11 tips to avoid ransomware attacks

A single careless click can be all it takes for ransomware to encrypt your files and throw your digital life into chaos. And, once a ransomware attack takes hold, full recovery is often impossible. Learn how smarter online habits and security tools like Norton 360 can help lock ransomware out before it locks down your device.

AV Comparatives award

2025

Consumer

Security Innovator

av test award

2026

Top Rated Product

Close-up of a hand touching a digital screen displaying a glowing pixelated cybersecurity shield, suggesting digital protection or secure technology.

Ransomware is a form of malware that locks you out of your own files and demands payment to regain access. Many also threaten to publish stolen data publicly if you don't comply. And even if you pay, there's no guarantee you'll get anything back.

According to Verizon's 2025 Data Breach Investigations Report, ransomware was involved in 44% of all reviewed breaches — a 37% increase over the previous year. Small businesses are particularly affected: while ransomware appears in 39% of breaches at larger organizations, that figure jumps to 88% for SMBs.

Here’s how to avoid ransomware attacks before they happen and what to do if your device does become infected.

1. Safeguard your personal information

Protecting your personal information and account credentials can help prevent ransomware by denying attackers an entry point into your devices, cloud services, or network. Phishing messages often impersonate trusted organizations to trick you into handing over information they can use to gain access.

To reduce your ransomware risk, never share the following information:

  • Login credentials: Stolen usernames and passwords can give attackers direct access to accounts or systems they may use to deploy ransomware.
  • Verification codes: One-time verification codes or other forms of two-factor authentication can let attackers bypass additional security controls after stealing your password.
  • Security question answers: Attackers may use these details to reset passwords and take control of accounts.
  • Remote-access details: Never provide unexpected callers or messages with remote desktop credentials, access codes, or permission to install remote-access software.
Real-life ransomware example: One Redditor was ransomed for £500, with the attacker saying they’d scam and harass their friends on Instagram if the victim didn’t pay up.

2. Don’t open suspicious emails

Phishing and social engineering messages —which often contain malicious links or attachments — were cited by 35% of affected organizations, making them the most common ransomware entry point in 2025 according to Spycloud’s 2025 Identity Threat Report. And the threat is likely to grow further as so-called phishing-as-a-service (PhaaS) tools make it easier for cybercriminals to launch convincing attacks at scale.

To help prevent phishing attempts developing into a ransomware infection:

  • Don’t click suspicious links or attachments: If you weren’t expecting the message or file, verify the sender independently before opening it.
  • Enable spam filters: Strong filtering can stop many phishing emails from reaching your inbox in the first place.
  • Use strong, unique passwords: Secure credentials make it harder for attackers to turn stolen account information into unauthorized access.
  • Enable multi-factor authentication (MFA): Protecting your accounts with MFA can help block attackers even if they do manage to steal your password.

3. Keep software updated

Keeping your software up to date is a key ransomware prevention step because attackers often exploit known vulnerabilities to gain access to devices and networks. When developers discover these security flaws, they release patches through software updates. But until you install them, your device remains more open to successful attacks.

A 2025 Gen Threat Report highlighted this threat by documenting how the Cl0p ransomware group exploited a critical Oracle E-Business Suite vulnerability to steal data from organizations including universities, airlines, healthcare providers, and media companies. Some victims only discovered the attack after receiving extortion demands or seeing their data published on leak sites.

To close these potential entry points, keep your operating system, browsers, and applications updated. Install security updates promptly when they appear, or enable automatic updates so critical ransomware protections are applied as soon as they're available.

4. Use a VPN on public Wi-Fi

Public Wi-Fi networks in cafes, airports, and hotels can expose your traffic to other people on the network. Attackers may exploit unsecured connections using techniques such as man-in-the-middle attacks to intercept sensitive data or steal login credentials. Those compromised credentials could then provide access to accounts or systems where ransomware can be deployed.

A VPN encrypts the connection between your device and the VPN server and masks your IP address, making it more difficult for attackers on a public network to intercept your data or track your activity. This helps create a more private connection, even on public Wi-Fi.

If you want to double-up your protection when using unsecured networks, the suite of advanced privacy and security features bundled within Norton VPN includes Double VPN, which encrypts the data you send and receive not just once, but twice, making it practically impossible for anyone to tamper with your internet traffic.

