Scam Awareness

Ransomware Attack in India 2026: What To Do

Hit by ransomware in India? Do not pay. Disconnect, save evidence, report to 1930 and cybercrime.gov.in. Free decryption tools and prevention basics.

SS&AK
Sai Samarth & Ashok Kamat
Cybersecify
17 min read

If ransomware has locked your files, do not pay. Disconnect the device from the internet and any network immediately so it cannot spread, do not delete the ransom note or the encrypted files, and photograph the ransom message with the time. Then check the free No More Ransom project run by Europol at nomoreransom.org to see whether a free decryptor already exists for your strain, and report the attack to the 1930 cybercrime helpline and at cybercrime.gov.in. Both CERT-In and the FBI advise against paying, because payment does not guarantee your files come back and it funds the next attack. Recovery from clean, offline backups plus free decryption tools is the safest path. This guide explains what ransomware is, how it reaches ordinary Indians and small businesses, exactly what to do in the first hour, and the basics that stop it happening again.

Who this is for

Anyone in India whose computer or phone suddenly shows a message demanding payment to get their files back, and anyone who wants to avoid that happening. That includes home users with family photos and documents, freelancers and students, and above all small and medium businesses: clinics, shops, chartered accountants, small manufacturers, schools, and startups. Small firms are hit hard because they hold valuable data (customer records, invoices, designs, patient files) but often run unpatched servers, shared passwords, and no tested backups. You do not have to be a big company to be a target. Automated attacks scan the internet and hit whatever is exposed.

What ransomware actually is

Ransomware is malicious software that locks you out of your own data. Most strains encrypt your files, scrambling them so they cannot be opened, and leave a note demanding a payment, usually in cryptocurrency like Bitcoin, in exchange for a decryption key. Some simpler versions just lock the screen. The demand often comes with a countdown timer and a threat to delete the files or raise the price.

Two things make it dangerous. First, strong encryption cannot be reversed without the key, so without a backup or a free decryptor your files may be unrecoverable. Second, many groups now steal a copy of your data before encrypting it, a tactic called double extortion, so they can threaten to leak it even if you restore from backup. Ransomware is a business for organised criminal groups, and the people running it are not going to keep their word because you paid.

Why this matters now in India

Ransomware is not a rare, foreign problem. It is a large and growing threat inside India, aimed increasingly at smaller organisations.

  • CERT-In, India’s national computer emergency response team, reported a surge in ransomware in 2024 targeting internet-exposed database servers, virtualisation servers, and network storage devices, with groups such as Mallox brute-forcing exposed Microsoft SQL databases to deploy their payload. See the official CERT-In India Ransomware Report 2024.
  • The CyberPeace Foundation tracked 98 publicly known ransomware incidents affecting Indian organisations in 2024, a 55 percent rise over the 63 the year before, with the industrial sector taking about 75 percent of attacks, healthcare next at around 12 percent, and finance about 10 percent, per its Ransomware Trends 2024 analysis.
  • The Data Security Council of India (DSCI) reported that India saw on the order of one million ransomware detections in 2024 in its India Cyber Threat Report 2025, reflecting how much of the activity is automated and widespread.
  • CERT-In handled over 29 lakh cyber incidents in 2025 overall, including large volumes of malicious-code infections, per a Press Information Bureau note on its work.

These counts largely reflect reported and publicly known cases, mostly from organisations. Individual and small-business infections are widely under-reported, so the real number of people affected is higher. The point is not the exact figure. It is that this is common, it is hitting Indian small businesses, and the defences are the same whether you are a household or a firm.

How ransomware reaches ordinary people and small businesses

Almost every infection starts with one of a handful of everyday routes.

