Tip
💡 Many students keep the backup folder on the same laptop — ransomware encrypts that folder too. Keep backups offline or with versioning/immutable storage. Run a restore drill at least once. "I have a backup" is not enough; "I restored successfully" is. Never forget!
Ravindra Bagale's Tip – मराठी
💡 खूप students backup folder laptop वरच ठेवतात – ransomware त्या folder लाही encrypt करतो. Backup offline किंवा versioning/immutable हवा. Restore drill एकदा तरी करा. "Backup आहे" म्हणजे नाही; "restore केलं" म्हणजे हो. बिल्कुल विसरू नका!
Ravindra Bagale's Tip – हिंदी
💡 बहुत students backup folder उसी laptop पर रखते हैं – ransomware उस folder को भी encrypt कर देता है. Backup offline या versioning/immutable रखो. Restore drill कम से कम एक बार करो. "Backup है" काफी नहीं; "restore किया" मतलब हाँ. बिल्कुल मत भूलना!
How do I fix common ransomware protection gaps?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Files encrypted, ransom note | Malware ran with your user rights | Disconnect; restore from offline / older version; reset credentials from a clean device |
| Backup also encrypted | Backup was always online on the same PC | Add offline / immutable copy; separate credentials for backup |
| Company hit via one VPN account | No MFA + shared password | Enforce MFA; rotate passwords; review VPN logs |
| “Cracked” software installed | Trojanised installer | Reimage; only use licensed software |
| Macros enabled globally | Convenience over safety | Disable macros by default; enable only for trusted, signed docs |
Try it at home
Write a one-page personal plan with exactly these lines filled in:
- Where is my offline / versioned backup?
- Date of last successful restore test:
- Which accounts have MFA today?
- Who do I call at work / family if files lock?
Learn it properly
Got it? Ransomware = locked files + pressure to pay. Your real shield: offline backup, updates, MFA, no macros, least privilege. Paying is not escape — a restore drill is. Also see the MFA guide.
समजलं का? ransomware म्हणजे फायली कुलूपबंद आणि पैसे भरायचा दबाव. खरा ढाल: ऑफलाइन बॅकअप, update, MFA, मॅक्रो नको, किमान अधिकार. पैसे देऊन सुटका नाही – पुनर्स्थापना सराव हवा. MFA मार्गदर्शकही बघा.
समझ में आया? ransomware यानी फ़ाइलें ताला बंद और पैसे का दबाव. असली ढाल: ऑफ़लाइन बैकअप, अपडेट, MFA, मैक्रो नहीं, कम अधिकार. पैसे देकर छुटकारा नहीं – पुनर्स्थापना अभ्यास ज़रूरी. MFA गाइड भी देखो.
Frequently asked questions
What is ransomware?
Malware that encrypts files (and sometimes steals a copy) and demands payment for a key or silence.
What is the best personal defence?
A backup the malware cannot reach, plus updates, MFA and careful email habits — verified with a restore drill.
Should I pay the ransom?
Public agencies generally discourage paying. It funds crime and often fails. Prefer clean backups and professional help.
Why did my backup get encrypted too?
It was probably always online on the same computer. Add an offline or immutable copy with separate access.
How does ransomware usually arrive?
Phishing, stolen remote-access passwords without MFA, unpatched gateways or trojanised installers.
What should I do in the first hour?
Disconnect the device, avoid panic wiping if evidence matters, change email passwords from a clean device and start restore planning.