5. Perform backups regularly

A regular data backup of your files stored on another device or in the cloud is one of the most effective ransomware defenses because it removes the attacker's leverage. Even if ransomware encrypts everything on your computer, a recent backup allows you to restore your files without paying a ransom.

Most operating systems include built-in backup tools, and many also offer automatic backup settings you can enable once and forget. This makes regular backups one of the lowest-effort, highest-impact ways to protect yourself against ransomware.

6. Use a strong password and MFA

Weak and reused passwords are almost an open invitation for ransomware attackers, because they allow hackers to automatically test common passwords across thousands of accounts until one works (a technique known as password spraying). Once attackers get in, ransomware is often one of the first things they deploy.

In 2025, UK transportation company Knights of Old collapsed after the Akira ransomware group gained access after guessing a single employee password. All data, servers, backups, and disaster recovery systems were encrypted, and the ransom demand of £5 million exceeded what the 158-year-old company could afford to pay.

To avoid this kind of exposure, choose a strong, unique password for every account. Aim for at least 15 characters, combining words into passphrases, and including uppercase and lowercase letters, numbers, and symbols randomly. A password manager makes this more practical by generating truly randomized passwords and storing them for you. Some, such as Norton Password Manager, even include auto-change features that update passwords automatically every few months.

Finally, enable multi-factor authentication (MFA) wherever it's available. Even if a password leaks, MFA adds a second verification step that keeps attackers out, closing the gap that weak or stolen passwords would otherwise leave open.

7. Disable macros in documents

Macros are small scripts used to automate tasks in Microsoft Office applications such as Word and Excel. But attackers can abuse them by embedding malicious macro code in documents and distributing the files through phishing emails or other channels.

If a user enables a malicious macro, it can execute commands, steal data, or download additional malware — including ransomware. Modern versions of Microsoft Office generally block macros in files downloaded from the internet by default, but attackers continue to use social engineering and other techniques to persuade victims to bypass these protections.

For example, between September 2025 and January 2026, Russian state-backed threat group APT28 conducted a macro malware campaign targeting organizations across Western and Central Europe. Attackers distributed malicious documents through spear phishing emails and attempted to convince recipients to enable their malicious content.

To reduce your risk, consider disabling macros directly in Microsoft Office by following these steps:

  • Windows 11: Open Word, Excel, or PowerPoint and go to File > Options > Trust Center > Trust Center Settings > Macro Settings. Select Disable all macros with notification (recommended) or Disable all macros without notification, then click OK.
  • macOS: Open Word, Excel, or PowerPoint and select the app name from the menu bar, then go to Preferences > Security. Choose Disable all macros with notification (recommended) or Disable all macros without notification.
Screenshots showing how to delete ransomware in Microsoft Office.

8. Disable unused remote access

Remote Desktop Protocol (RDP) lets you connect to a Windows computer remotely. It’s useful for IT teams and remote workers, but internet-exposed RDP is also a common ransomware entry point. Attackers may scan for open RDP services, brute-force weak credentials, or use stolen passwords to gain access and move deeper into a network.

If you don’t use RDP, disable it. Unnecessary remote-access services create extra opportunities for attackers. If remote computer access is required, avoid exposing RDP directly to the public internet. Instead, place it behind a secure VPN or other controlled access layer, and protect accounts with strong passwords and multifactor authentication.

The key idea is simple: the fewer remote entry points you expose, the smaller your attack surface.

9. Do not pay ransom demands

No matter how urgent the situation feels, it’s never advisable to pay the ransom. Paying up helps fund cybercrime and can even encourage future attacks, and, most importantly for you, doesn’t actually guarantee that you'll regain access to your data. Even if attackers provide a decryption key, it may not work properly or restore all of your files.

More and more victims are following the advice of cybersecurity experts and the FBI and choosing not to pay. According to Coveware, only 23% of ransomware victims paid in Q3 2025, a historic low. Global ransomware payments also fell from $1.25 billion in 2023 to around $813 million in 2024.

10. Use firewall protection

A firewall monitors incoming and outgoing network traffic and blocks connections that violate its security rules. This creates an important barrier between your device or network and potentially malicious traffic.