  1. Phishing. An email, SMS, or WhatsApp message carries an infected attachment or a link, disguised as an invoice, a resume, a courier or delivery notice, a bank alert, or a tax document. Opening the attachment or the file behind the link starts the infection.
  2. Pirated and cracked software. Cracked Windows, Office, design tools, and games, along with the key generators and activators that come with them, are a classic delivery method. The crack you download to save money often installs the malware that locks your data.
  3. Fake apps. Apps installed from outside the Google Play Store or Apple App Store, especially fake loan, banking, KYC, or reward apps, can carry mobile ransomware or the malware that leads to it. Android is more exposed here because it allows sideloading.
  4. Exposed servers and remote access. Small businesses that put a database, remote desktop, or network storage device directly on the internet, often without updates or strong passwords, get found by automated scanners and brute-forced. This is the pattern CERT-In highlighted for 2024.
  5. Infected USB drives and malicious ads. Shared USB sticks and poisoned online advertisements round out the common routes.

The single strongest habit against all of these: install software and apps only from official sources, and never open an unexpected attachment or link, even if it appears to come from someone you know.

What to do the moment you are hit

If a ransom message appears, act in this order. Speed limits the damage.

  1. Disconnect immediately. Unplug the network cable and turn off Wi-Fi on the affected device so the ransomware cannot spread to other computers or shared drives. If it is a work network, isolate the machine from the rest.
  2. Do not pay, and do not delete anything. Keep the ransom note and the encrypted files. They are needed to identify the strain and to check for a free decryptor.
  3. Preserve evidence. Photograph the ransom message. Note the exact time. Save any suspicious email, SMS, or file that came just before the lock.
  4. Protect your backups. Disconnect external drives and USB sticks that were not already attached, so a clean backup survives untouched.
  5. Check other devices. Look at every computer on the same network. Isolate any that show signs of infection.
  6. Check No More Ransom. Go to nomoreransom.org, use the Crypto Sheriff tool, and see whether a free decryptor exists for your strain before you consider anything else.
  7. Report. Call the 1930 helpline and file at cybercrime.gov.in. If you are a registered organisation, also report to CERT-In within six hours per its directions.
  8. Restore from a clean backup once the device is wiped and confirmed clean, or seek qualified help if you are unsure.

Why paying rarely works

Paying feels like the fast way out. It usually is not. CERT-In advises that victims are not encouraged to pay, because it does not guarantee the files are released, and the FBI’s ransomware guidance says the same: some victims who paid were never sent a working key, and payment does not stop stolen data from being leaked. The decryption tools attackers provide are often slow or buggy and can corrupt files. Double-extortion groups may leak your data whether or not you pay. And every payment funds the next attack and marks you as someone who pays, inviting a repeat. You are negotiating with a criminal who has already lied to you once.

Can you decrypt your files for free?

Often, yes, and you should always check before doing anything else. The No More Ransom project, run by Europol, the Dutch National Police, and security companies including Kaspersky, offers more than 130 free decryption tools covering many known ransomware families, and the tools have been downloaded by millions of people worldwide. Upload the ransom note or a sample encrypted file to the Crypto Sheriff tool on the site, and it will tell you whether a free decryptor exists for your strain and give step-by-step instructions. The portal works from India and is available in many languages. If no tool exists yet, keep a copy of the encrypted files, because new decryptors are released regularly and one may appear for your strain later.

The prevention basics that actually work

Most ransomware is stopped by a small set of unglamorous habits, drawn from CERT-In and Cyber Swachhta Kendra guidance:

  • Keep offline backups and test them. Follow the 3-2-1 rule: three copies, two types of media, one kept offline or offsite. The disconnected copy is the one ransomware cannot encrypt. Test that you can actually restore.
  • Update everything promptly. Ransomware exploits known, unpatched flaws. Turn on automatic updates for your operating system and apps.
  • Use strong, unique passwords and multi-factor authentication on email, accounting, and admin accounts.
  • Install only from official sources. No pirated software, no sideloaded apps, no attachments from strangers.
  • Do not expose servers to the internet. Keep databases, remote desktop, and network storage behind protection, not open to the world.
  • Limit permissions. Use role-based access so one compromised account cannot reach everything.
  • Train the people around you. Most attacks start with a human click. A short talk about phishing and pirated software goes a long way.

