If ransomware has locked your files, do not pay. Disconnect the device from the internet and any network immediately so it cannot spread, do not delete the ransom note or the encrypted files, and photograph the ransom message with the time. Then check the free No More Ransom project run by Europol at nomoreransom.org to see whether a free decryptor already exists for your strain, and report the attack to the 1930 cybercrime helpline and at cybercrime.gov.in. Both CERT-In and the FBI advise against paying, because payment does not guarantee your files come back and it funds the next attack. Recovery from clean, offline backups plus free decryption tools is the safest path. This guide explains what ransomware is, how it reaches ordinary Indians and small businesses, exactly what to do in the first hour, and the basics that stop it happening again.
Who this is for
Anyone in India whose computer or phone suddenly shows a message demanding payment to get their files back, and anyone who wants to avoid that happening. That includes home users with family photos and documents, freelancers and students, and above all small and medium businesses: clinics, shops, chartered accountants, small manufacturers, schools, and startups. Small firms are hit hard because they hold valuable data (customer records, invoices, designs, patient files) but often run unpatched servers, shared passwords, and no tested backups. You do not have to be a big company to be a target. Automated attacks scan the internet and hit whatever is exposed.
What ransomware actually is
Ransomware is malicious software that locks you out of your own data. Most strains encrypt your files, scrambling them so they cannot be opened, and leave a note demanding a payment, usually in cryptocurrency like Bitcoin, in exchange for a decryption key. Some simpler versions just lock the screen. The demand often comes with a countdown timer and a threat to delete the files or raise the price.
Two things make it dangerous. First, strong encryption cannot be reversed without the key, so without a backup or a free decryptor your files may be unrecoverable. Second, many groups now steal a copy of your data before encrypting it, a tactic called double extortion, so they can threaten to leak it even if you restore from backup. Ransomware is a business for organised criminal groups, and the people running it are not going to keep their word because you paid.
Why this matters now in India
Ransomware is not a rare, foreign problem. It is a large and growing threat inside India, aimed increasingly at smaller organisations.
- CERT-In, India’s national computer emergency response team, reported a surge in ransomware in 2024 targeting internet-exposed database servers, virtualisation servers, and network storage devices, with groups such as Mallox brute-forcing exposed Microsoft SQL databases to deploy their payload. See the official CERT-In India Ransomware Report 2024.
- The CyberPeace Foundation tracked 98 publicly known ransomware incidents affecting Indian organisations in 2024, a 55 percent rise over the 63 the year before, with the industrial sector taking about 75 percent of attacks, healthcare next at around 12 percent, and finance about 10 percent, per its Ransomware Trends 2024 analysis.
- The Data Security Council of India (DSCI) reported that India saw on the order of one million ransomware detections in 2024 in its India Cyber Threat Report 2025, reflecting how much of the activity is automated and widespread.
- CERT-In handled over 29 lakh cyber incidents in 2025 overall, including large volumes of malicious-code infections, per a Press Information Bureau note on its work.
These counts largely reflect reported and publicly known cases, mostly from organisations. Individual and small-business infections are widely under-reported, so the real number of people affected is higher. The point is not the exact figure. It is that this is common, it is hitting Indian small businesses, and the defences are the same whether you are a household or a firm.
How ransomware reaches ordinary people and small businesses
Almost every infection starts with one of a handful of everyday routes.
- Phishing. An email, SMS, or WhatsApp message carries an infected attachment or a link, disguised as an invoice, a resume, a courier or delivery notice, a bank alert, or a tax document. Opening the attachment or the file behind the link starts the infection.
- Pirated and cracked software. Cracked Windows, Office, design tools, and games, along with the key generators and activators that come with them, are a classic delivery method. The crack you download to save money often installs the malware that locks your data.
- Fake apps. Apps installed from outside the Google Play Store or Apple App Store, especially fake loan, banking, KYC, or reward apps, can carry mobile ransomware or the malware that leads to it. Android is more exposed here because it allows sideloading.
- Exposed servers and remote access. Small businesses that put a database, remote desktop, or network storage device directly on the internet, often without updates or strong passwords, get found by automated scanners and brute-forced. This is the pattern CERT-In highlighted for 2024.
- Infected USB drives and malicious ads. Shared USB sticks and poisoned online advertisements round out the common routes.
The single strongest habit against all of these: install software and apps only from official sources, and never open an unexpected attachment or link, even if it appears to come from someone you know.
What to do the moment you are hit
If a ransom message appears, act in this order. Speed limits the damage.
- Disconnect immediately. Unplug the network cable and turn off Wi-Fi on the affected device so the ransomware cannot spread to other computers or shared drives. If it is a work network, isolate the machine from the rest.
