How to protect yourself in case they do.

The best we can say is… maybe.
And maybe has been slowly changing over time to something closer to possibly.
It depends on a lot of things, including the type of backup, where it’s stored, and most importantly, the specific ransomware involved. There are many types (or variants) of ransomware, each with different characteristics.
Fortunately, there’s an easy way to keep your backups safe.

Usually, ransomware doesn’t bother with your backups, but it can. Keep backing up the same way you always have. Every so often, copy your backups to a drive you disconnect and store safely. That keeps your files safe.
Ransomware
Ransomware is malware. Once it infects your machine, it begins encrypting your files. Once done, it displays a message indicating your files have been encrypted. Your files are inaccessible to you until you pay a fee — the ransom — for the decryption key.
Most ransomware uses strong encryption. There’s little chance of cracking the encryption to get your files back. Typically, you’re left with three options:
- Pay the ransom. Strongly discouraged, as it encourages more attacks.
- Restore the files from a backup. Strongly encouraged. This can make it all a non-issue, but requires backups taken before the hack.
- Give up. Remove the malware and live with the loss of the encrypted files.
Relying on the backups, of course, assumes the backups themselves haven’t been encrypted by the malware.
Help keep it going by becoming a Patron.
What ransomware encrypts
What we call “ransomware” is not a single thing. It’s an entire class of malware that shares a particularly destructive behavior. There are hundreds, if not thousands, of types of ransomware.
They differ in two important ways: where they look for your files, and which files they choose to encrypt.
Which drives are scanned
Most ransomware scans only your system drive. For most systems, that’s the “C:” drive. Any other drives — including your backup drive — are ignored. This gives access to your important files (typically stored on C:) and allows the ransomware to quickly encrypt files before you notice.
More sophisticated variations that can scan all drives attached to the system, including external and/or network connections, do exist. Anything with a drive letter could be at risk.
One bit of good news is that only drives are scanned. Storage accessed only via your browser or a dedicated application, such as some forms of cloud storage and online backup services, is not directly at risk. There’s still bad news, however, since if those services synchronize files to one of your drives, as OneDrive, Dropbox, and others do, it’s likely they’ll sync the files once they’ve been encrypted, perhaps overwriting previously saved, unencrypted versions.
Which files are encrypted
Ransomware does not encrypt all files. This fact is often overlooked in the panic. It can’t encrypt everything; Windows itself needs to keep working, as does the mechanism the ransomware uses to display its demands and recover your files.
Ransomware usually targets what I call potentially high-value files based on the filename extension:
- Documents such as “.doc”, “.docx”, “.txt”, and others
- Spreadsheets and finance databases like “.xls”, “.xlsx”, “.qbw”, and more (particularly impactful for businesses)
- Photos, including “.jpg”, “.jpeg”, and so on (particularly impactful for individuals with precious family photos)
This isn’t meant to be an exhaustive list, but it points out that not all files are always at risk.
In fact, if you’re using an image backup program, it’s worth noting that I didn’t list “.tib” (Acronis’s format), “.mrimg” (Macrium Reflect’s), or “.pbd” (EaseUS Todo’s). More often than not, these files are not encrypted. Because backup files are large, the encryption process could take a long time, making it more likely that the malware is detected before it does its damage.
So there are three possibilities for those backup image files:
- They’ll be ignored. This is the most common.
- They’ll be encrypted. This is less frequent.
- They’ll be deleted. This is rarer still, but it would leave you without a backup.
While it’s infrequent, ransomware can encrypt backups, but we don’t know if a specific ransomware variant will.
What it takes for backups to be encrypted
In order to truly put your backups at risk:
- The ransomware variant needs to scan more than the C: drive.
- The ransomware variant needs to choose to encrypt backup files.
Most ransomware has neither of those characteristics. It’s not likely to happen.
But most is not all. You could encounter ransomware that encrypts your backups.
How to protect yourself
The knee-jerk reaction to hearing that backups might get encrypted is to disconnect the backup drive when you’re not actually making a backup. Don’t do that.
If you do, backups are no longer automated. You have to remember to reattach the drive in order to back up. Forgive me, but I don’t want to rely on your memory — or mine, for that matter — to back up, especially when the risk we’re trying to avoid remains relatively small compared to the many other reasons you want that backup to happen.