How to report and get help in India

These channels are free and operate 24x7.

  • 1930. The national cybercrime helpline, operated by the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs. Call it as soon as you are hit.
  • cybercrime.gov.in. File a formal complaint online. Keep the acknowledgement number.
  • CERT-In. Registered organisations and critical infrastructure operators must report cyber incidents, including ransomware, to CERT-In within six hours per its Section 70B directions, at incident@cert-in.org.in.
  • No More Ransom. Check for a free decryptor before considering payment.
  • Cybersecify WhatsApp helpline: +91 99644 43350. If you are unsure whether a message or file is a threat, or you have just been hit and need a plain-language sanity check on what to do next, send it to us. Verification is free. We do not ask for your passwords, OTPs, or UPI PIN, and we never charge citizens for the sanity check.

Save the 1930 number and the WhatsApp number now. During an active incident, you will not have time to search.

If ransomware reached you, the same habits protect you from the other scams out there. We publish related citizen-safety guides:

The bottom line

Ransomware is common, it targets Indian households and small businesses, and it feels catastrophic in the moment. It usually is not the end. Disconnect, do not pay, preserve the evidence, check No More Ransom for a free decryptor, restore from a clean backup, and report to 1930 and cybercrime.gov.in. Then close the door behind you with offline backups, prompt updates, and official-source-only software. The shame belongs to the criminal, not to you. The response that protects you is fast, calm, and free.

Frequently asked questions

What is ransomware and how does it reach ordinary people in India?

Ransomware is malicious software that locks or encrypts the files on your computer or phone and then demands a payment, usually in cryptocurrency, to get them back. It reaches ordinary Indians and small businesses through everyday channels: phishing emails with infected attachments or links, pirated or cracked software and activators downloaded from unofficial sites, fake apps sideloaded outside the Google Play Store or Apple App Store, malicious ads, and weakly protected remote-access setups on shop or office computers. CERT-In, India’s national computer emergency response team, has flagged a rise in ransomware hitting internet-exposed database servers and network storage devices, which small firms often run without patching. You do not need to be a large company to be a target. Attackers scan the internet automatically and hit whatever is exposed. A single click on a fake invoice, resume, or delivery notice is often all it takes for the encryption to begin spreading across a device and any drives connected to it.

Should I pay the ransom to get my files back?

No, do not pay if you can avoid it. Both CERT-In in India and the FBI in the United States advise victims not to pay, because payment does not guarantee you will get your files back and it funds more attacks. In many documented cases, victims who paid were never sent a working decryption key, or were sent one that only partially worked, or were extorted a second time. Paying also marks you as someone who pays, which invites repeat targeting. Before even considering payment, disconnect the device, preserve the ransom note, and check the free No More Ransom project run by Europol to see whether a free decryptor already exists for your ransomware strain. Report the incident to the 1930 cybercrime helpline and at cybercrime.gov.in. If a business is involved and the data loss is severe, take legal and professional advice before making any decision, but understand that payment is a gamble with a criminal, not a purchase with a guarantee.

What should I do in the first hour after a ransomware attack?

Move fast and stay calm. First, disconnect the infected device from the internet and from any office network by unplugging the network cable and turning off Wi-Fi, so the ransomware cannot spread to other machines or shared drives. Do not shut the computer down if you can avoid it, as some evidence and recovery options live in memory. Second, do not pay anything and do not delete the ransom note or the encrypted files, since they are needed to identify the strain. Third, photograph the ransom message and note the exact time. Fourth, disconnect any external hard drives, USB sticks, and backups that were not already attached, so a clean backup survives. Fifth, isolate other computers on the same network and check them. Sixth, report to the 1930 helpline and file at cybercrime.gov.in, and if you are an organisation, report to CERT-In. Speed limits the spread and improves your reporting position. The first hour decides how much you save.

Can I decrypt my files for free without paying?

