RepublicCyberIntel

Ransomware, explained for normal people (and the backup habit that defeats it)

20 September 2026

Padlock with backup reminder

How it works

Ransomware encrypts your files and sells back the key. Modern gangs add double extortion: pay, or your photos and documents get published. Since ~2020 the software itself is rented (ransomware-as-a-service), so the person attacking you is often just an "affiliate" — which is why small targets get hit as often as big ones.

Entry is mundane: a phishing attachment, an unpatched computer, a reused password on a remote-desktop login. WannaCry (2017) spread via a leaked exploit to 200,000+ machines including hospitals; NotPetya the same year, disguised as ransomware but built only to destroy, caused an estimated $10 billion in damage to companies that were never targets.

Should victims pay?

Law-enforcement guidance everywhere says no: payment funds the next wave, marks you as a payer, and decryption keys frequently fail. The stance is only survivable with one thing in place beforehand.

The 3-2-1 backup rule

  • 3 copies of important data (original + two backups).
  • 2 different media (e.g. external drive + cloud).
  • 1 copy offline or immutable (unplugged drive, or cloud versioning) — ransomware encrypts connected drives too.

For phones: enable cloud backup and periodic computer backup. For family documents: one encrypted USB in a drawer, refreshed quarterly, beats every antivirus subscription.

The rest of the armour

Patch promptly (WannaCry only hit unpatched machines), unique passwords plus 2FA (see our breach check), and suspicion toward attachments — scan odd links with the scam-link scanner first. Ransomware is a tax on the unprepared; preparation is cheap.