Ransomware Encryption
Ransomware encryption looks similar to losing a password to your own encrypted drive, but it's a fundamentally different situation — the key exists, it's just held by whoever attacked you, and the right response has more to do with the malware still on the system than with the encrypted files themselves.
What's actually happening
Ransomware encrypts files, sometimes an entire drive, using a key generated at the time of the attack, then typically deletes or corrupts the originals and leaves a ransom note demanding payment for the key. Some ransomware families have implementation flaws that researchers have already broken, meaning a free decryptor already exists for that specific strain; more recent, well-built ransomware generally doesn't have a known weakness.
How recoverable this really is
Varies enormously by which specific ransomware strain is involved, which is exactly why identifying it precisely — rather than assuming the situation is hopeless, or assuming it's easily fixable — is the real first step. Some well-known older strains have free public decryptors; well-implemented current ones generally don't. Beyond the ransomware's own flaws or lack of them, the other realistic path is whatever backups existed before the attack and weren't reachable by it, and in some cases forensic recovery of remnants of the original files if the ransomware deleted rather than overwrote them, similar in principle to the accidental deletion scenario, though this varies by ransomware family.
The general approach
Isolate the affected system from any network immediately to stop further spread, identify the specific ransomware family from the ransom note or the file extension it appended (projects like "No More Ransom" maintain identification tools and known decryptors), and check for backups untouched by the attack before considering anything else.
Don't pay the ransom as a first move, and don't reinstall the operating system or reformat the affected drives before an expert has looked at what's there. Paying doesn't guarantee a working key even when the attacker is willing to provide one, and a clean reinstall destroys exactly the remnants — deleted originals, ransomware artifacts needed for identification — that a real recovery attempt would need intact.
Practical, step-by-step guides for specific recovery software will be added here as separate linked articles.
This page describes the general situation, not a guaranteed fix for your specific case. If you'd rather have someone experienced take a look before you try anything, see what a hands-on evaluation looks like.