Some backup programs provide ransomware-specific protection. Macrium Reflect’s “Image Guardian” feature, for example, locks down the backup images it creates so ransomware doesn’t have access. Check to see if your backup program has a similar feature.
Do this
My recommendation:
- Leave your backup drive attached and automate your backup routine.
- Every so often, make a copy of your backups somewhere else. Copy them to a device that is then disconnected. It could be another external drive or even another computer on your network. One approach is to have two backup drives but only connect one at a time, and swap them periodically.
Don’t get me wrong: the risk of ransomware encrypting your backup exists, but it’s on the low end of the scale. It’s much more important that your automated backups continue to help you recover from more likely issues.
Of course, the best defense is to never get ransomware (or any malware) in the first place and stay safe in general.
Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.


Good common-sense article from Leo who makes it clear that you cannot make yourself 100% safe, but if you do the right things, especially by keeping good backups, you’re going to be reasonably safe.
Thank you!!
I use the backup program/application that creates *.tib and lately *.tibx (not to advertise the product name, unless you (Leo) decide to).
Since around a year ago that program/application has a built in security feature against ransomware.
Of course I always keep copies of my *.tib and *.tibx files on a second HDD that is only on when I make the copy, regardless, but I believe if you (Leo) check the latest version of this program/application, may be you’ll find it right to advise most readers accordingly on this issue. I also believe it is only a matter of time until all backup products will have such a protection, but until then…
Best regards from across the ocean 🙂
Sounds like Acronis. Macrium Reflect has had a similar backup-protection feature for some time as well. I really like it.
No reason not to mention that you are using Acronis True Image. Leo used to recommend it but now he recommends Easeus Todo or Macrium Reflect.
How much does syncing my files to One Drive help protect me from Ransomware (or does it at all)? Can ransomware encrypt my files on One Drive? I am a retired Home User, so I do not have the resources available to large businesses or corporations. I do however suspect that I am as much of a target as anyone else on the Internet and that it would be foolish to assume otherwise. What do you think Leo?
Your own backups are most important, but yes, ransomware can affect OneDrive (or Dropbox or others…). This article has a section on it: How to Protect Your Cloud Storage and Backups from Ransomware
I can definitely say, YES! I have had customers & family get ransomware and their external backup hard drives also were encrypted (unable to restore).
Luckily, we setup on multiple backups and were able to get the previous weeks backup drives and, after thorough cleaning and removal of infections, do a complete clean restore.
We use Macrium Reflect and their later, Paid, Version (over the last couple of years) has a feature called “Image Guardian”, that locks down the backup hard drive and only it can right to the backup drive. It has worked quite well, and I am sure many other backup producers have added such protection by now.
What we like about Macrium Reflect is, it is very affordable, reliable, easy to use and tech support has been great (always one of the most important things!). And I believe one of the first (if not the first) to add the hard drive backup protection!
If I understand correctly, if you wish to write malware to attack unmounted devices, you can use the mountvol command to discover volume names. You can then mount the devices. It takes some parsing of mountvol’s output, and you have to run your malware as administrator.
I haven’t tried it, but your victim might thwart your malware with a USB switch to de-power the device, or an “AB” switch that connects a device to either of two computers, by switching the device to a non-existent computer.
I am a computer service/repair guy down here in New Zealand, one of my clients had a ransomware attack and IT DID ENCRYPT the backup drive plugged into the PC at the time and also some shared folders over the local network on other users PC’s
Yeah, it’s unfortunately starting to happen. It’s not the majority of ransomware attacks, but it’s definitely happening.
Leo:
Would it be beneficial to rename doc, txt, jpg files (etc) to something else (like d1c, t6t, and j4g respectively) as long as we remember to change the file name back to doc, txt, jpg (etc) when we want to open or use the file again? I know there are many, many file extensions that are used by other programs, so finding a good file extension to use might be hard to do. Even if we change the file extension, I wonder if ransomware looks IN the files to see if it is a document or photo file.
I don’t believe ransomware looks in the files, but honestly — what you’re describing sounds like a lot of work, possibly error prone, and could STILL be encrypted by some forms of ransomware. Sorry.