Often yes, and you should always check before paying anything. The No More Ransom project, run by Europol, the Dutch National Police, and security firms including Kaspersky, offers more than 130 free decryption tools covering many known ransomware families. Go to nomoreransom.org, use the Crypto Sheriff tool to upload the ransom note or a sample encrypted file, and it will tell you whether a free decryptor exists for your strain. The portal works from India and is available in dozens of languages. If a tool exists, it comes with step-by-step instructions to recover your files at no cost. If no tool is available yet, keep a copy of the encrypted files, because researchers release new decryptors regularly and one may appear for your strain later. Do not delete the encrypted data assuming it is lost forever. Free recovery is not guaranteed for every strain, but checking No More Ransom is free, safe, and often successful, and it costs a criminal nothing when you skip the ransom.

How does ransomware infect phones and laptops?

The most common routes are phishing, pirated software, and fake apps. Phishing means an email, SMS, or WhatsApp message with an infected attachment or a link to a malicious file, often disguised as an invoice, job offer, courier update, or bank notice. Pirated or cracked software, including cracked Windows, Office, Photoshop, or games downloaded from torrent and unofficial sites, frequently bundles ransomware or the loaders that install it. Fake apps sideloaded from outside the Google Play Store or Apple App Store, especially fake banking, loan, or utility apps, can carry mobile ransomware or spyware. Other routes include malicious online ads, infected USB drives passed between machines, and weakly secured remote-desktop or database services that attackers brute-force. CERT-In has specifically warned about ransomware groups exploiting internet-exposed database servers and network storage. On phones, Android is more exposed than iPhone because Android allows sideloading. The single most protective habit is to install software and apps only from official sources and never open unexpected attachments.

How do I report a ransomware attack in India?

For individuals and small businesses, call the 1930 national cybercrime helpline, operated 24x7 by the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs, and file a formal complaint at cybercrime.gov.in as soon as possible. Provide the ransom note, the time of the attack, any suspicious email or message that preceded it, and details of any payment demanded. If money was already sent to the attacker, report that too, because fast reporting can sometimes help trace or freeze accounts. Registered companies and critical infrastructure operators have an additional obligation: CERT-In directions under Section 70B of the Information Technology Act require organisations to report cyber incidents, including ransomware, to CERT-In within six hours of noticing them, by email to incident@cert-in.org.in. Reporting does not cost anything and it builds the national picture that helps authorities disrupt these groups. Keep the acknowledgement number from cybercrime.gov.in, as banks, insurers, and police may ask for it during any follow-up.

Does paying the ransom guarantee I get my data back?

No. Paying a ransom is not a purchase with a warranty, it is a payment to a criminal who has already lied to you. The FBI states that in its experience some victims who paid were never given the promised decryption key, and that payment does not stop stolen data from being leaked later. Many ransomware groups now run double extortion: they encrypt your files and also copy your data before locking it, then threaten to publish it whether or not you pay. So even a victim who pays and recovers their files can still have their customer records, financial data, or personal photos leaked. Decryption tools supplied by attackers are also often slow, buggy, or incomplete, and can corrupt data. On top of all this, paying funds the next wave of attacks and marks you as a paying target. This is why CERT-In and the FBI both advise against paying and recommend recovery from clean backups plus free tools where available.

How can a small business protect itself from ransomware?

Small businesses in India are frequent ransomware targets because they hold valuable data but often lack basic defences. The core measures, drawn from CERT-In and Cyber Swachhta Kendra guidance, are practical and mostly free. Keep regular offline or disconnected backups of critical data and test that you can actually restore them, because a backup you never tested may fail when you need it. Apply software and operating-system updates promptly, since ransomware often exploits known unpatched flaws. Enforce strong, unique passwords and turn on multi-factor authentication for email, accounting, and admin accounts. Restrict who can install software and access shared drives using role-based permissions. Do not expose database servers, remote desktop, or network storage directly to the internet without protection. Train staff to spot phishing and to avoid pirated software. Use reputable antivirus and keep it updated. None of these steps require a big budget, and together they stop the vast majority of attacks.

What backups protect me from ransomware?

