HomeTrainingMalware and ransomware
This is the module’s public preview page. Employees take the course in the learning environment with a test and records.Start the course →
Module 5 · 8 min

Malware and ransomware

Attachments, downloads, macros, remote access, and data leakage.

The employee does not run unknown files and knows what to do when suspicious activity appears on screen.

Threat

The June 2026 Latvijas Valsts meži incident showed that ransomware also affects large Latvian companies.

What to know

  • Ransomware is not only data encryption. Data is often stolen first and then used for extortion.
  • An attachment may be an Office file, archive, PDF with a link, installer, or "security update".
  • Attackers also exploit vulnerabilities in public systems, not only email.
  • If a system behaves strangely, the important thing is not to hide it or quietly try to fix it alone.

Actions

  • Do not open unexpected attachments when the context and sender are unclear.
  • Do not install remote-access tools because a stranger tells you to.
  • If you ran a suspicious file, follow company procedure and report immediately.
  • Do not delete evidence: keep the email, screenshot, time, and sequence of actions.

Workplace scenario

Suspicious attachment

After opening an attachment, the computer slows down, an unknown window appears, and file names change. The employee is afraid of being blamed.

Think before the test

  • Why should the email and evidence not be deleted?
  • When should work on the device stop, and who must be informed?
  • Why is fast reporting more important than finding blame?

For the manager and responsible person

Ransomware training must end with a concrete reporting path, not just a vague "be careful".

  • Write a simple “first 15 minutes” incident card.
  • Separate the employee task from the IT task: report, preserve, do not hide.
  • Verify that backup restoration works in practice.

Sources