Ransomware has gone from a niche threat to one of the most common causes of catastrophic data loss for individuals and businesses alike. It's simple in concept and devastating in effect: malicious software encrypts your files and demands payment for the key. In 2026 the attacks are more targeted and more professional than ever. This guide explains what ransomware is, how it spreads, how to prevent it, exactly what to do if you're hit, and where data recovery fits into the picture.
From the engineers at CBL Data Recovery Singapore, who help businesses and individuals recover after attacks.
What ransomware actually is
Ransomware is malware that encrypts your files β documents, photos, databases, backups it can reach β and then displays a ransom note demanding payment (usually in cryptocurrency) for the decryption key. Some strains also steal a copy of your data first and threaten to publish it unless you pay, a tactic called "double extortion."
The crucial point: once files are properly encrypted with a strong key the attacker controls, they cannot be brute-forced open. That's what makes ransomware so dangerous β and why prevention and backups matter far more than any cure.

How ransomware spreads
Most infections arrive through a handful of well-worn routes:
- Phishing emails β a malicious attachment or link that installs the malware when opened. Still the number-one entry point.
- Compromised remote access β weak or reused passwords on remote desktop (RDP) and VPNs let attackers walk straight in.
- Unpatched software β known vulnerabilities in operating systems and applications that were never updated.
- Malicious downloads and fake updates β software from untrusted sources, or "update now" pop-ups that are really malware.
- Lateral movement β once inside one machine, ransomware spreads across the network, which is why a single click can take down an entire office.
How to prevent ransomware attacks
There's no single silver bullet β prevention is about layers. The ones that matter most:
- Back up properly β the 3-2-1 rule. Three copies, on two media, one off-site. Critically, keep at least one offline or immutable backup the ransomware can't reach. This is your ultimate safety net.
- Patch everything. Keep operating systems and applications up to date to close the holes attackers exploit.
- Lock down remote access. Strong, unique passwords, multi-factor authentication, and no exposed RDP.
- Train people. Most attacks start with a click. Teach staff (and yourself) to spot phishing.
- Least privilege and segmentation. Limit what each account and machine can reach, so one infection can't spread everywhere.
- Endpoint protection with behavioural detection to catch attacks in progress.
The single most valuable of these is backups β because a good, isolated backup turns a ransomware attack from a catastrophe into an inconvenience.
Ransomware deliberately seeks out and encrypts connected backups β network drives, always-on external disks, even some cloud sync. A backup that's permanently connected is a backup that can be encrypted too. Keep at least one copy offline or immutable, and test that you can actually restore from it. See our ransomware data recovery service.
What to do if you're hit
The first hour matters. Stay calm and work through this:
- Isolate immediately. Disconnect the affected machine(s) from the network and Wi-Fi to stop the spread. Don't shut everything down blindly β isolate first.
- Don't pay reflexively. Paying funds crime, doesn't guarantee a working key, and marks you as a target for repeat attacks. Treat it as a last resort, and get advice first.
- Identify the strain. Some older ransomware families have free, legitimate decryptors available. Note the ransom note and encrypted file extensions.
- Preserve everything. Don't delete the encrypted files or wipe the machine β recovery may depend on them, and they're evidence if you report the crime.
- Restore from a clean, offline backup once the threat is removed and you're sure the malware is gone.
- Get professional help for anything beyond a simple restore β especially on servers and RAID.
Where data recovery fits in
Data recovery is part of ransomware response, but it's important to be honest about what it can and can't do:
- It can recover files lost to the collateral damage of an attack β corrupted volumes, damaged RAID arrays, formatted drives, and files deleted in the chaos.
- It can sometimes decrypt files hit by older or flawed ransomware strains that have known weaknesses or public decryptors.
- It cannot brute-force strong, correctly-implemented encryption. When files are properly encrypted with a key only the attacker holds, no lab can magic them open β which is exactly why isolated backups are non-negotiable.
A recovery lab is most valuable for restoring the systems and data around an attack, and for giving you an honest assessment of what's recoverable so you can make good decisions.

Individuals aren't exempt
Ransomware isn't only a corporate problem. Home users lose family photos and personal documents to it too β usually via phishing or a malicious download, and often with their only "backup" being an always-connected external drive that got encrypted along with everything else. The same rules apply: keep an offline backup, be wary of unexpected attachments, and keep your system updated.
When to call a lab
Call a lab when ransomware has hit a server or RAID array, when the attack corrupted or damaged your storage beyond a simple restore, when you need an honest assessment of whether encrypted files can be recovered, or when your backups also fell victim. Preserve the affected systems, isolate them, and get a professional diagnosis before making irreversible decisions.
CBL's ISO-certified lab helps individuals and businesses recover data and systems after ransomware attacks β free diagnosis, fixed quote before any work.
- WhatsApp: +65 8127 7508
- Call: +65 6588 0261

The bottom line
Ransomware encrypts your files and demands payment, spreads mostly through phishing and unpatched or exposed systems, and can't be undone once strong encryption is in place. That's why the winning strategy is prevention plus backups: patch, lock down remote access, train people, and β above all β keep an isolated, tested backup the malware can't reach. If you are hit, isolate first, don't rush to pay, preserve everything, and get professional help. A good backup is the difference between a bad day and a business-ending disaster.
