Imagine that one day you switch on your computer and are greeted by a message telling you that all your files have been encrypted and that you’ll only be able to recover them if you pay a sum of money to a stranger. You’ve lost your photos from that summer, your important documents and the information you needed for your studies. What would you do? Would you pay the ransom? Would you report the incident to the authorities? Or would you try to sort out the problem yourself? Although it may seem as though this sort of thing never happens, the truth is that it has become a reality for many people and businesses who have fallen victim to ransomware attacks.
The ransomware is malicious software that prevents access to the victim’s data or device and demands a payment to restore it. In short, it is a cybercrime which has grown exponentially in recent years, and which causes serious financial and reputational damage to those affected.
In this post, we’re going to explain what ransomware is, how it came about, how it works, what the consequences are, and how we can protect ourselves against it. If you’d like to find out more about this topic, read on.
The start of the ransomware attacks
First, let’s put this situation into context. The fact is that, whilst the ransomware attacks They look as though they’ve come straight out of modern science fiction films, but nothing could be further from the truth, as they’ve been around since the days of floppy discs.
The first ones ransomware attacks date back to the late 1980s, when a biologist called Joseph Popp distributed around 20,000 floppy discs infected with a programme that encrypted files on computers and demanded $189 to unlock them. This case is known as the AIDS Trojan or the PC Cyborg.
Since then, ransomware has evolved and diversified, exploiting new technologies and system vulnerabilities. Some of the most notorious and destructive attacks in history include:
- CryptoLocker: It first appeared in 2013 and spread via emails containing malicious attachments. It demanded payment in bitcoins in exchange for the decryption key.
- WannaCry: It emerged in 2017 and exploited a vulnerability in the Windows operating system that had been leaked by a group of hackers. It blocked access to the system and demanded a ransom of $300 in bitcoins. Its victims included hospitals, businesses, banks and public bodies.
- NotPetya: It also occurred in 2017 and was based on the WannaCry code, but with some modifications that made it more damaging and difficult to remove. In this case, it offered no way of recovering the data, as its purpose was to cause as much damage as possible. It is estimated to have caused losses of over 10,000 million dollars.
How ransomware attacks work
So, how do ransomware attacks work? Well, this virus infects computers or electronic devices in various ways, but the most common are as follows:
- The spam email: usually includes attached files or links that in some way pique users’ interest. The aim is to get them to click on the link and thereby download the ransomware. They often pose as trusted organisations or friends, so it is best to be vigilant and check the sender of the message carefully.
- The malicious advertising: Have you ever found yourself browsing the web and been redirected to another page without meaning to? Well, be careful, as this is another way of spreading the virus. This method usually uses exploit kits, which are programmes that detect and exploit vulnerabilities in web browsers or installed plug-ins.
- The removable devices: We’re talking about USB sticks, external hard drives, SD cards and other devices which, when connected to a computer or other device, trigger the ransomware.
If, unfortunately, the virus has already infected your electronic device’s system, however it got there, it can act in two main ways:
- The encrypting ransomware: This is the most common form and involves encrypting the victim’s files using a key known only to the attacker. A message is then displayed demanding a ransom in exchange for the decryption key.
- The locker ransomware: It is less common and involves blocking access to the victim’s system or device, preventing them from using it. A message is then displayed demanding a ransom payment. The message usually purports to come from a legitimate authority, such as the police or a government agency.
Consequences of ransomware attacks
Ransomware attacks pose a very serious threat to organisations and users, particularly in two areas:
- Financial losses: Ransomware can affect an organisation’s operations and reputation, leading to a loss of revenue, customers or business opportunities.
- Data loss: It may prevent access to critical, sensitive and valuable data, which could have legal, regulatory or strategic consequences for the organisation.
Protection against these attacks
Protecting yourself against this type of attack can be difficult, though not impossible. Take note of these recommendations we’re sharing with you:
- Keep your operating system software up to date. This recommendation also applies to corporate environments. Keeping your software up to date helps you fix vulnerabilities and prevent infections.
- Raise staff awareness on the risks of ransomware and how to avoid them.
- Make sure you have a response plan in the event of an infection. You can use anti-malware programmes whenever you suspect your computer is infected.
- Use the cloud technologies to make copies of safety of your data and access it from anywhere.
Recover the data and remove the ransomware
To recover your data and remove the ransomware, you can follow these steps:
- Switch off or unplug the computer on the network. This will prevent the ransomware from spreading to other devices or shared files.
- Never get in touch with cybercriminals Don’t pay the ransom. This will only encourage them to carry on attacking, and it won’t guarantee that you’ll get your data back.
- Use a antivirus software to clean the infected device. Follow the instructions provided by the programme you choose and make sure you remove the malware completely.
- Use a ransomware decryption tool to recover your files. Before using them, make sure you have removed the ransomware from your device.
Can these offences be reported?
The answer is yes. Report the incident to the National Institute of Cybersecurity (INCIBE) or the National Police’s Technology Investigation Brigade. According to the INCIBE website, to report a ransomware attack you will need:
- A detailed description of the incident and your contact details.
- The original ransom note in the format in which it appears on your computer. If you do not have it or cannot find the file, please send a screenshot showing the content of the note.
- Two files encrypted by the ransomware (which do not contain personal data, whose original formats were Word or Excel, and which are less than 1 MB in size).
Would you like to find out more? We invite you to subscribe to Educa.Pro …and start enjoying a wide range of specialised training courses today, with absolutely no limits!