Website Preloader

Ransomware

Ransomware can wreak havoc on anyone’s life, but the more it’s understood, the easier it is to prevent.

Everyone has secrets—personal data, passwords, private documents, etc—and people will spend lots of money to keep this information secret or gain access to it. Ransomware is just one way that hackers win access to personal information, expecting its owner will pay to win it back.

Ransomware is a nasty bit of malicious software—malware for short—that encrypts files and documents on either one computer or a network of computers and servers. Once the victim’s network is encrypted, the hacker will only let them regain access to their network in exchange for a ransom or sum of money.

article ransomware spot

The Hack Attack

Step 1: A hacker infiltrates your computer. The most common ways ransomware enters computer networks are:

  • Email—Phishers will trick people into clicking on a malicious link that redirects them to a fake login page or a suspicious email attachment that will infect the computer with malware.
  • Vulnerable software—People with malicious intentions can find holes in any software that’s not properly protected. They do this by overrunning the system with commands until it’s forced to fail and give them access without them even needing to harvest credentials.
  • Pirated software—disguises itself as a safe app/program, but is actually a virus. Once downloaded, it infects the user’s device.
  • Removable devices like a USB drive—hackers will infect a device in the hopes that the victim will plug that device into a computer.

Step 2: The hacker encrypts as much of your data as possible. Essentially, the malware enters the computer’s IT infrastructure, gathers as much data as it can get its sticky little hands on, rushes the data into a room, and locks the door—metaphorically, speaking. The only one with the key to that door is the hacker. Big oof.

Step 3: The hacker displays a message requesting a ransom payment in exchange for your data. The hackers want their money and you want your data, but the hackers themselves are the only ones that can access your data. And that’s why the majority of ransomware is designed to present the victim with a little note stating just that. They may even threaten to release your data to the public if you don’t pay up.

While an attack like this is terrifying, there are ways you can prevent it and stop a hacker in their tracks.

How to avoid it?

Don’t click strange links and attachments! Do a careful investigation before taking any actions on even the least “phishy” email.

Invest in email and endpoint protection software. This software scans emails and attachments for harmful files and also detects phishing scams before you fall victim to them.

Back up your data. Creating a backup of your data means you have a copy of it somewhere safe, like an external hard drive or the cloud. This preventative measure is a last resort to retrieving your data if it’s being held for ransom. The user won’t have to pay the hacker, so those snakes can count their losses. However, if the hacker has taken your data and downloaded it onto another device, it’s still possible they’ll release it to the public.

Two effective ways to backup data:

  • External hard drives—they live outside a computer and can be plugged into other devices.
  • Cloud storage—allows files and data to be stored off-site and can be accessed through other devices.

 

Using any of these storage options allows you to wipe your computer entirely without worrying about losing anything important.

What to do if it happens to you?

  • Identify: Try to determine where the attack came from and what type of malware you’re dealing with.
  • Isolate: Separate the infected device from all other devices by deleting any paired devices from the Bluetooth settings or even physically unplugging any other devices connected to the computer.
  • Report: Report the attack to the FBI using the Internet Crime Complaint Center.
  • Restore the data: This step depends largely on what you’ve done to secure your data. However, paying the ransom usually proves to be ineffective or an invitation for more ransomware. You can either try to remove the malware on your device by taking it to a professional and restoring bits of your hard drive or you could wipe the whole thing entirely.
  • Prevent further attacks: Be aware of what you’re doing on the internet—follow the different suggestions mentioned in this article and stay safe!

Try a Virtual Private Network

Go a step further in protecting your online activity with a virtual private network, or VPN. A VPN is an encrypted internet connection between a device and a network. It protects sensitive data and blocks unauthorized access to your traffic and identity.

VPNs are common in corporate environments, so if you work remotely, you may already use a VPN to access your employer’s server. But they are also useful if you frequently connect to the internet using public Wi-Fi. VPNs also protect against your data being sold by your internet service provider. (Yep, that’s a thing.)

If you’re trying a VPN for the first time, go with an established provider who has good reviews and a money-back guarantee. Make sure the VPN does not track your internet traffic or sell your data to third parties—many free VPN services do. Look for a simple, user-friendly interface and good customer service, preferably with 24/7 live chat.

Limit Personal Info Shared Online

Your personal online behaviors are a valuable protection against cyber threats. Limit the personal information you share online. This includes:

  • credit card and bank account numbers
  • address
  • phone number
  • other identifiers

It’s also smart to think twice before posting social media comments with personal thoughts and details about your life. True, hackers can use this information to guess passwords or as part of impersonation schemes, but your public social media posts could also hurt your relationships or career.

Remember, you can’t control how your opinions are perceived and it’s almost impossible to remove something entirely once it’s posted online. Current or potential employers may monitor your social media, and the more information that’s out there, the more likely it can be used against you. So be smart about what you say online.

Use Social Media Protections

Protect yourself on social media by adjusting your privacy settings and options.

  • Restrict who follows you on social media. Consider limiting how much colleagues and other professional acquaintances know about your personal life.
  • Don’t accept friend requests from people you don’t know.
  • Block your tweets and posts from search engines, so they’re only visible to your followers. Remember that any follower can screenshot what you write, even if they can’t retweet it.
  • Don’t link your social media accounts. Anytime you link an account, you’re increasing the visibility of whatever you post across multiple platforms. Personal information that’s available in many places makes you more vulnerable to phishers.
  • Don’t post personal information that is commonly used for passwords or password security questions, like the name of your elementary school or first pet’s name. Avoid posting about where you bank and shop. Even seemingly harmless facts can help scammers locate you.
  • Don’t post anything you don’t want the world to read.

Protect Your Passwords

Use strong, unique passwords on every site where you have an account. This is crucial for sites that access confidential personal or financial information.

Too obvious passwords provide no protection. The same goes for reused passwords. If a hacker cracks one account, they’ll try that password for every single account connected to your email address.

You’re not alone if you find it difficult to keep track of all those different password combinations. Try a password manager. A password manager creates, encrypts, and securely stores your passwords in a vault and you can access any of those passwords with a single complex password.

Password managers can also store other info like credit card numbers and PINs. Many reputable password managers offer a basic service for free, with a small fee for premium features or multiple devices.

Scammers are getting more sophisticated with email and text messages, so don’t click any links or open attachments from sources you don’t recognize. They may even send links to websites that look exactly like a website you trust. Look for other telltale signs that a message is a scam.

  • Incorrect company names or URLs. Scammers often use slightly different spellings or extensions to trick you into thinking they’re legit.
  • Poor spelling and grammar. Real companies don’t often make typos and definitely check spelling before sending messages to clients.
  • Generic greetings. Official messages are nearly always personalized with your name instead of a generic greeting.
  • Urgent calls to action. Keep an eye out for red flags like “your account is suspended, ”reset your account password now,” or other high-pressure calls to action.

Shop Safe Online

Online shopping is common and generally safe. That said, always look for a security padlock symbol to the left of the company’s name in the URL bar. Click this icon to visit the site’s security certificate.

Double-check the URL begins with HTTPS. This indicates the data you send and receive is encrypted.

If you still want to buy from a vendor that’s selling directly on social media or want to use a site without proper security in place, it’s best to use a service like PayPal.

Your PayPal account is linked to your credit card or bank. Purchases you make via PayPal are encrypted and the seller has no access to your account number. Still, anytime you use PayPal, make sure your security software is updated and avoid any financial transactions using public Wi-Fi.

This article has been republished with permission. View the original article: Ransomware.