Type something to search...
What is ransomware and how to protect your website from it?

What is ransomware and how to protect your website from it?

Ransomware is malicious software that locks you out of your own files or data, usually by encrypting them, and then demands a payment in exchange for the key to unlock them. Many modern attacks also steal a copy of the data first and threaten to publish it if you don't pay. You protect your website from ransomware by keeping software patched, locking down access to your server and admin accounts, limiting what each account and process can do, and, above all, keeping backups that an attacker can't reach or delete.

Ransomware is often discussed in terms of office networks and hospitals, but websites and web servers are targets too. They're always online, often run outdated software, and hold valuable data such as customer records and orders. This article explains how ransomware affects websites specifically, how attackers get in, and a practical set of defences you can put in place, plus what to do if the worst happens.

What Is Ransomware?

Ransomware is a category of malware built for extortion. Once it's running on a system, it typically does some combination of the following:

  • Encrypts files: Documents, databases, website files, and sometimes backups are scrambled with strong encryption. Without the key, the data is unreadable.
  • Steals data: Before encrypting, many groups copy sensitive data off the server. This is known as double extortion.
  • Leaves a ransom note: A text file or replaced homepage explains what happened and how to pay, usually in cryptocurrency.
  • Threatens further harm: Some attackers threaten to leak data, contact your customers, or launch a denial-of-service attack if you don't pay.

Encryption used by serious ransomware groups is generally not breakable, so recovery depends on having a clean copy of your data somewhere else.

How Ransomware Affects Websites

Website ransomware usually looks a little different from the kind that hits office PCs. Common forms include:

Encrypted Website Files

An attacker who gains access to your server, through a vulnerable plugin, a web shell, or stolen credentials, runs a script that encrypts files in your web root. Your .php, .js, and image files are renamed with a new extension and the homepage is replaced with a ransom message. The site stops working immediately.

Database Extortion

Attackers find a database exposed to the internet with weak or default credentials, such as MySQL, MongoDB, Elasticsearch, or Redis. They copy or delete the data and leave behind a table or record explaining how to pay to get it back. Often the attacker never actually kept a copy, so paying returns nothing.

Hosting Account and Server-Wide Attacks

If an attacker gets root access to a server or control over a hosting panel, they may encrypt every site on the machine, along with local backups stored in the same place.

Data Theft Without Encryption

Some groups skip encryption entirely. They steal customer data from an e-commerce database and demand payment to keep it private. Your site keeps running, but you face a data breach.

How Ransomware Gets Onto a Website

Attackers need a way in. The most common entry points for websites are:

  1. Vulnerable plugins, themes, and software: Unpatched CMS extensions, outdated PHP applications, and old server software with known vulnerabilities are routinely exploited by automated scanners.

  2. Stolen or weak credentials: Reused passwords for WordPress admin accounts, hosting panels, SSH, FTP, or database users. Credentials are often harvested from breaches of unrelated services.

  3. Exposed services: Databases, admin panels, or remote desktop services left open to the whole internet.

  4. Phishing: A convincing email tricks someone into entering their hosting or registrar login on a fake page.

  5. Compromised developer machines: Malware on a laptop used to manage the site can steal saved SFTP, SSH, or panel credentials.

  6. Supply-chain issues: Pirated or nulled themes and plugins frequently contain backdoors that give attackers direct access.

Notice that most of these are the same weaknesses behind other kinds of website hacks. Ransomware is often simply the final payload after an attacker has already got in.

How to Protect Your Website From Ransomware

No single measure is enough. The goal is to make getting in hard, limit the damage if someone does, and make sure you can always recover.

1. Keep Everything Patched

Updating software is the single most effective way to shut the doors attackers use:

  • Update your CMS core, plugins, and themes promptly, and enable automatic updates for trusted components.
  • Remove plugins and themes you don't use, even if they're deactivated.
  • Keep your server's operating system and packages updated. On Ubuntu or Debian, unattended upgrades can install security updates automatically:
sudo apt update
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades

On RHEL-based systems such as Rocky Linux or AlmaLinux, the equivalent is dnf-automatic.

  • Run a supported PHP version. PHP branches only receive security fixes for a limited time, so check the official PHP supported versions page and upgrade before your version reaches end of life.

2. Lock Down Every Login

Strong authentication makes stolen or guessed passwords far less useful:

  • Use unique, long passwords stored in a password manager for every account: CMS admin, hosting panel, SSH, SFTP, database, registrar, and email.
  • Turn on two-factor authentication wherever it's offered, especially for admin and hosting accounts.
  • Use SSH keys instead of passwords for server access, and disable password logins once keys are working. Keep your current SSH session open and test a new connection in a second terminal before closing it, so a mistake doesn't lock you out.
  • Limit login attempts and consider a security plugin or firewall that blocks brute-force attacks.

3. Close Exposed Services

Your database should never be reachable from the whole internet unless there's a strong reason. On a typical single-server setup, MySQL or MariaDB should listen only on localhost. In /etc/mysql/mysql.conf.d/mysqld.cnf (MySQL) or /etc/mysql/mariadb.conf.d/50-server.cnf (MariaDB), check for:

[mysqld]
bind-address = 127.0.0.1

Restart the service after changing it with sudo systemctl restart mysql (or mariadb).

Use a host firewall to allow only what you need. With UFW on Ubuntu, a basic web server policy looks like this. Allow SSH before enabling the firewall, and keep your existing session open while you test:

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

If you're on managed hosting, check the control panel for remote database access settings and disable any you don't use.

