In short: Ransomware is malware that encrypts your files or locks your device and demands money to restore access. On home computers and phones it almost always arrives through a user action: an attachment from a phishing email, a fake download, a «cracked» program or an unpatched vulnerability. The golden rule is not to pay the ransom (payment doesn't guarantee your data back) and to prepare in advance: 3-2-1 backups, timely updates, two-factor authentication and caution with attachments. A VPN closes one specific vector — interception and tampering on untrusted Wi-Fi — but it does not scan files and does not replace a backup.
What ransomware is and how it works
Ransomware is malicious software that takes away access to your own data and demands a ransom to give it back. This usually happens in one of two ways: files are encrypted with a strong algorithm (crypto-ransomware) or the whole system is locked (locker-ransomware). In both cases a demand appears on screen to transfer money — normally in cryptocurrency — in exchange for a decryption key.
It helps to understand that modern ransomware doesn't «explode» on contact. First it quietly gains a foothold, studies which files and drives are reachable, disables some defenses, and only then starts encrypting. For a home user that means there can be a delay between infection and lockout, and the event often shows up as documents and photos that suddenly won't open and carry a strange file extension.
Three related terms are worth separating:
- Encryptors — scramble documents, photos and archives. The most common and dangerous type: without the key, files can't be recovered.
- Lockers — block the screen or browser but usually leave files intact; common on Android as «blockers» showing a fake fine.
- Data-stealing ransomware — copies your files before encrypting and threatens to publish them. More on this in the double-extortion section.
How ransomware gets onto a device
One idea saves a lot of grief: in the overwhelming majority of everyday cases, infection starts with the user's own action or with an out-of-date program. A device does not get encrypted «by itself» just from being online. Below are the main channels and which one a VPN actually closes.
| Infection vector | What it looks like | Does a VPN close it? |
|---|---|---|
| Phishing email with an attachment | An «invoice», «resume» or «photo» as .doc/.zip/.exe from a stranger | No — you open the file |
| Fake download or «cracked» software | An activator, a «free» version of paid software, a fake update | No — choosing the source protects you |
| Malicious link on a website | A «Download» button, a pop-up «your PC is infected» | Partly — some VPNs block known malicious domains |
| Interception or tampering on open Wi-Fi | A swapped file or page on an unsecured network | Yes — it encrypts the channel and blocks tampering |
| Vulnerability in an unpatched OS or app | Infection with no obvious click, through a software hole | No — updates close this |
| Stolen passwords and logins | Access to your services with a leaked password | Partly — a VPN protects the password in transit, not on the device |
A closely related problem is malicious apps and infostealers: they harvest saved passwords and cookies, and those logins are then resold to the people who run extortion. Password theft and encryption attacks are links in the same chain, so you have to defend against both together.
Double and triple extortion: why it's worse than plain encryption
A few years ago a backup was enough: files encrypted, restore from backup, move on. Attackers responded with double extortion: they copy the data first and encrypt it second. Now a backup saves you from losing files, but not from the threat of publishing what was stolen — personal photos, scanned documents, private messages.
Then triple extortion appeared: on top of encryption and the leak threat they add extra pressure — a DDoS attack on your resources, or messages to your contacts. For an ordinary person the takeaway is simple: a backup made in advance is still hugely valuable, but it doesn't remove the need to keep the malware out in the first place. That's why prevention matters more than a recovery plan.
Ransomware on phones: Android and iOS
On smartphones the picture differs from computers. On Android you mostly meet lockers: an app from a third-party source covers the screen with a fake «fine» banner and demands payment. The files themselves are usually intact, and the blocker is removed by booting into safe mode and deleting the suspicious app. True Android encryptors are noticeably rarer.
On iPhone a classic encryptor is almost impossible because of app sandboxing: one app can't freely encrypt another's files. A similar-feeling scenario does exist, though — a lockout through a hijacked account: an attacker gains access to your Apple ID, turns on «Find My» and locks the device with a ransom demand. The defense here isn't antivirus but a strong, unique password and solid account protection with two-factor authentication.
What to do if a device is already infected
If files are already being encrypted or a ransom note is on screen, act calmly and in order:
- Disconnect from the network — pull the cable, turn off Wi-Fi. This stops encryption of network drives and cuts the malware's link to its server.