For desktops:
1. Attach a mains powered back up drive and plug the power cord into a mechanical timer (the kind you use to switch your Xmas lights on and off). Set it to come on at X o’clock, and off at Y o’clock each night while you’re dreaming of a Covid-free. politically stable world.
2. Set Macrium Reflect or similar to clone your C drive within those hours (with a little buffer before and after to allow for the timer’s mechanical inaccuracy.
3. Assuming ransomware isn’t able to infect while the computer isn’t being used, you should be 99% protected.
4. For 99.9999999%, you could plug your modem into the same timer (I don’t bother). It’s not 100% because I suppose it is possible for sleeper ransomware to infect during the day unseen and activate during your chosen cloning time. For laptops at home you could do the same, but if you’re in say a hotel, I can’t think of a reliable (i.e. non-memory reliant) way to ensure internet connection is off during the cloning process.
Hope this is useful.
I have run a small one man shop in my town for the past 10 years. Coming from IBM I am very conscious of need for backups and the damage Ransomware or malware can do a client’s data, so for years I have recommended full system backups, originally I used True Image, but over time I have switched to Macrium Reflect. Last year I had recommended a client use it on her computer and assured her this would get us out of a jam, should anything happen. Well it did happen and no, the backup did not get us out of it. Both full image backups were encrypted with the malware, just like all her files. The only thing we were able to recover was from a 10 month offline backup and that meant lots and lots of email was missing, (she runs a small business from her home and this was a huge deal).
So, if recovery is really important, definitely keep a fairly recent backup offline. I felt terrible that she trusted me and what I thought was safe, turned out to not be.
NOTE: I also had Windows 10 file history running, but of course it was encrypted as well.
Really IMPORTANT specially for those with large systems and important Data…I would suggest keeping backups of more than 30 days on EXTERNAL DRIVES, MORE THAN ONE.. And to Start your computer, using an EXTERNAL “Rescue Media” and if you like to be more sure, create TWO Rescue Media, on two dates at least 31 days apart. .And Start your PC using one, if not successful, use the other.
Mounting and unmoving the back-up clone.
Powering up and shutting down the backup clone.
Assume the cloning operation is done once a day (or once a week, or other than that). It s better to mount the back-up clone immediately upon stating the backup task, and un mounting it after. Why ? Because it is harder for the ransomware to mount an unmounted drive. That can be automated with the back-up software (CarbonCopyCloner does it for me).
Backup drives can be powered immediately upon mounting. To do that, you can use home automation software. (1) it triggers drive power-up through an instruction to the drive’s electric plug. Once done (2), it triggers the initiation of the mounting and back-up task, through a shell script addressed to the backup software, (3) upon end of backup and drive un mounting, the backup software informs the home automation software that it is time to unplug the drive, which is achieved through an email initiated by the backup software and listened to by the mail application, which issues accordingly an instruction to the home automation software. For a 20 minutes backup occurring in the dark of the night, the backup drive is fed with electricity and mounted on the computer only 20 minutes., which is kind of neat.
You can increase level of protection (and complexity and, unfortunately, power usage) by backing up to a network computer (which then also needs to run during the night). There is no way the ransomware can follow you there.
Warning, a fire in your home will still destroy your local backup however protected it may be.
FWIW
Interestingly, just a couple of days after reading this, ransomware got to our OFF-SITE server system and made everything go away. About 8 TB of data vanished in a short time. [Still trying to figure out how they got in – all our machines appear to be clean.] No way they actually encrypted everything, and no big list of encrypted files. Just a ransom note and a couple of relatively small data files. My guess – they played with the directory structure in order to hide everything. Still wish I knew what they did, though. [At least it *was* the backup, so we can just back it all up again.]
Easeus Todo has just announced a new feature that they have called the Security Zone. This is a segment (unmaped?) of the external backup hard drive that is only accessible to the Easeus Todo program and not to File Explorer. The intention is to make it inaccessible to malware — especially to ransomware. The capability to run automatic backups is also provided.
This is good news. Macrium Reflect has a similar feature, though its files remain visible to File Explorer, but locked down using Windows File Permissions.