• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Techransomware

How to Stop Hackers From Taking Over Your Computer

By
Haley Sweetland Edwards
Down Arrow Button Icon
By
Haley Sweetland Edwards
Down Arrow Button Icon
April 21, 2016, 8:03 PM ET
Online Crime
BERLIN, GERMANY - AUGUST 20: Symbolic feature with topic online crime, data theft and piracy and hacker, here the silhouette of a person with a laptop in his hands, on Augut 20, 2015 in Berlin, Germany. (Photo by Thomas Trutschel/Photothek via Getty Images)Photography by Thomas Trutschel Photothek via Getty Images

Grayson Barnes had just started working at his father’s law firm in Tulsa, Oklahoma when a note popped-up on one of the computer screens. It informed him that all the files on the firm’s digital network had been encrypted and were being held ransom. If he ever wanted to access them again, he had to pay $500, in the Internet currency Bitcoin, within five days. If he didn’t, the note concluded, everything would be destroyed.

“It wasn’t just a day’s worth of work,” Barnes told TIME. “It was the entire library of documents, all the Word documents, all the Excel.”

Uncertain of what to do next, Barnes called the police and then the Federal Bureau of Investigations. Everyone he spoke to told him the same thing: there was nothing they could do.

If he paid the $500, there was no guarantee he’d get the files back, they said. But if he didn’t pay, there was no way to save the firm’s data and, because many of these sorts of cybercriminals live abroad, there’s no way for the police or the FBI to prosecute the attackers. “They said, basically, ‘Look, we can’t help you,’” Barnes said. Two days later, the firm paid up.

Get Data Sheet, Fortune’s technology newsletter.

And that, cybersecurity experts say, is why so-called “ransomware” attacks have become so ubiquitous in the last two years: they’re relatively low-budget, low stakes, and don’t require much skill to pull off. Instead of going after high-value, heavily fortified systems, like banks or corporations, that require complex technological skills to hack, cybercriminals use ransomware to go straight for easy targets: small businesses, schools, hospitals, and Joe Blow computer users like us, who are likely to pay a few hundred—or a few thousand—bucks to get our digital lives back.

“It’s a one-to-one relationship with the victim, and it’s anonymous,” said Juan Guerrero, a senior security researcher at Kaspersky Lab, a cybersecurity company that fielded 750,000 attacks last year, just among its own clients.

While each type of ransomware virus is different, some, like CryptoLocker, boasted a 41% “success rate”—meaning that more than a third of victims ended up paying the ransom, according to a survey in the United Kingdom by the University of Kent. That virus earned between $3 million and $27 million for its criminal overlords, according to various estimates.

While there’s no central clearinghouse that keeps of every ransomware attack, cybersecurity experts estimate that there are several million attacks on American computers a year. The average victim shells out about $300, according to a study by the global cybersecurity firm Symantec. But that adds up overtime.

In 2014, for example, one version of ransomware, CryptoWall, infected more than 625,000 computers worldwide, including a quarter million in the U.S., according to Dell Inc., and earning hackers roughly $1 million in just six months.

Between April 2014 and June 2015, the Internet Crime Complaint Center, a partnership between the nonprofit National White Collar Crime Center and the FBI, received 992 complaints about another version of ransomware, Cryptowall, in which victims reported losses of more than $18 million. Some cybersecurity experts estimate that hackers are earning north of $70,000 a month on ransomware.

With that much money flowing in, ransomware is on the rise. “These sorts of attacks are absolutely increasing,” Guerrero said.

According to Symantec, there was a 250% increase in new ransomware available on the black market between 2013 and 2014, and by 2015, the underground ransomware industry had begun to mimic the way modern software is developed: there are criminal engineers and manufacturers, retailers, and “consumers”—hackers on the lookout for the newest, most effective product.

Some criminals, who are usually based in Russia, Ukraine, Eastern Europe and China, have begun licensing what’s known as “exploit kits”—all-inclusive ransomware apps—to individual hackers for a couple hundred dollars a week.

U.S. Hospitals Face Growing Ransomware Threat

As with most computer viruses, victims are often first targeted with a fraudulent email. If hackers can get victims to open an email and then download an attachment, then they can infiltrate their computer—and any computer associated with that computer’s network. Roughly 23% of people open phishing messages, according to a 2015 data-breach report from Verizon Enterprise Solutions. More than 10% then click on the attachments.

Victims can also have their computers infected merely by visiting a compromised website—no download required—or joining an infected network. Sites that are the most likely to get people in trouble are those peddling pirated movies, TV and sports games, pornography, or networks like Tor that facilitate sharing of huge numbers of user files. PC users are generally more vulnerable to ransomware than Mac users in part because there are more PCs in the world. From a criminal’s perspective, malware designed to exploit a PC offers access to more potential victims.