The backups that survive a ransomware attack are the ones the ransomware cannot reach. Follow the widely recommended 3-2-1 approach: keep at least three copies of important data, on two different types of media, with one copy kept offline or offsite. The offline copy is the one that saves you, because ransomware encrypts everything it can touch, including connected external drives and always-on network storage and, in some cases, cloud drives that sync automatically. An external hard drive that you plug in only during backup and then unplug, or a cloud backup service with versioning that lets you roll back to a pre-attack state, both give you a clean copy to restore from. Test your restore process at least a few times a year, because an untested backup is a hope, not a plan. For a small business, this can be as simple as a rotated set of external drives kept in a drawer plus a versioned cloud backup. For individuals, it can be a monthly copy of photos and documents to a drive you keep disconnected. Backups turn a ransomware disaster into an inconvenience.

Can ransomware attack my Android phone?

Yes. Android phones can be hit by mobile ransomware, and India sees this more than iPhone because Android lets users install apps from outside the official store. Mobile ransomware typically arrives as a fake app: a fake loan app, a fake banking or KYC app, a cracked paid app, a fake video player, or an app promoted through a link in SMS or WhatsApp. Once installed and granted permissions, it can lock the screen and demand payment, or in some cases encrypt files on the phone. The strongest defences are simple. Install apps only from the Google Play Store, and do not sideload APK files sent by strangers or downloaded from unofficial sites. Do not grant accessibility, admin, or file permissions to apps that have no reason to need them. Keep Android updated and keep Google Play Protect enabled. Be especially wary of loan and reward apps promising instant money, which are a common cover for malware in India. If your phone is locked by ransomware, do not pay. Report at cybercrime.gov.in and seek help to safely reset the device.

Is my data leaked even if I have good backups?

Possibly, and this is the part many people miss. Backups protect you from losing access to your files, but they do not undo theft. Many modern ransomware groups use double extortion: before they encrypt your files, they quietly copy your data out, then threaten to publish or sell it unless you pay, even if you can restore everything from backup. So a business with perfect backups can still face a leak of customer records, employee data, or financial information. This is why prevention matters as much as recovery, and why a ransomware attack that touches personal data may also trigger obligations under India’s Digital Personal Data Protection framework and require notifying affected people and authorities. If you suspect data was stolen as well as encrypted, treat it as a data breach, not just an outage: report to CERT-In and cybercrime.gov.in, preserve evidence, take legal advice, and be honest with anyone whose data was exposed. Backups keep your business running. Only good security keeps your data from being taken in the first place.

Frequently Asked Questions

What is ransomware and how does it reach ordinary people in India?

Ransomware is malicious software that locks or encrypts the files on your computer or phone and then demands a payment, usually in cryptocurrency, to get them back. It reaches ordinary Indians and small businesses through everyday channels: phishing emails with infected attachments or links, pirated or cracked software and activators downloaded from unofficial sites, fake apps sideloaded outside the Google Play Store or Apple App Store, malicious ads, and weakly protected remote-access setups on shop or office computers. CERT-In, India's national computer emergency response team, has flagged a rise in ransomware hitting internet-exposed database servers and network storage devices, which small firms often run without patching. You do not need to be a large company to be a target. Attackers scan the internet automatically and hit whatever is exposed. A single click on a fake invoice, resume, or delivery notice is often all it takes for the encryption to begin spreading across a device and any drives connected to it.

Should I pay the ransom to get my files back?

No, do not pay if you can avoid it. Both CERT-In in India and the FBI in the United States advise victims not to pay, because payment does not guarantee you will get your files back and it funds more attacks. In many documented cases, victims who paid were never sent a working decryption key, or were sent one that only partially worked, or were extorted a second time. Paying also marks you as someone who pays, which invites repeat targeting. Before even considering payment, disconnect the device, preserve the ransom note, and check the free No More Ransom project run by Europol to see whether a free decryptor already exists for your ransomware strain. Report the incident to the 1930 cybercrime helpline and at cybercrime.gov.in. If a business is involved and the data loss is severe, take legal and professional advice before making any decision, but understand that payment is a gamble with a criminal, not a purchase with a guarantee.