- Do not pay, and do not delete anything. Keep the ransom note and the encrypted files. They are needed to identify the strain and to check for a free decryptor.
- Preserve evidence. Photograph the ransom message. Note the exact time. Save any suspicious email, SMS, or file that came just before the lock.
- Protect your backups. Disconnect external drives and USB sticks that were not already attached, so a clean backup survives untouched.
- Check other devices. Look at every computer on the same network. Isolate any that show signs of infection.
- Check No More Ransom. Go to nomoreransom.org, use the Crypto Sheriff tool, and see whether a free decryptor exists for your strain before you consider anything else.
- Report. Call the 1930 helpline and file at cybercrime.gov.in. If you are a registered organisation, also report to CERT-In within six hours per its directions.
- Restore from a clean backup once the device is wiped and confirmed clean, or seek qualified help if you are unsure.
Why paying rarely works
Paying feels like the fast way out. It usually is not. CERT-In advises that victims are not encouraged to pay, because it does not guarantee the files are released, and the FBI’s ransomware guidance says the same: some victims who paid were never sent a working key, and payment does not stop stolen data from being leaked. The decryption tools attackers provide are often slow or buggy and can corrupt files. Double-extortion groups may leak your data whether or not you pay. And every payment funds the next attack and marks you as someone who pays, inviting a repeat. You are negotiating with a criminal who has already lied to you once.
Can you decrypt your files for free?
Often, yes, and you should always check before doing anything else. The No More Ransom project, run by Europol, the Dutch National Police, and security companies including Kaspersky, offers more than 130 free decryption tools covering many known ransomware families, and the tools have been downloaded by millions of people worldwide. Upload the ransom note or a sample encrypted file to the Crypto Sheriff tool on the site, and it will tell you whether a free decryptor exists for your strain and give step-by-step instructions. The portal works from India and is available in many languages. If no tool exists yet, keep a copy of the encrypted files, because new decryptors are released regularly and one may appear for your strain later.
The prevention basics that actually work
Most ransomware is stopped by a small set of unglamorous habits, drawn from CERT-In and Cyber Swachhta Kendra guidance:
- Keep offline backups and test them. Follow the 3-2-1 rule: three copies, two types of media, one kept offline or offsite. The disconnected copy is the one ransomware cannot encrypt. Test that you can actually restore.
- Update everything promptly. Ransomware exploits known, unpatched flaws. Turn on automatic updates for your operating system and apps.
- Use strong, unique passwords and multi-factor authentication on email, accounting, and admin accounts.
- Install only from official sources. No pirated software, no sideloaded apps, no attachments from strangers.
- Do not expose servers to the internet. Keep databases, remote desktop, and network storage behind protection, not open to the world.
- Limit permissions. Use role-based access so one compromised account cannot reach everything.
- Train the people around you. Most attacks start with a human click. A short talk about phishing and pirated software goes a long way.
How to report and get help in India
These channels are free and operate 24x7.
- 1930. The national cybercrime helpline, operated by the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs. Call it as soon as you are hit.
- cybercrime.gov.in. File a formal complaint online. Keep the acknowledgement number.
- CERT-In. Registered organisations and critical infrastructure operators must report cyber incidents, including ransomware, to CERT-In within six hours per its Section 70B directions, at incident@cert-in.org.in.
- No More Ransom. Check for a free decryptor before considering payment.
- Cybersecify WhatsApp helpline: +91 99644 43350. If you are unsure whether a message or file is a threat, or you have just been hit and need a plain-language sanity check on what to do next, send it to us. Verification is free. We do not ask for your passwords, OTPs, or UPI PIN, and we never charge citizens for the sanity check.
Save the 1930 number and the WhatsApp number now. During an active incident, you will not have time to search.
Related guides
If ransomware reached you, the same habits protect you from the other scams out there. We publish related citizen-safety guides:
- The First Hour After Cyber Fraud in India, on what to do in the first 60 minutes after any cyber incident.
- Pause, Verify, Then Act, the universal three-rule defence against every scam type.
- Fake Loan App Scams in India, a common route for mobile malware.
- Digital Arrest Scams and UPI and QR Code Fraud, the two highest-loss scam categories in India right now.
- Your Digital Footprint Is the Scam’s Raw Material, on why attackers already know enough about you to target you.
The bottom line
Ransomware is common, it targets Indian households and small businesses, and it feels catastrophic in the moment. It usually is not the end. Disconnect, do not pay, preserve the evidence, check No More Ransom for a free decryptor, restore from a clean backup, and report to 1930 and cybercrime.gov.in. Then close the door behind you with offline backups, prompt updates, and official-source-only software. The shame belongs to the criminal, not to you. The response that protects you is fast, calm, and free.