What to do when ransomware encrypts only your audio and video files
Ransomware does not always lock every document on a computer. Some strains focus on extensions used for recordings, films, music libraries, podcasts, CCTV exports, or smartphone backups. If photos, spreadsheets, and other files still open while MP3, WAV, MP4, MOV, or AVI files have changed, the attack may be targeting valuable media specifically.
This selective encryption can feel less urgent than a complete system lock, especially when Windows still starts normally. However, family videos, business recordings, and original audio projects can be difficult or impossible to replace. A careful response can preserve the best chance of recovery while preventing the malware from damaging connected devices and cloud copies.
Australian users may have media spread across a Windows desktop, an external drive, a NAS device, and a cloud account accessed through an NBN connection. People in Sydney, Melbourne, Brisbane, and regional areas also commonly transfer phone videos through shared folders or messaging apps, creating several possible paths for reinfection.
Disconnect the affected computer safely
Immediately disconnect the infected computer from Wi-Fi and wired networks. Unplug Ethernet, disable Bluetooth, and remove USB storage, portable hard drives, SD cards, and media players. Do not reconnect a backup drive simply to check whether its files are intact; some ransomware searches for attached and networked storage after encrypting the main computer.
If the device belongs to a business, school, production team, or household with shared accounts, isolate other computers as well. A compromised Windows login may provide access to shared folders used for wedding footage, local sports recordings, or a small business’s marketing archive. Record the ransom note, changed file extensions, contact addresses, and the time the encryption was discovered.
Avoid opening many encrypted files, running random “repair” programs, or renaming extensions. Those actions rarely restore the data and may overwrite useful evidence. If the computer is still active, a security professional can advise whether to shut it down, create a forensic image, or preserve volatile information before cleaning.
Identify the ransomware and protect evidence
Look for the ransom note, an unusual filename suffix, and an email address or cryptocurrency instruction. Do not assume that the file extension identifies the malware family: criminals can reuse suffixes, and one ransomware group may produce several variants. Submit a copy of the note and one small encrypted file to a reputable identification service, but never upload private recordings or confidential business material.
Keep an untouched copy of several encrypted files and the ransom note on offline storage. Note the original locations, approximate file sizes, and whether the affected media came from a phone, camera, editing application, or network share. This information can help determine whether the files were fully encrypted or merely renamed.
If the incident involves a business or organisation, preserve logs and contact the Australian Cyber Security Centre through its reporting channels. Where personal information may have been exposed, the Notifiable Data Breaches scheme may apply, particularly to organisations covered by the Privacy Act. A ransom demand does not prove that data was stolen, but it should be treated as a possible security incident.
Check recovery options before considering payment
First examine clean backups created before the encryption date. Check an offline USB drive, a disconnected NAS snapshot, Windows File History, macOS backups, and version history in services such as OneDrive or Google Drive. Cloud synchronisation can be deceptive: encrypted files may have synced over healthy versions, while older versions or deleted-file recovery remain available for a limited period.
Do not connect a backup until the computer has been cleaned or replaced. For cloud accounts, change passwords from a separate trusted device, enable multifactor authentication, revoke unknown sessions, and inspect the recycle bin and activity history. Guidance on protecting cloud backups is useful when ransomware has reached synchronised storage.
| Recovery source |
What to check |
Main caution |
| Offline backup |
Last healthy copy of media |
Keep it disconnected until cleanup |
| Cloud history |
Earlier versions and recycle bin |
Encryption may have synchronised |
| System restore |
Older settings and shadow copies |
It may not restore personal media |
| Decryptor |
Exact ransomware family and variant |
Avoid fake tools and bundled malware |
| Data recovery lab |
Original drive condition |
Costs can be high and results vary |
Do not pay quickly because the affected files are irreplaceable. Payment may fund further crime, does not guarantee a working decryptor, and can identify your organisation as a repeat target. Even when criminals send a tool, it may be defective or leave files partially damaged.
Try decryptors and specialist recovery methods
Search for a decryptor only after identifying the ransomware family and exact variant. Use well-known security vendors, the Australian Cyber Security Centre, or established incident-response resources rather than advertisements promising instant recovery. Test any legitimate tool on copies, and scan downloaded programs before running them on the affected system.
Some families target compressed archives containing media, while others encrypt file contents without changing the apparent format. If the incident involves the Phobos family, information about Phobos recovery methods may help clarify why ZIP or RAR collections behave differently from individual recordings.
A professional data-recovery laboratory may help when the disk has not been heavily used since encryption. Stop using the drive if files were deleted as part of the attack, because new activity can overwrite recoverable sectors. Recovery is never guaranteed, particularly with modern solid-state drives and automatic TRIM operations.
Clean the system and rebuild your media library
The safest long-term response is usually to preserve evidence, wipe or securely rebuild the affected computer, install current operating-system updates, and restore only verified clean data. On Windows, use a trusted anti-malware scanner and consider an offline scan. Remove unknown remote-access tools, browser extensions, scheduled tasks, and new administrator accounts.
Mac users should follow platform-specific removal and backup practices; the Mac security guide provides relevant information for checking an Apple computer before restoring recordings. Do not assume that a Mac, NAS, or phone is automatically safe because the original encryption occurred on Windows.
After recovery, maintain at least one backup that is disconnected or otherwise protected from automatic modification. Use separate accounts for daily work and administration, enable multifactor authentication, and update routers, phones, editing software, and storage appliances. Australian households often accumulate large media libraries from school concerts, holidays, and family events, so organise irreplaceable files and test restoration before an emergency occurs.
Practical recovery priorities
- Isolate the infected device and every connected storage location.
- Preserve the ransom note, encrypted samples, filenames, and timestamps.
- Identify the ransomware before downloading a decryptor or recovery utility.
- Check offline backups and cloud version history from a clean device.
- Report suspected business or personal-data exposure through the appropriate Australian channels.