GCSE · Computer Science · Edexcel · Spec 1CP2
Malware – ransomware
One USB stick. One school network. Every file is still there — and not one of them will open.
Computer Science · Structure
How one USB stick locked a whole school
Tap each part to follow the stick. Find where the malware came in, how far it reached, and the check that was skipped.
Tap any part of the diagram to see what it does.
Computer Science · Malware
Open door or locked door?
For each everyday action, decide: does it open a way in for malware, or reduce the risk?
Still to sort
Opens a way in or raises the risk (0)
Malware, including ransomware, can use this to get into a system.
Reduces the risk (0)
A check that helps keep malware out.
Where the line is: Only one action here lowers the risk. Every other action is a way in, or makes getting in more likely.
Ransomware · the victim's side
Reason it through
Why is being locked out of your own files such a big problem?
First link · your turn
Ransomware is on the computer. What does it do to the files?
WHAT YOU'VE LEARNED
A quick recap of today's lesson.
One unchecked USB stick, and a whole school's data is still there but out of reach.
What you need to know
- Ransomware is malware that locks a computer and encrypts the files, so the user cannot access their data.
- The user stays locked out until a ransom is paid. A ransom is money the criminals demand.
- Ransomware does not need to delete anything. The files are still there, but the owner can't get at them.
Have a goYour mate Sam says, 'Ransomware wipes your homework off the computer, gone forever.' What would you tell Sam it actually does to the files?
It encrypts them. They're still there, but you can't get at them.
Sam has mixed up deleting with encrypting: the data isn't gone, the owner is just locked out of it.
- It's its own named type of malware, alongside viruses, worms, trojans, spyware and adware.
Have a goTrue or false: 'Ransomware is just another name for a virus.'
False. Ransomware is its own named type of malware.
Both are malware, which makes them feel like the same thing, but the list of malware types names them separately.
- Malware has several ways in. An unchecked USB stick and an email attachment are two of them.
- More ways in: pirated or fake software, a fake app, a link on a fake website, and unsafe Wi-Fi.
- A security weakness, or vulnerability, in an operating system, an application or other code is one way ransomware gets in.
- No antivirus, or software left un-updated with a known weakness, raises the risk. Scanning a stick before use lowers it.
Have a goLaptop A has antivirus and up-to-date software. Laptop B has no antivirus and an application with a known security weakness that was never updated. Which is at greater risk?
Laptop B.
No antivirus and an un-updated known weakness each raise the risk, so B has two things working against it.
- The damage can be data loss, system failure or financial loss, on one device or across a whole network.
- In the school story, scanning the USB stick before executable files reached the network would have stopped the breach.
The big picture
Ransomware is a named type of malware that locks a computer and encrypts its files, so the owner can't get at their own data until a ransom is paid. It can get in through an unchecked USB stick, among other routes, and the damage can reach a whole network.
Key points
Worked example
Problem
Maya plugs a USB stick into her laptop without scanning it. Her laptop has no antivirus. Later, her files won't open and a message demands money. Name the type of malware, say what it has done to her files, and give two things that raised the risk.
⚠ Watch out
Writing that ransomware deletes files, or calling it 'a virus'. It encrypts files so the owner can't get at them, and it has its own place in the list of malware types.
Memory hook
Locked, not lost: ransomware leaves the files where they are, but encrypted, so you can't open them until the ransom is paid.
Check yourself
Without scrolling up: name one thing that raises the risk of malware getting in, one thing that lowers it, and one kind of damage ransomware can cause.
Flashcards
(11)What does ransomware do?
What is a ransom?
Does ransomware have to delete your files to block you?
Name the five other named types of malware that sit alongside ransomware.
Is ransomware just another name for a virus?
Name three ways malware can get into a system.
What is a security vulnerability?
Name two things that raise the risk of ransomware getting in.
What reduces the risk from a USB stick?
Name three kinds of damage ransomware can cause.
In the school story, which check would have prevented the breach?
Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.
Learning with Lightbulb is opening soon
You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.
Keep me postedMore Edexcel GCSE Computer Science topics
How this lesson was checked. This Edexcel GCSE Computer Science (specification 1CP2)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.