At a glance
Cybercriminals can use malware to lock you out of your files and then demand payment to restore access. This is called ransomware. Never pay a ransom. Protect yourself by keeping your software updated, backing up your data, and avoiding suspicious links or downloads.
If you think you’ve been affected by ransomware, find out how to recover.
What is ransomware
Ransomware is a common and dangerous type of malware. It works by locking your devices or encrypting your files so you can’t access them.
Cybercriminals then demand a payment, often in cryptocurrency, to restore your access or stop them from leaking your data online.
Ransomware can affective both individuals and organisations, and may cause serious disruption, data loss and financial loss.
Paying doesn’t guarantee you’ll regain access to your data, or that they won’t sell or leak your information online. It can even make you a target for further attacks.
Keep a backup of your data and files. If you experience ransomware and don't have a backup, you could lose these files forever.
Our hotline is available 24 hours a day, 7 days a week. Call 1300 CYBER1 (1300 292 371) for help and advice.
Watch this video to learn more about ransomware.
Warning signs of ransomware
Common signs you may be a victim of ransomware include:
- pop-up messages demanding payment to unlock your files
- being locked out of your devices, accounts or files for unknown reasons
- files that request a password or code to open or access them
- files being moved or missing from their usual folders or locations
- files with unusual file extensions, or file names or icons that have changed unexpectedly.
How to prevent ransomware
Ransomware can infect your devices in the same way as other malware or viruses. Follow our tips to help reduce the risk of it affecting your systems and devices.
Be cautious of suspicious messages
Cybercriminals may use phishing messages to trick you into clicking links, opening attachments or sharing personal information.
If a message seems suspicious, don’t click links or open attachments. Learn how to spot and avoid phishing.
Be careful opening files or downloading programs
Sometimes you need to open a file or download a program from the internet. Follow these steps to help to reduce your risk.
Check that software is made by a trusted company before downloading and installing it on your device. Always download software from the company’s official website or an official app store.
Check file extension names and never download files if they’re not what you’re expecting, or from someone you don’t know. For example, you may have requested a PDF, but the file name ends in .exe or .msi. This could be a sign of a malicious file.
Avoid pirated or illegal software. It may contain malware or not receive security updates. Avoid software that asks for excessive or suspicious permissions.
Regularly backup your information
You should always keep backups of your important information. This is because you may not be able to access your files if you’re locked out of your device. The best recovery method from a ransomware attack is to restore from an unaffected backup.
Refer to our personal cyber security handbook for more advice about backups.
Update your devices and software
Cybercriminals can use known weaknesses to hack your devices. Keep your devices, applications and operating systems up to date. Updates usually include security updates, which keep you protected.
If you have a server or Network Attached Storage (NAS) device on your network, make sure it is updated regularly. If you aren’t sure how to update it, check the manufacturer’s instructions or ask an IT professional for help.
Refer to our personal cyber security handbook to learn how to update your device and software.
Use multi-factor authentication
Multi-factor authentication (MFA) is when you need 2 or more different ways to verify you are the account owner before you can log in. For example, you may need your login details and an authentication code. Using MFA makes it harder for cybercriminals to access your accounts.
Refer to our personal cyber security handbook for advice on how to implement MFA.
Use passkeys or strong, unique passwords
Use passkeys whenever they are available. Where passkeys are not available, use strong, unique passwords for each of your online accounts.
Refer to our personal cyber security handbook for advice about passwords.
Use antivirus software
Antivirus software can help to prevent, detect and remove ransomware on your device. Make sure you turn on ransomware protection and allow automatic updates.
It’s important to learn what real warnings look like so you can spot fake ones. Some websites use fake alerts to trick you into clicking harmful links. Knowing your antivirus warnings can help you avoid these threats.
Refer to our personal cyber security handbook to learn more about antivirus software.
Disable Microsoft Office macros
Microsoft Office applications can execute macros to automate routine tasks. Macros can be used to deliver ransomware to your device. If you don’t need to run macros, it’s best practice to disable them.
If you do need to run macros, consider preventing macros from running automatically and restricting which macros can run.
Visit the Microsoft website for information on enable or disable macros.
Control access to your devices and data
Controlling who can access your devices helps reduce the risk of ransomware and limits how much data an attack can steal, lock or delete.
Give users only the access they need to do their job. There are 2 types of accounts on Windows and macOS: standard and administrator. Everyday users should use a standard account. Only users who need to perform administrative tasks, such as installing software or changing system settings should use an administrator account. Using a standard account as your main account can reduce the risk of ransomware.
For help setting up your accounts, follow:
If you’re unsure how to set this up in a business, speak to an IT professional.
Extra measures for small business or advanced home networks
You can reduce the possibility of an attack with extra protective measures.
Secure your servers
If you use a Network Attached Storage (NAS) server or other server in your home or business, take extra care to secure it. These devices are common targets for cybercriminals because they often store important files or perform important functions.
There are many ways that you can help protect these devices from ransomware. For example, make sure your servers or NAS devices are updated regularly and accounts are secured with a strong passphrase or MFA.
You should also consider monitoring and setting up alerts for high disk activity and account logins on these devices. General advice is published in our 2021 Increased Global Ransomware Threats advisory.
If you need help to secure your NAS or server, including specific ways to reduce risk, speak to an IT professional.
Reduce your external-facing footprint
Audit and secure any internet-exposed services on your network, such as:
- remote desktop
- file shares
- webmail
- remote administration services.
If you’re unsure how to do this, speak to an IT professional.
Migrate to cloud services
Consider using reputable online or cloud services with built-in security, instead of managing your own security or cloud service. For example, use online services for functions like email or website hosting.
Further information
For further details, download our Ransomware prevention guide [PDF 2.01 MB].
You can also explore the ransomware playbook. This provides advice on how to prepare for, respond to and recover from a ransomware attack.
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.