Ransomware viruses have gotten more sophisticated in recent years, experts say. For example, some versions of ransomware are now designed to seek out the files on a victim’s computer that are most likely to be precious, such as a large number of old photographs, for example, tax filings, or financial worksheets. Other versions use social engineering tricks to make a victim feel guilt or shame—and therefore more likely to pay the ransom. Some appear to be official notices from the FBI or a cyber law enforcement agency claiming to know that a victim recently watched illegal porn, bought drug paraphernalia, or downloaded a pirated movie. In some particularly alarming cases, ransom notes come in over a computer’s speakers: the booming voice of a stranger demanding a Bitcoin payment echoes through the victim’s living room.


This Malicious Software Can Hold Your Data for Ransom

In the past year, ransomware attacks have shut down at least three health care centers, including one hospital in Los Angeles that paid $17,000 to regain access to its patients’ records. In March, MedStar Health, the massive, $5 billion health care juggernaut that operates 10 hospitals in the Washington, DC region, saw its computer system knocked offline for days in what some employees characterized as a ransomware attack.

Police departments, school districts, and small businesses, like Barnes’ law firm have also been recent targets, in part because they have less sophisticated security systems. According to Intel Security, 80% of small and medium-sized businesses don’t use data protection and fewer than half secure their email.

The only way to protect against a ransomware attack is rote: keep your operating system up to date, renew your anti-virus software regularly, back up your files on a daily or weekly basis, and never download anything from an email address you don’t recognize. Many cybersecurity experts warn that people should be particularly skeptical of emails with attachments that appear to be from trusted brands, like FedEx or Amtrak, when they arrive unexpectedly.

Once a computer has been infected with ransomware, there’s often very little that a consumer can do, said Robert Siciliano, the CEO of ID Theft Security.com. With some, limited variations of ransomware, law enforcement have the tools to reverse and remove the virus. But in most cases, victims are stuck between a rock and a hard place.

If a victim pays a ransom and the files are not restored, there’s no way to demand a refund. Most ransomware schemes require Bitcoin payments to be routed through file-sharing technologies, so law enforcement officials can’t usually identify where the money went. Like many in the cybersecurity world, Siciliano advises not paying the ransom in the first place. That money, he says, ends up funding newer, more innovative variations of the virus.

Barnes says he doesn’t feel great about having paid the $500 ransom for his law firm’s files, but given the situation, he and his colleagues didn’t have much of a choice. “Everything is backed up now,” he said. “It’s not happening again.”

About the Author
By Haley Sweetland Edwards
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

Latest in Tech

Man wearing a black suit with a microphone
InvestingMicrostrategy
Michael Saylor’s Strategy flirts again with the danger threshold at which his company is worth less than his Bitcoin
By Jim EdwardsJanuary 2, 2026
15 hours ago
Musk
Travel & LeisureElectric vehicles
Tesla is officially smaller than China’s BYD in EV sales as it reports second-straight year of falling sales
By Nick LichtenbergJanuary 2, 2026
15 hours ago
blondie
Lawintellectual property
Betty Boop and Blondie join Mickey Mouse and Winnie the Pooh in the public domain
By Andrew Dalton and The Associated PressJanuary 2, 2026
16 hours ago
Eric Simons
Commentarystart-ups
15 years after skipping college to launch 3 startups, I believe the taboo around questioning higher ed is holding an entire generation back
By Eric SimonsJanuary 2, 2026
17 hours ago
Eric Schmidt sat in a white chair, speaking on a stage.
AIGoogle
How former Google CEO Eric Schmidt is motivated by Henry Kissinger to keep working past 70
By Jordan BlumJanuary 2, 2026
18 hours ago
Eric Schmidt, former Google CEO, speaks during the Collision 2022 conference at Enercare Centre in Toronto, Canada.
AIElectricity
Google ex-CEO Eric Schmidt jumps into the AI data center business with a failed, 150-year-old Texas railroad turned oil giant
By Jordan BlumJanuary 2, 2026
19 hours ago

Most Popular

placeholder alt text
Success
Marriott’s CEO spoke out about DEI. The next day, he had 40,000 emails from his associates
By Ashley LutzJanuary 1, 2026
2 days ago
placeholder alt text
Success
Melinda French Gates got her start at Microsoft because an IBM hiring manager told her to turn down its job offer—'It dumbfounded me'
By Emma BurleighDecember 31, 2025
3 days ago
placeholder alt text
Politics
Buddhist monks peace-walking from Texas to DC persist even after being run over on highway outside Houston
By The Associated PressDecember 30, 2025
3 days ago
placeholder alt text
Success
Red Lobster’s 36-year-old CEO led the company after bankruptcy. Now he’s plotting the 'greatest comeback in the history of the restaurant industry'
By Sydney LakeJanuary 2, 2026
19 hours ago
placeholder alt text
Banking
Man says Goldman Sachs put him through a gauntlet of 39 one-on-one interviews—and the decisive conversation was less than a minute
By Dave SmithJanuary 2, 2026
20 hours ago
placeholder alt text
C-Suite
Exiting CEO left each employee at his family-owned company a $443,000 gift—but they have to stay 5 more years to get all of it
By Nick LichtenbergDecember 30, 2025
4 days ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.