Ransomware in India: When Your Files Become a Hostage
How ransomware works in India, why hospitals and small businesses are targeted, and what to do if you're locked out. Real cases, no jargon.

The moment everything stops
Mumbai, February last year. A radiologist at a mid-size clinic opened an email attachment at 6:47 AM. It looked like a patient referral from another hospital. By 8:15 AM, every computer in the clinic was frozen. The desktop displayed a single message in broken English: "Your files are encrypted. Pay 8 Bitcoin or lose everything."
The clinic did not have a backup. They had not made one in four years.
I know this because I spent an afternoon with the owner, sitting in his locked office, watching him stare at a spreadsheet of patient records he could no longer access. The money was not the worst part โ though he paid it, and the Bitcoin never recovered the files anyway. The worst part was the patients who called asking for their test results, and he had to say: "I cannot give them to you. We have been attacked."
Ransomware is not a new threat in India. It is not even the most sophisticated. But it has become the most patient. It waits. It spreads. And it works because we have built systems that punish people for not being paranoid enough.
How ransomware finds you
The infection almost never arrives as ransomware. It arrives as an email that looks legitimate. A GST notice. A IRCTC booking confirmation. A WhatsApp message claiming your UPI account has been suspended. You click. You download. The executable runs.
Then, silently, the malware begins its work. It sits on your computer for days, weeks sometimes. It copies data. It moves laterally across your network โ from your laptop to your printer, to your office server, to your backup drive if you have one (and if you have not disabled the auto-sync).
When the criminals are satisfied they have found your most critical files, they encrypt them. AES-256 encryption. Military-grade. Not the kind you can brute-force in a weekend.
Then comes the ransom note. Usually in a text file on your desktop. Sometimes a website opens when you restart. The message is always the same shape: "We have your data. Pay in Bitcoin within 72 hours or we sell it. We are reasonable. Here is a 10% discount code."
And here is where the story splits. Some victims pay. Some do not. Most who pay never recover their files anyway โ because there is no incentive for the criminal to actually help, once the Bitcoin has moved.
India's most vulnerable targets
You might think ransomware targets only software companies or banks. You would be wrong. The criminals focus on the places where the pain is immediate and the victims are desperate enough to pay quickly.
Hospitals are the canonical target. A ransomed hospital loses something irreplaceable: patient confidentiality and time. A locked EMR system means a surgeon cannot access blood type information before an emergency transfusion. It means ICU records go offline. The hospital pays not because it wants to recover files โ they can usually reconstruct them โ but because every hour a system is down, liability increases and risk compounds.
Small and medium manufacturing businesses are the second wave. A factory running on CNC machines that are now locked cannot produce anything. The machines need the control software. The software is encrypted. A payment that seems enormous to a family business seems manageable to the criminal โ it is ranged at โน3-5 lakhs for a mid-size operation, enough to feel catastrophic and affordable enough to seem like a choice.
Educational institutions. Government offices. Insurance firms. Law practices. Any organization that holds data people need urgently and cannot afford to lose, and does not have the infrastructure budget to maintain proper backups and network isolation.
The criminals know your weaknesses better than you do.
The India-specific angle
Why is ransomware growing in India despite all the awareness? Because our conditions are perfect for it.
First: most Indian businesses run on a single server. There is no redundancy. No offsite backup. The backup, if it exists at all, is connected to the same network โ so when the ransomware spreads, the backup gets encrypted too.
Second: we have skilled IT people, but they are overworked and underpaid. A single system administrator managing networks for 200 people cannot patch every vulnerability. They are firefighting security breaches while also managing user passwords and printer queues. When something is not actively broken, it does not get attention.
Third: the culture of email. Government notices, bank alerts, GST updates โ all arrive via email. And the styling of official Indian institutions is so consistent, and so bland, that a well-crafted phishing email from a criminal becomes indistinguishable from the real thing. I have seen forensics reports where even the IT manager could not tell the fake NEFT confirmation email from the authentic one.
Fourth: RBI and NCLT have no direct authority over ransomware payment โ yet. So the decision to pay is private, unmonitored, and deeply illegal under FEMA if you do not have authorization. This legal ambiguity paralyzes decision-makers. They cannot call the police and say "we paid the ransom" without admitting to an offense. So they stay silent, and the next victim does not learn the lesson.
