CYBER WELFARE

Protect your Digital Privacy

Ransomware and personal files: the other ways photos and documents can disappear

Family photos, holiday videos, scans of important documents: for many people, they live in one place only. The phone, the laptop, or an online account that is simply taken for granted.

As long as that place works, nobody thinks about it. But some attacks target exactly that single place. When it comes to ransomware and personal files, the pattern is simple: the files are made unreadable and a ransom is demanded to unlock them. It is the best-known of these attacks, and it is not the only one.

This post explains how these attacks work and why, in almost every case, they do less harm to people who keep a copy of their data somewhere separate. It is the threat-side companion to the recommendation on backing up photos and videos.

One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

One evening you open the family laptop to print a recipe. All the folders are there, but the photos will not open: the file names have a strange extension, and a text file you never created has appeared on the desktop.

The message says your files have been encrypted and that, to get them back, you must pay within a few days.

The external drive where you kept “the copy” had been plugged into the laptop for months. On it, the same strange names. And the folder synced with the cloud shows the same unreadable files: syncing has faithfully copied the damage.

Why a missing or always-connected backup increases the risk

All the attacks that follow share one thing: they strike where your data exists, and it is enough for it to exist in one place only.

A copy that lives on the same device, on a drive that is always connected, or in a folder that updates itself automatically shares the fate of the original. It is not a real second copy: it is the same target in two locations.

A backup — a copy of your data kept separately, from which files can be restored — changes the picture only if it is genuinely separate: disconnected, or able to keep earlier versions of your files.

1. Ransomware at home

In plain terms. A malicious program makes your files unreadable and demands a payment to give them back.

How it works. Ransomware — literally “ransom software” — usually gets in through an email attachment, a program downloaded from outside the official app stores, or software that has not been updated. Once active, it applies encryption to your files, a transformation that makes them readable only with a key, and that key is held by whoever built the attack. It often encrypts everything it can reach: internal drives, connected external drives, folders shared over the home network.

Why a missing backup makes it worse. Without a separate copy, two paths remain: give up on the files or consider paying. And paying guarantees nothing: the key may never arrive, or may not work on every file.

Possible impact. Loss of years of photos and documents, emotional pressure to decide in a hurry, possible publication of the files if the attack also copied them.

What should make you suspicious. Files that will not open and have changed extension, a ransom note on the desktop or in every folder, a computer that is unusually slow while the drive works for no apparent reason.

How to protect yourself. Automatic updates switched on — the recommendation on keeping your software up to date explains why they matter — programs only from official sources, and above all a backup that is disconnected after use or keeps a version history. If ransomware strikes, the device can be cleaned and the files restored from the healthy copy.

2. Deletion through a compromised account

In plain terms. Someone gets into your cloud account and deletes, moves or holds your files hostage.

How it works. Access usually comes from a reused password that ended up on a list, or from a phishing message — a fake page imitating the service so that you type in your credentials. From inside the account, everything can be seen: photos can be downloaded, folders emptied, even the bin cleared. In some cases the files are deleted after being copied, and a demand for money arrives by email.

Why a missing backup makes it worse. If the cloud account is the only place where your photos live, whoever controls the account controls your memories too. A second copy somewhere else, with different credentials, turns the deletion into a nuisance rather than a loss.

Possible impact. Loss of your archive, exposure of private pictures and documents, loss of the account itself if the recovery details are changed.

What should make you suspicious. Sign-in notifications from unknown places or devices, empty folders, confirmation emails for changes you did not make, a bin emptied for no reason.

How to protect yourself. A unique password for the account that holds your photos — storing passwords safely helps here — multi-factor authentication (MFA, a second check on top of the password, such as a code on your phone) and a copy of your data outside that account.

3. When syncing spreads the deletion

In plain terms. Syncing keeps two places identical; if one gets damaged, so does the other.

How it works. Syncing is the mechanism that keeps two folders the same, for example the one on your computer and the one in the cloud. It is convenient because every change spreads everywhere. But deletions spread too, and so do files encrypted by ransomware. There is not always an attacker involved: a single mistake, or an attack on just one device, is enough for the damage to reach everything within minutes.

Why a missing backup makes it worse. Many people assume a synced folder is already a backup. It is one only if the service keeps a version history — earlier versions of your files for a certain period — and only if you notice the problem before those versions expire.

Possible impact. Deleted or unreadable files on every connected device, often discovered only when you need them.

What should make you suspicious. Warnings about “many files deleted”, storage use that suddenly drops, files that all appear to have been modified at the same moment.

How to protect yourself. Treat syncing as a convenience, not as protection. Check whether the service keeps earlier versions and for how long, and add a copy that does not update itself: an external drive connected only while the backup runs.

4. Device theft

In plain terms. Your phone or laptop is stolen, and everything on it goes too.

How it works. Often, whoever steals a device is after its resale value, not your files. But if the device is not protected by a screen lock and encryption, the photos and documents remain readable by whoever is holding it. Either way, for you, those files are gone.

Why a missing backup makes it worse. Theft is a double problem: losing the data and the possibility that someone else can see it. A backup deals with the first; device encryption reduces the second.

Possible impact. Loss of photos and documents not copied elsewhere, possible access to the contents if the device is not encrypted, access to accounts still signed in.