Firewalls can help reduce ransomware risk by blocking unauthorized connections, restricting access to vulnerable network services, and disrupting communication between malware and attacker-controlled servers. However, a firewall can't stop every ransomware attack, and some ransomware can encrypt files without communicating with an external server.

Most operating systems include a built-in firewall, so make sure yours is enabled. Businesses may also benefit from more advanced firewall protection that can inspect network traffic and detect suspicious activity.

11. Download antivirus software

Antivirus software adds another important layer of ransomware protection by monitoring files, applications, and system activity for malicious behavior. Modern security software can detect and block different types of ransomware, potentially stopping an infection before it can encrypt your files.

Antivirus protection can also help block other threats and attack methods associated with ransomware, including malicious downloads, dangerous websites, and malware delivered through deceptive links or attachments.

We’re so confident in the ability of the antivirus engine at the heart of Norton 360 to remove viruses from your device, it comes with a Virus Protection Promise, meaning if we can’t remove a virus, you’ll be eligible for a full refund.

Signs your device is infected with ransomware

Ransomware often begins encrypting files before you realize anything is wrong. In many cases, the first clear warning is a lock-screen or pop-up displaying a ransom note demanding payment in exchange for decrypting your files or system.

A screenshot of a ransomware ransom note.
A screenshot of a ransomware ransom note.
A screenshot of a ransomware ransom note.

But other warning signs such as unexpected file changes, sudden system slowdowns, unfamiliar extensions, or security tools switching off without explanation can also indicate malicious activity. While none of these signs proves ransomware on its own, several appearing together should be treated seriously.

Here's what to watch for:

  • Ransom notes: A message may appear on your screen or inside affected folders demanding payment in exchange for restoring access to your files.
  • Locked or inaccessible files: Documents, photos, or other files may suddenly stop opening because ransomware has encrypted them.
  • Unfamiliar file extensions: Affected files may be renamed or given unusual extensions that weren’t there before.
  • Unexpected file changes: Files may be renamed, moved, modified, or deleted without your input as ransomware affects your system.
  • Unusual system behavior: Your device may slow down, freeze, or become less responsive while ransomware encrypts files or performs other malicious activity.
  • Disabled security tools: Certain ransomware strains attempt to shut down antivirus software, firewalls, backups, or other protections to avoid detection and make recovery more difficult.
  • Suspicious network activity: Some ransomware communicates with attacker-controlled servers, which may cause unexplained spikes in network traffic. This is more likely to be noticed by security software or network administrators than by everyday users.

What to do if you think your device is infected with ransomware

If you suspect you’ve been impacted by ransomware, acting quickly can help limit the damage and prevent the infection from spreading. Don't interact with the ransom note or rush to pay — instead, isolate the affected device and work through these steps:

  1. Isolate the infected device: Immediately disconnect the device from Wi-Fi, Ethernet, external drives, and shared networks to help prevent ransomware from spreading or communicating with attackers. Avoid connecting backup drives while the infection is still active.
  2. Don't pay the ransom: Paying provides no guarantee that you'll recover your files and helps fund further attacks. Save the ransom note and other evidence, and consider reporting the attack to law enforcement or the relevant cybercrime authority.
  3. Use a clean device for sensitive tasks: If possible, use an unaffected device to research the ransomware, contact support, access important accounts, or download recovery tools. Avoid entering passwords or other sensitive information on the infected device.
  4. Scan for and remove the ransomware: Use a reputable malware removal tool to identify and remove the infection. More serious infections may require professional assistance or a complete system reinstall.
  5. Check for a decryption tool: Some ransomware strains have known weaknesses or recovered decryption keys that allow victims to unlock files for free. Use reputable cybersecurity sources to check whether a trusted decryptor is available for your specific ransomware infection.
  6. Restore from a clean backup: Once you're confident the ransomware has been removed — or you've wiped and reinstalled the operating system — restore your files from a backup created before the infection.

How to recover data after a ransomware attack?

Once the ransomware has been contained and removed, the next priority is recovering your files. The best recovery method depends on the type of ransomware, whether a working decryptor exists, and whether you have clean backups available.

