Skip to content

Ransomware

In plain terms

Your files are still there, but none of them will open, and a message demands payment to make them readable again. Nothing has been stolen in the usual sense: everything has been locked in place.

Definition

Ransomware is malicious software that renders a device's files unreadable by encrypting them, then demands payment in exchange for the means to restore them. This isn't a theft of files but a denial of access: the data stays where it is, and it's the key that's missing.

How it works

The entry point is one of the usual paths: an opened attachment, software downloaded outside its official source, a poorly protected remote access. Once executed, the program scans the files on the device and everything connected to it — a plugged-in external drive, a shared folder, a continuously syncing backup — and replaces them with encrypted versions. This last point is what decides the severity: a backup connected at the time of execution is encrypted along with everything else, which is why an unplugged backup is not an excessive precaution. A message then appears, often accompanied by a deadline and a threat to raise the amount. The deadline has no technical function: it exists to stop you from thinking and from calling someone.

Warning signs

  • Files whose extension has changed and that no longer open in any program
  • Full-screen message or text file dropped in every folder, demanding payment
  • Payment demanded in cryptocurrency, with a countdown
  • Marked slowdown and intense disk activity just before files become unreadable
  • Recent documents missing from the list of recently opened files

How to verify

There's nothing to verify in the usual sense: if your files no longer open and a payment is being demanded, the situation is established. What remains to be determined is the extent — which other devices, external drives and shared spaces were reachable from the affected machine at the time.

What to do

Disconnect the device from the network and turn it off before looking into anything else: as long as it's connected, the damage can spread to shared folders and drives still reachable. Don't pay: payment doesn't guarantee your files will be restored, it funds the activity, and it marks you as a payer. Don't reformat immediately — the encrypted files should be kept, since a decryption method may exist or appear later.

If it already happened

Keep a copy of the encrypted files and the ransom message; they're needed for any later attempt at recovery. File a police report. Report the incident to cybermalveillance.gouv.fr, which directs you to service providers and lists available decryption tools. Restore from a backup that wasn't connected to the device, onto a reinstalled system rather than the affected one. If the device held professional data or other people's data, the obligation to inform those people arises and deserves legal advice.

Frequently asked questions

If I pay, will I get my files back?
Nothing guarantees it. You're entirely dependent on the goodwill of the person who attacked you, with no recourse if they do nothing or the tool provided doesn't work. It's also what marks you as a payer for the future. French authorities advise against paying.
Would antivirus software have prevented this?
It can stop what it recognizes, and it doesn't recognize everything. The protection that actually holds up lies elsewhere: regular, disconnected backups that you've checked at least once actually restore. A backup that's never been tested isn't a backup.
Were my files stolen as well as encrypted?
You can't know from the affected machine, and it's a real possibility — some attacks combine both. Treat any credentials stored on it as exposed: change them from another device, starting with your main email account.

Official sources

Also known as: ransomware, ransom software, crypto-ransomware, malicious encryption.

This article is part of the Malware family. Last updated: 2026-09-03.