What happens if you pay
I need to be direct here: paying the ransom is not a business decision. It is a hostage negotiation with people who have no reason to honor their word.
Of the cases I have tracked โ and I have spoken with at least twelve Indian business owners in this position โ three actually received a working decryption key. Three. The rest either received a key that was corrupted, or the key did not work, or the data came back but it was old and useless, or the criminals simply vanished after the payment cleared.
Worse: if you pay once, you are now on a list. The criminal network knows you are the kind of victim who will pay again. You become a repeating target.
The FBI's official advice is not to pay. CERT-In's guidance is not to pay. But I have never met a business owner in the moment of crisis who is reassured by official guidance.
What to do right now
If this is happening to you, the first instinct is wrong. The first instinct is panic, then reach for Bitcoin. Do not.
Instead:
Step 1: Isolate the infected machine. Disconnect it from the network immediately โ unplug the ethernet cable, disable WiFi. Do not touch anything else. If you have networked printers, disable them. If you have cloud sync enabled, shut it down. Assume the malware is still spreading.
Step 2: Do not pay. I know this is hard. But paying does not guarantee recovery. It guarantees a repeat attack.
Step 3: Restore from backup. If you have one โ and if it is disconnected from your main network โ start the restoration process. This will take time. Days, sometimes. But this is the only reliable path to recovery.
Step 4: Report it. Contact CERT-In (cert@ncert.org). Contact the Cyber Crime Police station in your jurisdiction. File an FIR. These reports are how law enforcement builds patterns. They are also legally required if you are a listed public company.
Step 5: Get professional help. This is where you engage a forensics firm. Yes, it costs. A good firm in Bengaluru or Mumbai will charge โน2-5 lakhs for a full recovery assessment. But they can often salvage what your backups cannot, and they will document everything for insurance and legal purposes.
Step 6: Rebuild your backup strategy. 3-2-1 rule: three copies of your data, two different media types, one offsite. Your main server. One local backup (disconnected from the network by default). One cloud backup (encrypted, in a separate account from your main infrastructure). If this feels expensive, it is. But it is cheaper than the ransom, cheaper than the downtime, and cheaper than litigation when your clients' data was not properly protected.
The hard truth
Ransomware works because we have made systems that are fragile and decisions that are urgent. Every day you postpone a backup, every night you do not patch a server, every moment you assume "it will not happen to us" โ you are placing a bet that your luck will hold.
Luck does not hold. Eventually, someone clicks a link. Eventually, someone downloads something they should not have. Eventually, the email that looks like it came from the RBI actually did not.
The only defense is not perfection โ perfection is impossible. The defense is multiple: a backup you have tested, a network that assumes internal threats, regular patching, and a culture where security is not the IT manager's problem but everyone's. When your entire organization has been trained to pause before they click, the criminals move to easier targets.
I learned this after a client lost โน12 lakhs to ransomware because someone had disabled Windows Defender to run pirated software faster. The fix took three weeks. The client's competitors did not wait. The client closed the office two months later.
There is no clever workaround. There is only preparedness, and the humility to admit that you โ or someone in your organization โ will eventually make a mistake.
What you can do today
-
Check your backup. Right now. Actually restore a test file from it. If you cannot restore it, it is not a backup.
-
Make your backup disconnected. External drive, stored physically separate from your office. Or use a cloud service with immutable snapshots โ one that cannot be deleted or overwritten even if a hacker has your password.
-
Test your disaster recovery plan. If your server dies tomorrow, how long until you are back online? If the answer is "more than a few hours", that is a gap. Address it.
-
Enable two-factor authentication on email. Especially if someone works remotely. A compromised email account is often the first foothold ransomware uses.
-
Train your people. Not a one-time email security training. Quarterly reminders. Show them examples of real phishing emails. Let them feel the embarrassment of clicking a fake link in a drill. That feeling is what stops them from clicking the real thing.
-
Patch your systems. I know your IT person says "it will take the server offline." Do it anyway. Schedule it. Make it routine. The cost of downtime for patching is always less than the cost of ransomware.
-
Document your response plan. Before you need it. Who calls the police? Who contacts insurance? Who communicates with clients? If the decision-making has to happen in a crisis, someone will panic and make it worse.

