Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Windows Update Ransomware

Windows Update Ransomware

Randy Hall By Randy Hall Updated Jul 2024 3 min read Share

When you see a Windows update, you anticipate a security improvement, not a threat. However, a sneaky extortion scam disguised as a Windows update page has recently appeared.

Its danger lies in encrypting files on your computer. The scammers then demand payment to return your files. This extortion scam is known as Big Head ransomware. Currently, it is aimed at U.S. consumers.

Understanding Big Head Ransomware

Fortinet, a cybersecurity company, discovered Big Head ransomware. Fortinet believes Big Head launched in May 2023. There are several variants designed to lock your files and demand money.

The first version shows a fake Windows Update screen. After about 30 seconds, it disappears. By then, it locked your files and changed the file names.

In some cases, you might see “README” files. These carry email addresses, Telegram account details, and even Bitcoin addresses. All these are there to collect money from you in exchange for unlocking your files.

The second version has a different method. Instead of a Windows Update screen, it changes your desktop wallpaper to a ransom note. This note asks for one Bitcoin, which is around $30,000.

Protecting Your Company

Big Head ransomware can damage your business. But you can protect yourself and your sensitive data. Here’s how:

  • Watch out for phishing scams: Most ransomware comes through these scams. Make sure you understand and can identify the telltale signs of a scam.
  • Back up your data often: The more frequently you back up, the less data you lose if attacked.
  • Choose where you back up your data carefully: Some ransomware can delete backups.
  • Secure your backup: Even if the ransomware can’t delete your backup, it might still be able to lock it. If possible, store an offline copy.

Safeguard Against Ransomware

Big Head ransomware is a severe threat. It may not be widespread yet, but it’s better to be safe than sorry. Be cautious with Windows updates, and safeguard your organization from phishing scams. Back up your data frequently and store the backups in a secure location. These measures can prevent ransomware attacks. When you safeguard your files, you protect your company.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime