No More Ransom Project
No More Ransom is a nonprofit initiative offering free decryption tools, ransomware prevention advice, and a Q&A resource for victims.
Summary
No More Ransom is a nonprofit, public-private partnership between law enforcement and cybersecurity companies (led by Europol and the Dutch National Police) that provides free decryption tools, ransomware prevention advice, and a Q&A resource for victims. The project was born out of the realization that ransomware was becoming an epidemic — 718,000 users hit between April 2015 and March 2016, an increase of 5.5x over the prior period — and that the fight against cybercrime requires joint effort between police, justice departments, Europol, and IT security companies.
What You Need to Know
-
Free decryption tools exist: If your files have been encrypted by ransomware, there is a repository of keys and applications that can decrypt data locked by different ransomware families — at no cost and regardless of where you are located in the world. Currently available decryptors cover Midnight/Endpoint, FunkSec, Phobos/8base, DoNex, HomuWitch, BlackBasta, Rhysida, Lockbit 3.0, Akira, Ragnar, Bianlian, and RanHassan.
-
Paying is never recommended: Paying the ransom does not guarantee you will recover your files, and there can be bugs in the malware that make encrypted data unrecoverable even with the right key. Paying also proves to cybercriminals that ransomware is effective, encouraging them to continue and expand their attacks.
-
Prevention is possible: Following simple cybersecurity advice can help you avoid becoming a victim. Keep your software updated, use reputable security software, and be cautious about opening email attachments or clicking links from unknown sources.
-
Ransomware comes in several types: Encryption ransomware encrypts personal files (documents, spreadsheets, pictures, videos); lock screen ransomware (WinLocker) locks the computer screen without encrypting files; Master Boot Record (MBR) ransomware changes the boot process; and mobile device ransomware targets Android devices via drive-by downloads or fake apps.
-
Use the Crypto Sheriff: The project provides a tool called Crypto Sheriff to help identify which type of ransomware has affected your device, so you can check whether a decryption solution is available.
Take Action Today
- Before you pay — check for a free decryptor: Visit No More Ransom’s decryption tools page and search for your ransomware family. If a tool exists, it will decrypt your files without payment.
- Back up everything: Maintain offline backups of critical data and regularly test restores. Backups are your most reliable defense against ransomware.
- Patch and update: Keep operating systems, applications, and antivirus software up to date. Outdated software is the most common entry point.
- Report incidents: If you are hit by ransomware without a free decryption tool available, file a report with IC3.gov (U.S. victims) or your local law enforcement.
Related Pages
- cisa-stopransomware — CISA’s ransomware prevention tips and reporting resources
- fbi-cybersecurity — FBI guidance on ransomware and IC3 reporting
- cisa-cyber-essentials — CISA’s four essential cybersecurity practices for small business
- Cyber Resource Center — Master page with all resources