What to Do When Ransomware Encrypts Removable Drives
Ransomware that targets only USB sticks, external hard drives, SD cards, or backup disks can be especially confusing. The computer may start normally, while family photos, business documents, accounting files, or project folders on removable storage suddenly carry unfamiliar extensions and refuse to open.
This pattern does not mean the computer is safe. The malware may have searched for mounted drives, encrypted accessible files, and then stopped before affecting the internal disk. Treat the incident as an active compromise until the device and every connected storage item have been checked carefully.
Disconnect And Preserve Evidence
Immediately unplug removable drives from the affected computer, but do not repeatedly reconnect them to “test” whether the files work. If several drives were attached, label them without changing their contents. Note the original file extensions, the new encrypted extensions, ransom-note names, and the approximate time the files became inaccessible.
If the computer is connected to Wi-Fi or Ethernet, disconnect it from the network. This can prevent a ransomware process from reaching shared folders, cloud-synchronised locations, or other computers on a home or office network. Do not delete ransom notes or rename encrypted files, since both can help identify the ransomware family.
Immediate Handling Checklist
- Disconnect affected storage and avoid opening encrypted files.
- Photograph ransom notes, filenames, and unusual extension changes.
- Keep one encrypted sample and a copy of the ransom note.
- Do not pay or contact the criminals from the affected computer.
If the incident began after opening an attachment or visiting a suspicious page, record that detail. Australian users can report cybercrime through ReportCyber and review guidance from the Australian Cyber Security Centre, while businesses should preserve logs for their IT provider or insurer.
Check Whether The Computer Is Infected
A removable-drive attack may be caused by ransomware running locally, a malicious script launched from the USB device, or a compromised account that can access network storage. Run a reputable, updated security scan from a clean environment. If the infection is suspected to be active, use Windows Safe Mode or a trusted rescue environment rather than browsing normally.
Do not assume that a clean-looking desktop proves the system is unaffected. Look for unfamiliar startup entries, scheduled tasks, newly installed applications, disabled security tools, and suspicious processes. On a Mac, review login items, profiles, browser extensions, and applications added shortly before the encryption event.
Other threats can arrive through the same email or website. For example, a deceptive message may install a downloader before ransomware appears; a guide to removing scam email malware can help explain that related infection path. Browser pop-up activity, unexpected redirects, or language changes also deserve investigation, as described in this guide to adware language changes.
Identify The Ransomware Strain
Identification determines whether a free decryptor exists and whether recovery tools are safe to use. Search the ransom-note wording, encrypted extension, contact address, and a small encrypted file through a reputable ransomware-identification service. Never upload private documents containing personal, financial, or client information; use harmless samples where possible.
Some ransomware families append a fixed extension, while others rename files or leave the original name unchanged. A ransom note may identify the group, but criminals sometimes imitate well-known strains. Security researchers and the No More Ransom project occasionally publish decryptors, although availability depends on the exact variant and its encryption implementation.
A decryptor should be used only after the malware has been removed and copies of the encrypted data have been preserved. Test it on duplicates first. A faulty tool, incorrect strain match, or interrupted process can damage the only remaining copy.
Recover Files Without Making Things Worse
Before attempting recovery, create a forensic copy or sector-by-sector image of the affected drive if the data is valuable. Store that copy offline and work on a duplicate. This is particularly important for irreplaceable wedding photos, medical records, university work, or files belonging to a small business in Melbourne, Perth, or regional New South Wales.
Check whether the files exist elsewhere: an unplugged backup disk, a cloud version history, a NAS snapshot, an email attachment, or a second computer. A backup is useful only if it was not connected during the attack and has not silently synchronised the encrypted versions. Apple Time Machine, Windows File History, and business backup platforms may retain earlier copies, but verify their dates before restoring.
Avoid random “ransomware recovery” programs advertised in pop-ups or forums. Some are ineffective, while others install additional malware or demand payment for a tool that does not match the infection. Australian households often buy USB storage from retailers such as Officeworks or JB Hi-Fi; replacement hardware is inexpensive compared with losing evidence, so copy data to a clean, newly formatted device only after recovery decisions are complete.
Clean Devices And Prevent A Repeat
After preserving evidence, reinstall or thoroughly clean the affected computer using trusted security tools. Changing passwords from a separate, clean device is sensible, especially for email, cloud storage, banking, and administrator accounts. Enable multifactor authentication and remove unknown sessions from important online services.
Reformatting a removable drive removes the encrypted files and any malware stored on it, so do this only after imaging, copying, or deciding that recovery is no longer possible. Scan replacement drives before use and disable automatic execution features. Keep external backups disconnected except during scheduled backup tasks.
For households in Brisbane or Adelaide, removable drives may hold years of family media; for tradespeople, farms, and local retailers, they may contain invoices, tax records, or job files. Use the three-copy approach: maintain the working copy, a separate local backup, and an offline or securely protected backup. Test restoration regularly, particularly before tax time or major business deadlines. Update operating systems, browsers, and security software, and treat unexpected delivery notices, invoices, and USB devices as potential attack routes rather than harmless conveniences.