4. Apply the Principle of Least Privilege

Ransomware can only encrypt what the compromised account is allowed to write to. Reducing permissions reduces the blast radius:

  • Don't run your web server or PHP as root.
  • Give each site its own system user and PHP-FPM pool on shared servers, so a compromise of one site can't touch the others.
  • Set sensible file permissions: directories 755, files 644, and configuration files containing credentials even tighter.
  • Give database users only the privileges each application needs, and use a separate user per site.
  • Give CMS users the lowest role that lets them do their job, and remove accounts for people who no longer need access.

For WordPress, you can also stop admin users from editing code through the dashboard by adding this to wp-config.php, above the "That's all, stop editing!" line:

define( 'DISALLOW_FILE_EDIT', true );

5. Use a Web Application Firewall and Malware Scanning

A web application firewall (WAF) filters malicious requests before they reach your application, blocking many common exploit attempts against known vulnerabilities. Options range from cloud services such as Cloudflare and Sucuri to application-level plugins such as Wordfence for WordPress.

Pair it with regular malware scanning and file change monitoring, so you're alerted if files are added or modified unexpectedly. Early detection of a web shell can stop an intrusion before it turns into ransomware.

6. Keep Backups the Attacker Can't Reach

Backups are your safety net, but only if they survive the attack. Ransomware operators know that victims with good backups don't pay, so they deliberately look for and delete backups they can find.

The key principles are:

  • Follow the 3-2-1 rule: Three copies of your data, on two different types of storage, with one copy off-site.
  • Keep at least one copy off the server: Backups stored in the same hosting account or on the same disk will usually be encrypted along with everything else.
  • Make at least one copy immutable or offline: Object storage with versioning or object lock, or a backup service that doesn't let the website server delete old backups, means a compromised server can't wipe your history.
  • Keep several restore points: Attackers sometimes sit on a system for days or weeks. Retaining older backups lets you restore from before the intrusion.
  • Test restores regularly: A backup you've never restored is a hope, not a plan.

Protecting the backups themselves is a topic in its own right. The main idea is simple: the credentials that can create a backup should not be able to delete it.

7. Protect the People and Devices Around the Site

Many ransomware incidents start outside the server:

  • Train anyone with admin access to spot phishing emails and fake login pages.
  • Keep computers used to manage the site patched and protected with reputable antivirus software.
  • Don't save hosting or SSH passwords in plain text files or unprotected FTP clients.
  • Remove access for former staff, freelancers, and agencies promptly.

8. Monitor and Log

You can't respond to what you can't see. Useful monitoring includes:

  • Uptime monitoring, so you know immediately if your site goes down.
  • Alerts for new administrator accounts and file changes.
  • Server login logs, such as /var/log/auth.log on Ubuntu, reviewed or forwarded to a log service.
  • Hosting account notifications sent to an email address you actually read.

What to Do If Your Website Is Hit by Ransomware

If you discover a ransom note or encrypted files, act calmly and methodically:

  1. Isolate the site: Take the site offline or put it behind a maintenance page. If it's on a VPS, consider restricting network access so the attacker can't continue.

  2. Preserve evidence: Take snapshots or copies of logs and affected files before changing anything. They help work out how the attacker got in.

  3. Contact your host: Managed hosts often have incident teams and may have backups outside your account.

  4. Assess what was accessed: Work out whether customer data may have been stolen. Depending on your location and the data involved, laws such as the GDPR may require you to report a breach to authorities within a set time and notify affected people.

  5. Restore to a clean environment: Rebuild on a fresh server or clean hosting account where possible, restore from a backup taken before the intrusion, and then update everything.

  6. Close the entry point: Patch the vulnerability, remove backdoors, and change every password, key, and API token. Without this step, reinfection is likely.

  7. Report it: Consider reporting to your national cybercrime or cybersecurity agency. They may have guidance, and reports help track criminal groups.

Should You Pay the Ransom?

Law enforcement and security agencies generally advise against paying. Payment doesn't guarantee you'll get a working decryption key, doesn't guarantee stolen data will be deleted, marks you as a willing payer for future attacks, and funds further crime. In some jurisdictions, paying certain sanctioned groups may also be illegal. For websites in particular, restoring from good backups is almost always the better path, which is exactly why backups deserve so much attention.


FAQ: Website Ransomware

Yes. Attackers who gain access through a vulnerable plugin, stolen password, or exposed database can encrypt website files, wipe or steal databases, and leave a ransom note. Web servers are attractive because they're always online and often hold customer data.

They help, but don't rely on them alone. Some host backups are stored on the same infrastructure, kept for a short time, or not guaranteed. Keep at least one independent, off-site backup that you control.

No. HTTPS encrypts traffic between visitors and your server, but it does nothing to stop an attacker who exploits a vulnerability or logs in with stolen credentials.

Yes. Most attacks are automated and opportunistic. Scanners look for known vulnerabilities and weak passwords across millions of sites, regardless of size or traffic.

Typical signs include files with unfamiliar extensions, a homepage replaced by a ransom message, a database that's suddenly empty or contains a note, and a site that stops loading entirely. Check your server and hosting panel if you see any of these.

Patching and strong authentication stop most attacks from starting, but offline or immutable backups are what let you recover without paying. You need both.


Conclusion

Ransomware turns a website compromise into an extortion attempt, encrypting or stealing your files and data and demanding payment to get them back. For websites, it usually arrives through the same weak spots as any other hack: outdated software, weak or reused passwords, exposed services, and compromised devices.

The good news is that the defences are well understood. Keep software patched, protect every login with strong passwords and two-factor authentication, close services that don't need to be public, restrict permissions, and monitor for changes. Most importantly, keep tested backups that live off the server and can't be deleted by someone who breaks into it. With those in place, ransomware becomes an inconvenience you can recover from rather than a crisis you have to pay your way out of.

Tags :
Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
How does GDPR affect website security?

How does GDPR affect website security?

GDPR affects website security by turning it from a good habit into a legal obligation. If your website collects personal data from people in the EU (

Dive Deeper