Lesson 3 of 7 · 8 min
Ransomware: why backups beat paying
Ransomware locks or steals your files and sells them back to you. Understand how it works, why paying is a gamble, and the backup routine that takes away its power.
Ransomware is malicious software that takes something you value hostage and demands payment to give it back. Classic ransomware encrypts files, turning family photos, client documents or a company’s entire file server into unreadable data, then shows a note explaining how to pay, usually in cryptocurrency, to receive the decryption key. MITRE ATT&CK files this behaviour under “data encrypted for impact”: the encryption is not there to protect anything, only to deny you access.
How an attack unfolds
Ransomware rarely appears out of nowhere. The US Cybersecurity and Infrastructure Security Agency (CISA) describes the common entry points in its #StopRansomware guide: phishing emails, stolen or weak passwords for remote access, and unpatched vulnerabilities in internet-facing systems. On a personal computer, a trojan or a malicious download is the usual first step. Once inside, attackers frequently spend time looking around, disabling backups they can reach and copying valuable data, before triggering the encryption that the victim finally notices.
Double extortion: steal first, then lock
Backups made ransomware less profitable, so criminal groups adapted. Many now copy data away before encrypting it, then threaten to publish it if the victim refuses to pay. CISA calls this double extortion. It changes the calculation for businesses and individuals alike: a good backup gets your files back, but it does not undo a leak. That is why the outbound part of an attack matters as much as the encryption, and why seeing large or unusual uploads from a machine is a meaningful warning sign.
Why paying is a gamble
CISA and the FBI advise against paying ransoms. Payment does not guarantee a working decryption key, the tools criminals provide are sometimes slow or broken, and a copy of stolen data may still be sold or published later. Paying also funds the next attack and marks the victim as someone willing to pay. There can be legal risks too, depending on who receives the money. Before considering anything else, check the No More Ransom project, a collaboration between law enforcement and security companies that publishes free decryption tools for ransomware families whose encryption has been broken.
The 3-2-1 backup rule
Nothing weakens ransomware like a backup the attacker cannot reach. The long-standing 3-2-1 rule, recommended in CISA’s guidance on backups, is simple to remember:
- 3 copies of your important data: the original and two backups.
- 2 different kinds of storage, for example an external drive and a cloud service.
- 1 copy kept offline or off-site, disconnected from the computer, so ransomware on the Mac cannot encrypt it too.
On a Mac, Time Machine to an external drive covers the first part well; unplugging that drive when the backup is done keeps it out of reach. A second copy in a cloud service that keeps previous versions of files helps if the synced copy is overwritten with encrypted files. And a backup is only real once you have tested restoring from it: pick a file every few months and bring it back.
| Situation | With good backups | Without backups |
|---|---|---|
| Files encrypted | Wipe, reinstall, restore: hours of work, no ransom | Pay and hope, or lose the files |
| Files also stolen | Files restored; still need to handle the leak (passwords, clients, authorities) | Both problems at once |
| Backup drive was connected during the attack | That copy may be encrypted too; the offline copy saves you | Nothing to fall back on |
What FileVault and cloud sync do, and do not, do
Two Mac features are often mistaken for ransomware protection. FileVault encrypts your disk so that a thief who steals the Mac cannot read it; it does nothing against ransomware running inside your logged-in account, which sees your files decrypted just like you do. Cloud sync services such as iCloud Drive keep your files the same everywhere, which means an encrypted file can be synced over the good copy on your other devices. Sync is not a backup. What helps is version history, where the service keeps earlier versions of each file for a while, and a real backup that sync cannot touch.
Reducing the chance of an attack
- Keep macOS and apps up to date; many ransomware intrusions start with a known, already patched flaw.
- Use unique passwords and two-factor authentication, especially for remote access and email.
- Be suspicious of attachments and links, even from people you know.
- Do not install cracked software or unverified tools.
- Turn off sharing services you do not use, such as File Sharing and Remote Login.
Where a firewall helps
A firewall cannot decrypt files and FireAI does not remove ransomware. What it can do is limit the steps around the encryption. Ransomware and the tools that deliver it usually need to download components and contact their operators, and double extortion needs to upload your data. FireAI asks before an unknown app connects, shows where each app sends data on the world map, and its Paranoid and Under attack modes restrict what can connect at all. If you suspect an active attack, the kill switch cuts the Mac off from the internet in one click while you disconnect backups and get help.
If it happens
- Disconnect the computer from the network and unplug any backup drives.
- Do not delete the ransom note; take a photo of it. It helps identify the ransomware family.
- Check No More Ransom for a free decryptor.
- Report it: in the US to the FBI’s Internet Crime Complaint Center (IC3), elsewhere to your national cybercrime authority.
- Restore from a clean, offline backup onto a freshly reinstalled system.
- Change passwords from a clean device, especially if data may have been stolen.
Key takeaways
- Ransomware encrypts or steals files and demands payment; many groups now do both (double extortion).
- CISA and the FBI advise against paying: it does not guarantee recovery and funds further attacks.
- The 3-2-1 rule, with one offline copy, is the most effective defence against losing files.
- A backup only counts once you have tested restoring from it.
Check yourself
1. What does “double extortion” mean in ransomware attacks?
- The ransom is doubled after a deadline
- Data is copied away before encryption, and the attacker threatens to publish it as well as keeping it locked — Right.
- Two different ransomware programs attack at once
- The victim is asked to pay in two currencies
Criminals steal data first so that even victims with good backups face a leak, giving them a second reason to pay.
2. Why does the 3-2-1 rule require one copy to be offline or off-site?
- Offline storage is cheaper
- Ransomware on the computer can encrypt any backup it can reach, so an unreachable copy survives — Right.
- Cloud services do not allow backups
- It makes backups faster
A drive left connected can be encrypted along with the original files. A disconnected copy is out of the attacker’s reach.
3. Before considering paying a ransom, what free resource should you check?
- A search engine for “ransom discount”
- The No More Ransom project, which publishes free decryptors for some ransomware families — Right.
- The attacker’s support chat
- Your computer’s warranty
No More Ransom, run with law enforcement and security companies, offers free decryption tools where a ransomware family’s encryption has been broken.
Do it with FireAI
Put this lesson into practice on your own Mac.
- Rules: app, website, domain, IP or a range, forever or until you restart — Write a rule as precise as one address or as broad as an entire domain.
- The World map — See where your data actually goes, not just a hostname you’d have to look up yourself.
- Threat lists (opt-in) — Check your traffic against public threat data without sending it anywhere.
- Investigate a connection — Decide with the facts in front of you, not a vague warning.
- Security modes: Home, Coffee shop, Paranoid, Under attack — Match FireAI’s strictness to where your Mac actually is, in one tap.
- USB Network Protection: nothing from a USB drive goes online unasked — Plug in a drive someone handed you without letting what’s on it phone home.
Sources
- CISA: #StopRansomware Guide
- MITRE ATT&CK T1486: Data Encrypted for Impact
- No More Ransom (law enforcement and industry decryption tools)
- CISA / US-CERT: Data Backup Options
- Apple Support: Back up your Mac with Time Machine
- FBI Internet Crime Complaint Center (IC3)
Put it into practice on your Mac
Try every feature free for 17 days, no card needed.