When Malware Encrypts Browser Bookmarks And Saved Passwords
A browser that suddenly shows unreadable bookmarks, missing favourites or inaccessible saved passwords may be affected by ransomware, a malicious extension, or a broader system infection. Some threats encrypt browser profile files, while others steal or replace credentials before displaying a ransom message. Treat the incident as both a data-recovery problem and an account-security emergency.
Australian users should act quickly because browsers often contain access to myGov, banking, email, shopping and workplace accounts. Whether the affected computer is in Sydney, Melbourne, Brisbane or a regional area, the first priority is to prevent the malware from reaching other devices and cloud accounts.
Is the browser data really encrypted?
Check whether the bookmarks and passwords are genuinely encrypted or simply hidden, corrupted or unavailable because the browser profile has changed. Ransomware commonly adds a new file extension, leaves a ransom note, or changes the desktop background. A browser hijacker may only alter the homepage and search engine, while a malicious extension can interfere with stored data without encrypting personal files.
Do not open suspicious attachments, click a ransom payment link or install an unknown “browser recovery” program. Photograph or record the warning using another device if possible. Note the affected browser, the time the problem began, unusual file extensions and any recent downloads. This information can help identify the malware family and determine whether a legitimate decryptor exists.
Disconnect the infected computer
Immediately disconnect Wi-Fi and unplug the Ethernet cable. If the computer is connected to a home NBN modem, remove its network access rather than switching off the modem for the entire household. Disconnect external drives and USB storage, but avoid browsing through them on the infected machine.
Do not sign into accounts on the affected browser. Malware may capture passwords as they are typed, and an active browser session can give attackers access even when the password itself is not readable. If the device belongs to an employer, contact the organisation’s IT or security team before attempting extensive cleanup.
Protect accounts from a clean device
Use a trusted phone or computer that was not connected to the suspected infection. Change the password for your primary email first, followed by banking, myGov, social media, shopping and work accounts. Use unique passwords and enable multifactor authentication with an authenticator app or security key where available.
Review active sessions, recovery email addresses, forwarding rules and unfamiliar devices. Sign out everywhere when the service supports it. Contact your bank immediately if the browser stored payment details or if you notice suspicious transactions. Australian customers should use the bank’s official app or the number printed on a card, rather than contact information shown in a pop-up.
Preserve evidence and clean the system
Avoid deleting encrypted files or reinstalling Windows before preserving a copy of the ransom note, suspicious filenames and relevant logs. If you have enough storage, make a copy of affected data to a clean drive that remains disconnected afterwards. Do not copy executable files or browser extensions without professional advice.
Run a reputable security scan from a trusted source, preferably after starting Windows in Safe Mode when the infection prevents normal cleanup. Check browser extensions, recently installed applications and scheduled tasks. Adware can create repeated redirects and pop-ups; guidance on how to stop pop-up ads can help distinguish nuisance software from a more serious compromise.
Potentially unwanted applications are also worth investigating because bundled installers may add password-stealing extensions or remote-access tools. Review the potentially unwanted programs category for warning signs and removal approaches, but download utilities only from reputable publishers.
Recover bookmarks and password records safely
If browser synchronisation was enabled, do not assume that signing back in immediately is safe. First clean the computer, change the account password from a trusted device and revoke existing sessions. Then enable sync again and check whether bookmarks, extensions and saved credentials are restored from a clean cloud copy.
For local recovery, look for browser profile backups, Windows File History, macOS Time Machine, external backups or an enterprise password manager. A browser password export may be useful, but it creates a highly sensitive unencrypted file, so store it temporarily in a protected location and delete it securely after importing the credentials.
| Situation |
Safer response |
Avoid |
| Ransom note and renamed files |
Preserve evidence, isolate the device and identify the malware |
Paying immediately or deleting encrypted files |
| Bookmarks missing after a browser update |
Check the correct browser profile and trusted sync account |
Installing random “repair” extensions |
| Saved passwords exposed |
Change credentials from a clean device and revoke sessions |
Reusing the same password |
| Browser redirects and pop-ups |
Remove suspicious extensions and scan the system |
Clicking fake security alerts |
| No usable backup |
Seek a reputable incident-response or recovery service |
Downloading unverified decryptors |
Report the incident and rebuild securely
If personal information may have been exposed, document what was stored in the browser, when the compromise occurred and which accounts were accessed. Organisations handling personal information may have obligations under Australia’s Privacy Act 1988 and the Notifiable Data Breaches scheme. Individuals can report cybercrime through ReportCyber and scams through Scamwatch, while serious incidents can be discussed with the Australian Cyber Security Centre.
After cleanup, update Windows or macOS, the browser, extensions and security software. Reinstalling the operating system may be the safest option when malware has administrator access or the infection cannot be confidently removed. Restore only personal documents and verified backups, not unknown programs or old browser profiles.
Practical safeguards for Australian users
- Store passwords in a reputable password manager instead of relying only on browser autofill.
- Keep separate, offline backups of important documents and browser recovery information.
- Use multifactor authentication for email, banking, myGov and workplace accounts.
- Review browser extensions monthly and remove anything no longer required.
- Treat unexpected parcel, tax, energy and bank messages as suspicious, especially during busy periods such as tax time or major online sales.
A clean browser profile, fresh credentials and verified backups provide a safer path forward than trying to rescue every stored password from a compromised installation.