What should make you suspicious. Here the signal is obvious; the useful ones to watch for come afterwards: sign-ins to your accounts from the stolen device, messages sent in your name, requests for codes.

How to protect yourself. An automatic, tested backup, a screen lock, encryption switched on — the recommendation on encrypting your personal devices explains what it really protects — and a backup that is itself password-protected, because an external drive can be stolen too.

5. Extortion with private photos or videos

In plain terms. Someone threatens to share private images unless you pay or do what they ask.

How it works. The images may come from a compromised account, a stolen device or an unprotected backup. Sometimes, though, the threat is a bluff: messages sent out in bulk claim to hold images that do not actually exist, and rely on fear to extract a payment. In other cases the images were shared within a relationship of trust and later used as leverage.

Why an unprotected backup makes it more likely. A backup is a complete copy of your digital life. If it sits on a drive with no password or in a weakly protected account, it becomes a richer target than the original. Protecting your backups means protecting those same images.

Possible impact. Heavy emotional pressure, shame, isolation; in real cases, private content being shared. Responsibility always lies with the person making the threat, never with the person receiving it.

What should make you suspicious. Messages quoting an old password of yours to seem credible, payment demands with very short deadlines, pressure not to tell anyone.

How to protect yourself. Encrypted, password-protected backups and accounts with MFA. If it happens: do not pay and do not reply, keep the messages as evidence, talk to someone you trust and report it to the police. When minors are involved, report it straight away. This is not something to face alone.

6. Hardware failure or physical damage (not an attack, but a risk)

In plain terms. A drive that breaks, a phone dropped in water, a power surge: nobody is attacking you, but the files are lost all the same.

How it works. Every storage medium has a limited lifespan. Drives wear out, memory cards get damaged, and an accident at home — a flood, a burglary, a fire — can hit both the computer and the backup drive if they are kept in the same place.

Why a missing backup makes it worse. Professional recovery from a damaged drive is expensive and does not always succeed. A copy on a second storage medium, and one kept outside the home, turn a failure into an inconvenience.

Possible impact. Partial or total loss of data, recovery costs, files recovered but incomplete or corrupted.

What should make you suspicious. Unusual noises from the drive, read errors, files that open only in part, a device that freezes or restarts on its own.

How to protect yourself. The 3-2-1 backup rule: three copies, on two different types of storage, one of them kept away from home. And a test restore now and then, so you know the copy actually works.

Summary table

Attack or riskMain riskWhat should make you suspiciousEffective defences
Ransomware at homeEncrypted files, ransom demandStrange extensions, ransom noteUpdates, official sources, disconnected or versioned backup
Compromised accountArchive deleted or takenUnknown sign-ins, empty foldersUnique password, MFA, copy outside the account
Syncing that spreads damageDamage replicated everywhereMass-deletion warnings, storage droppingVersion history, a copy that does not sync
Device theftLoss of files and possible access to themSign-ins from the stolen device’s accountsAutomatic backup, screen lock, encryption
Extortion with private imagesPressure and content being sharedShort deadlines, demands for secrecyEncrypted backups, MFA, not paying, asking for help
Hardware failure or damageLoss of unrecoverable dataNoises, read errors, freezes3-2-1 rule, test restore

What they have in common

Six different situations, three defences that cut across almost all of them:

  1. A genuinely separate copy — disconnected after use, or with a version history, plus one kept away from home.
  2. Protected accounts and backups — a unique password, MFA, encryption: a copy anyone can reach is an extra risk, not a protection.
  3. A test restore now and then — a backup only truly exists if you can get your files back from it.

These are not advanced measures. They take some initial setting up and a few minutes every so often, and they change the outcome of almost every case described here. To choose the right storage, the comparison between cloud or external drive backup will help you find your way.

Protection checklist

  • ☐ Important photos, videos and documents have at least one copy outside the device
  • ☐ The backup drive is connected only while copying, then disconnected
  • ☐ The cloud service keeps earlier versions of files, and I know for how long
  • ☐ The account holding my photos has a unique password and MFA switched on
  • ☐ Backups and devices are encrypted and password-protected
  • ☐ Automatic updates are on, and programs come only from official sources
  • ☐ At least one copy is kept away from home
  • ☐ I have tried restoring a file from the backup in the last few months

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that attacks, mistakes and failures all strike in the same way: where data exists in one place only
SkillsTelling syncing apart from backing up, and recognising the signals of each attack
Secure BehaviourKeeping a separate, protected copy, and responding calmly to ransom demands

Reference level: FL3 — Autonomous, with elements of FL2 — Beginner in the sections on theft and hardware failure.

Conclusion

Ransomware, a compromised account, syncing that replicates a mistake, a theft, a threat, a failure: these are very different situations, and none of them requires anyone to have singled you out. They succeed where data exists in one place only, or where the copy is as easy to reach as the original.

That is why the most effective defence is also the simplest: a separate, protected and tested copy. To find out whether your backups really work, the signs your backup is not working are the next step; for a broader picture of where you stand, you can start with the digital resilience self-assessment.

Something to think about. If your phone and your computer both stopped working at the same moment tomorrow, where would you find this year’s photos?

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.