What should I do in the first hour after a ransomware attack?

Move fast and stay calm. First, disconnect the infected device from the internet and from any office network by unplugging the network cable and turning off Wi-Fi, so the ransomware cannot spread to other machines or shared drives. Do not shut the computer down if you can avoid it, as some evidence and recovery options live in memory. Second, do not pay anything and do not delete the ransom note or the encrypted files, since they are needed to identify the strain. Third, photograph the ransom message and note the exact time. Fourth, disconnect any external hard drives, USB sticks, and backups that were not already attached, so a clean backup survives. Fifth, isolate other computers on the same network and check them. Sixth, report to the 1930 helpline and file at cybercrime.gov.in, and if you are an organisation, report to CERT-In. Speed limits the spread and improves your reporting position. The first hour decides how much you save.

Can I decrypt my files for free without paying?

Often yes, and you should always check before paying anything. The No More Ransom project, run by Europol, the Dutch National Police, and security firms including Kaspersky, offers more than 130 free decryption tools covering many known ransomware families. Go to nomoreransom.org, use the Crypto Sheriff tool to upload the ransom note or a sample encrypted file, and it will tell you whether a free decryptor exists for your strain. The portal works from India and is available in dozens of languages. If a tool exists, it comes with step-by-step instructions to recover your files at no cost. If no tool is available yet, keep a copy of the encrypted files, because researchers release new decryptors regularly and one may appear for your strain later. Do not delete the encrypted data assuming it is lost forever. Free recovery is not guaranteed for every strain, but checking No More Ransom is free, safe, and often successful, and it costs a criminal nothing when you skip the ransom.

How does ransomware infect phones and laptops?

The most common routes are phishing, pirated software, and fake apps. Phishing means an email, SMS, or WhatsApp message with an infected attachment or a link to a malicious file, often disguised as an invoice, job offer, courier update, or bank notice. Pirated or cracked software, including cracked Windows, Office, Photoshop, or games downloaded from torrent and unofficial sites, frequently bundles ransomware or the loaders that install it. Fake apps sideloaded from outside the Google Play Store or Apple App Store, especially fake banking, loan, or utility apps, can carry mobile ransomware or spyware. Other routes include malicious online ads, infected USB drives passed between machines, and weakly secured remote-desktop or database services that attackers brute-force. CERT-In has specifically warned about ransomware groups exploiting internet-exposed database servers and network storage. On phones, Android is more exposed than iPhone because Android allows sideloading. The single most protective habit is to install software and apps only from official sources and never open unexpected attachments.

How do I report a ransomware attack in India?

For individuals and small businesses, call the 1930 national cybercrime helpline, operated 24x7 by the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs, and file a formal complaint at cybercrime.gov.in as soon as possible. Provide the ransom note, the time of the attack, any suspicious email or message that preceded it, and details of any payment demanded. If money was already sent to the attacker, report that too, because fast reporting can sometimes help trace or freeze accounts. Registered companies and critical infrastructure operators have an additional obligation: CERT-In directions under Section 70B of the Information Technology Act require organisations to report cyber incidents, including ransomware, to CERT-In within six hours of noticing them, by email to incident@cert-in.org.in. Reporting does not cost anything and it builds the national picture that helps authorities disrupt these groups. Keep the acknowledgement number from cybercrime.gov.in, as banks, insurers, and police may ask for it during any follow-up.

Does paying the ransom guarantee I get my data back?

No. Paying a ransom is not a purchase with a warranty, it is a payment to a criminal who has already lied to you. The FBI states that in its experience some victims who paid were never given the promised decryption key, and that payment does not stop stolen data from being leaked later. Many ransomware groups now run double extortion: they encrypt your files and also copy your data before locking it, then threaten to publish it whether or not you pay. So even a victim who pays and recovers their files can still have their customer records, financial data, or personal photos leaked. Decryption tools supplied by attackers are also often slow, buggy, or incomplete, and can corrupt data. On top of all this, paying funds the next wave of attacks and marks you as a paying target. This is why CERT-In and the FBI both advise against paying and recommend recovery from clean backups plus free tools where available.