Here are the main ways to recover ransomware-encrypted data and reclaim your digital life:

1.    Identify the ransomware strain: Check the ransom note, encrypted file extensions, or information from your security software to help determine which ransomware variant affected your device. Identifying the strain can help you find compatible recovery tools.

2.    Check for free decryption tools: Before writing off encrypted files, check whether a reputable ransomware decryption tool is available for the specific ransomware strain.

3.    Restore from a clean backup: If no decryptor is available, restore your files from an offline or cloud backup created before the attack. Only reconnect backup media after the infected system has been cleaned or rebuilt to avoid encrypting your backups too.

4.    Check cloud storage and file history: Cloud services may retain previous versions of files or deleted data that ransomware hasn't affected. Built-in backup and version-history features may also allow you to roll files back to versions saved before the attack.

5.    Consider professional data recovery: If important files can't be decrypted or restored, a reputable data recovery or cybersecurity specialist may be able to assess your remaining options. However, recovery isn't always possible, particularly when ransomware uses strong encryption and no clean backup or decryption key exists.

Safeguard your devices from ransomware with Norton

Ransomware can strike fast, locking you out of your files and putting your data at risk. Norton 360 helps defend your devices and data with real-time threat protection designed to help stop attacks in their tracks, plus dedicated cloud backup to help keep your important files safer.

With one powerful solution, you can help protect your files, privacy, and personal information from ransomware and other evolving threats. Choose Norton 360 and stay one step ahead of cybercriminals.

FAQs

What is the 3-2-1 rule for ransomware?

The 3-2-1 backup rule means keeping three copies of your data on two different types of storage, with one copy kept offsite or otherwise isolated from your main device. If ransomware encrypts your primary files, a clean backup gives you a way to restore them without relying on the attacker for recovery.

What daily habits can help prevent ransomware infections?

Helpful daily habits for preventing ransomware include avoiding unexpected links and attachments, keeping software and devices up to date, using strong and unique passwords, enabling multifactor authentication, and regularly backing up important files. Consistency is key, since ransomware often succeeds by exploiting weak credentials, unpatched software, or a single moment of misplaced trust.

What are common ransomware attack vectors?

Common ransomware attack vectors include phishing emails, stolen or weak credentials, unpatched software vulnerabilities, exposed remote-access services such as RDP, malicious downloads, and weaponized Office documents. The specific entry point varies by campaign, but attackers typically exploit the easiest available path into a device or network.

How does ransomware spread?

Ransomware can spread through phishing emails, malicious downloads, compromised websites, stolen credentials, and unpatched vulnerabilities. In business networks, some ransomware operators also move laterally between systems after gaining an initial foothold, using shared credentials, remote-access tools, or exposed services to reach more devices and encrypt additional data.

Oliver Buxton
Oliver Buxton, a staff editor for Norton, specializes in advanced persistent threats. His work on cyberterrorism has appeared in The Times, and his prior work includes writing digital safeguarding policies.

Editors’  note: Our articles offer educational information and are written to raise awareness about important topics in Cyber Safety. Norton products and services may not protect against every type of threat, fraud, or crime we write about. For more details about how we research, write, and review our articles, see our Editorial Policy.


Want more?

Follow us for all the latest news, tips, and updates.

Get powerful ransomware protection

Install Norton 360 to help protect against ransomware and other malware.

Get powerful ransomware protection

Install Norton 360 to help protect against ransomware and other malware.

Norton
360 Deluxe

Privacy preference center
By clicking "Accept All" you allow cookies that improve your experience on our site, help us analyze site performance and usage, and enable us to show relevant marketing content. You can manage cookie settings below. By clicking “Confirm Selection” you agree with the current settings. See Cookies Policy
We have received a GPC signal from your browser and have modified the default cookie preferences for you accordingly. By clicking “Accept all” you allow cookies that improve your experience on our site, help us analyze site performance and usage, and enable us to show relevant marketing content. You can manage cookie settings below. By clicking “Confirm selection” you agree with the current settings. See Cookies policy
Manage consent settings

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Preference cookies enable a website to remember information that changes the way the website behaves or looks, such as your preferred language or the region that you are in. De-selecting these cookies may result in improper functionality and setting of the website.

Performance cookies help us improve our website by analyzing how visitors use it and interact with it. De-selecting these cookies may result in poorly-designed content and slow site performance.


social media