Home / Ciberseguridad / Ransomware: the digital kidnapping that encrypts your files and demands a ransom

Ransomware: the digital kidnapping that encrypts your files and demands a ransom

Ilustración de un ataque ransomware que cifra archivos en un ordenador

Imagine that one day you turn on your computer and, instead of your desktop, a red screen appears: all your files have been encrypted and, to recover them, you must pay a ransom in cryptocurrencies. It is not a hacker movie: it is a real scam called ransomware, and every year it claims millions of victims around the world, from families to large hospitals.

What exactly is ransomware?

The word comes from English: ransom means rescate and software means programme. A ransomware is a malicious programme that gets into your computer, encrypts your files —turns them into a code you can no longer read— and demands money in exchange for the key to unlock them.

The most dangerous thing is that it does not act in full view of everyone: it can install itself silently and wait for weeks, copying information and spreading across the network, until it decides to strike. When it does, it is already too late: the company or the person is left without access to photos, documents or databases.

How do they manage to get in?

The entry point is almost always a person. The most common method is phishing: an email that looks legitimate —from your bank, a courier company or your boss— with a link or an attachment. A single click is enough for the programme to download.

They also get in through unupdated software. Operating systems and applications constantly publish security patches: if you do not install them, you leave a window open. And in companies, a server failure or a weak password can be enough for the attacker to get straight in.

Why do they demand payment in cryptocurrencies?

Because they are hard to trace. The ransom is usually demanded in bitcoins or other digital currencies, which makes it difficult to follow the trail of the money and the criminals. In addition, the groups that organise these attacks operate almost like companies, with technical support for victims who are hesitant to pay.

Experts recommend not giving in: paying does not guarantee that you will recover your files and, moreover, it finances more attacks. Many victims who pay never see their data again, and others discover that the criminals had taken it before encrypting it.

The best defence: the backup copy

If something cannot be kidnapped, the ransom loses its power. That is why the most effective measure is to have backup copies of your important files on an external drive or in the cloud, disconnected from the main computer. If you are attacked, you restore and that is it, without paying a cent.

Along with that, a bit of digital hygiene goes a long way: keeping software updated, using different and robust passwords for each service, enabling two-step verification and distrusting any email that demands an urgent click. And when in doubt, better to call the person “writing to you” on the phone to confirm.

An enemy that never sleeps

Ransomware is one of the fastest-growing threats, and it no longer only affects large corporations: anyone with a phone or a computer is a potential target. But the good news is that defences are also improving and that prevention remains surprisingly simple.

In the end, security does not depend on a magic piece of software, but on habits: backups, updates and common sense. With that, the data kidnapper finds the door closed.