- Don't pay right away. Payment doesn't guarantee a key and marks you as a priority target later.
- Record what happened — photograph the demand and note the extension of the encrypted files: this helps identify the ransomware family.
- Check for a free decryptor. The international No More Ransom project publishes free decryptors for many known families.
- Restore from a backup onto a known-clean system — ideally after a full OS reinstall.
- Change your passwords for important services from a different, clean device — the infected machine can't be trusted.
How to protect yourself in advance: four pillars
1. Backups on the 3-2-1 rule
Three copies of your data, on two different media, one of them offline or off-site. The key nuance: a copy that stays connected and syncs gets encrypted along with the original. That's why offline media and versioned backups — the kind you can roll back to a «before infection» state — matter so much.
2. Updates
A large share of infections exploit already-known vulnerabilities that were patched long ago. Auto-updating your OS, browser and apps closes this channel almost for free. Don't put off that restart — it's often what actually applies the patch.
3. Passwords and two-factor authentication
A stolen or weak password is one of the most common entry tickets. Unique passwords in a trusted, official app plus two-factor authentication sharply reduce the chance that your access is used for an attack.
4. Caution with mail and downloads
Phishing is once again the number-one way in. Don't open attachments or links from unexpected emails, check the sender's address, and download software only from official stores and developer sites. Avoid «activators» and cracked builds entirely.
The role of a VPN and safe connections
Let's be precise: a VPN is not a cure for ransomware. It doesn't scan files, can't tell a malicious attachment from a normal one, and won't recover encrypted data. So don't believe promises that «a VPN protects you from viruses» — we covered honestly what a VPN protects against and what it doesn't separately.
What a VPN really does in this context is secure the channel on an untrusted network. On open Wi-Fi (a cafe, airport or hotel) someone on the same network can try to swap a file or page you download and intercept the passwords you later use to sign in to important services. LiMP VPN's traffic encryption makes such interception and tampering practically impossible — this is the very «man in the middle» scenario we described in our article on the man-in-the-middle attack.
The right place for a VPN is one layer in a defense-in-depth stack, alongside backups, updates and antivirus. If you often work from other people's networks, it's worth keeping an encrypted connection on all the time — you can see LiMP VPN plans on the pricing page.
Anti-ransomware checklist
- Set up automatic 3-2-1 backups and keep one copy offline.
- Turn on auto-updates for your operating system, browser and apps.
- Use a password manager and enable two-factor authentication on email and key accounts.
- Don't open attachments or links from unexpected emails; verify the sender through another channel.
- Download software only from official stores and developer sites; avoid «activators».
- Install a modern antivirus with behavioral analysis and don't disable it.
- On open Wi-Fi, switch on LiMP VPN to rule out interception and tampering.
- Decide in advance where you'll restore from, and test at least once that the backup actually opens.
Frequently asked questions
Can ransomware encrypt my cloud backups?
Yes, if the cloud constantly syncs with your computer: the encrypted files simply upload over the originals. Versioning (the ability to roll back to a previous version of a file) and offline copies that aren't connected during the attack are what save you.
Should I pay the ransom if I have no backup?
Security experts and law enforcement advise against paying. Payment doesn't guarantee a working key, funds criminals and flags you as a paying target. First check the free decryptors on No More Ransom.
Will antivirus definitely stop new ransomware?
Not one hundred percent. A signature-based antivirus may not know the newest sample, which is why behavioral analysis — reacting to «mass file encryption» — matters. Antivirus is a necessary layer, but without a backup it can't fully protect you.
Can ransomware infect an iPhone?
A classic encryptor on iOS is extremely unlikely thanks to app sandboxing. The real risk is a device lockout through a hijacked Apple ID, so protect the account itself with a unique password and two-factor authentication.
Will a VPN protect me from ransomware?
Only partly and indirectly: a VPN closes interception and tampering on other people's networks, but it doesn't block malicious attachments and won't decrypt files that are already affected. It complements backups and updates rather than replacing them.
How do I spot the email that delivers ransomware?
Warning signs: an unexpected attachment (especially .zip, .exe or a document asking you to «enable macros»), urgency and pressure, a sender address that doesn't match the organization, and links pointing to unrelated domains. When in doubt, don't open it and contact the sender another way.
