Ransomware
Malicious software that encrypts a victim's data and demands payment (a 'ransom') for the decryption key. Deploying ransomware is a criminal offence under the Computer Misuse Act 1990 (s.3 — unauthorised acts with intent to impair). Paying a ransom may also have legal implications including potential sanctions law breaches.
Independent editorial summary — not the official statute text. Read the official version on legislation.gov.uk.
In a ransomware attack the victim can no longer access their device or the data stored on it because the files have been encrypted. Attackers typically gain access to the victim's network, establish control and plant malicious encryption software, and may also copy data and threaten to leak it. The victim then usually receives an on-screen notification demanding payment, typically in cryptocurrency, to unlock the computer or regain access to the data.
The National Cyber Security Centre and UK law enforcement do not encourage, endorse or condone paying ransom demands, noting that payment does not guarantee data or computer access will be restored, the computer will still be infected, and paying funds criminal groups who may target the victim again. Deploying ransomware can amount to an offence under section 3 of the Computer Misuse Act 1990, which criminalises doing an unauthorised act in relation to a computer, known to be unauthorised, with intent (or recklessness as to whether it will) to impair the operation of a computer or the reliability of data held on it.
Related terms
Official sources
This explanation is drawn from the official sources below; every substantive statement is verified against them. For advice on a specific matter, see our find help page.