How can a small business protect itself from ransomware?

Small businesses in India are frequent ransomware targets because they hold valuable data but often lack basic defences. The core measures, drawn from CERT-In and Cyber Swachhta Kendra guidance, are practical and mostly free. Keep regular offline or disconnected backups of critical data and test that you can actually restore them, because a backup you never tested may fail when you need it. Apply software and operating-system updates promptly, since ransomware often exploits known unpatched flaws. Enforce strong, unique passwords and turn on multi-factor authentication for email, accounting, and admin accounts. Restrict who can install software and access shared drives using role-based permissions. Do not expose database servers, remote desktop, or network storage directly to the internet without protection. Train staff to spot phishing and to avoid pirated software. Use reputable antivirus and keep it updated. None of these steps require a big budget, and together they stop the vast majority of attacks.

What backups protect me from ransomware?

The backups that survive a ransomware attack are the ones the ransomware cannot reach. Follow the widely recommended 3-2-1 approach: keep at least three copies of important data, on two different types of media, with one copy kept offline or offsite. The offline copy is the one that saves you, because ransomware encrypts everything it can touch, including connected external drives and always-on network storage and, in some cases, cloud drives that sync automatically. An external hard drive that you plug in only during backup and then unplug, or a cloud backup service with versioning that lets you roll back to a pre-attack state, both give you a clean copy to restore from. Test your restore process at least a few times a year, because an untested backup is a hope, not a plan. For a small business, this can be as simple as a rotated set of external drives kept in a drawer plus a versioned cloud backup. For individuals, it can be a monthly copy of photos and documents to a drive you keep disconnected. Backups turn a ransomware disaster into an inconvenience.

Can ransomware attack my Android phone?

Yes. Android phones can be hit by mobile ransomware, and India sees this more than iPhone because Android lets users install apps from outside the official store. Mobile ransomware typically arrives as a fake app: a fake loan app, a fake banking or KYC app, a cracked paid app, a fake video player, or an app promoted through a link in SMS or WhatsApp. Once installed and granted permissions, it can lock the screen and demand payment, or in some cases encrypt files on the phone. The strongest defences are simple. Install apps only from the Google Play Store, and do not sideload APK files sent by strangers or downloaded from unofficial sites. Do not grant accessibility, admin, or file permissions to apps that have no reason to need them. Keep Android updated and keep Google Play Protect enabled. Be especially wary of loan and reward apps promising instant money, which are a common cover for malware in India. If your phone is locked by ransomware, do not pay. Report at cybercrime.gov.in and seek help to safely reset the device.

Is my data leaked even if I have good backups?

Possibly, and this is the part many people miss. Backups protect you from losing access to your files, but they do not undo theft. Many modern ransomware groups use double extortion: before they encrypt your files, they quietly copy your data out, then threaten to publish or sell it unless you pay, even if you can restore everything from backup. So a business with perfect backups can still face a leak of customer records, employee data, or financial information. This is why prevention matters as much as recovery, and why a ransomware attack that touches personal data may also trigger obligations under India's Digital Personal Data Protection framework and require notifying affected people and authorities. If you suspect data was stolen as well as encrypted, treat it as a data breach, not just an outage: report to CERT-In and cybercrime.gov.in, preserve evidence, take legal advice, and be honest with anyone whose data was exposed. Backups keep your business running. Only good security keeps your data from being taken in the first place.

Need help verifying a scam?

Free verification and knowledge sharing. WhatsApp +91 99644 43350 or email help@cybersecify.com. For active fraud in the last 24 hours, call the National Cybercrime Helpline 1930 first.

Share this article
ransomwarescam awarenesscybercrime IndiaCERT-Indata protectionsmall business security