Man sits at a laptop computer and follows best practices to keep personal information and data safe from hackers.

How to protect data against hackers

04/28/2026

Either on-site or in the cloud, backups can keep your information safe and secure from cyber intruders.

While cybercriminals often focus their efforts on businesses, individuals are increasingly at risk of digital threats. Personal losses resulting from internet crimes exceeded $16 billion in 2024 — a 33% increase from the year before — according to data released in 2025 by the Federal Bureau of Investigation. Ransomware attacks, in which a hacker uses malicious software to encrypt a victim’s data unless they pay a ransom, can be particularly damaging and they increased 9% in 2024 from the year before. In fact the global cost of ransomware damage is expected to reach $74 billion in 2026, according to market data firm Cybersecurity Ventures.

The good news is that safeguarding your personal data isn’t difficult — provided you have a backup plan. By backing up your data to the cloud or to external storage devices, you can help protect it from ransomware attacks and quickly restore it should an attack occur.

Key takeaways:

  • Consumers are becoming increasingly at risk of ransomware attacks that target their personal data.
  • A breach can lead to the loss of valuable personal data and pave the way for credit card fraud or identity theft.
  • Backing up data regularly and using data protection tools from Fifth Third Bank are among the steps you can take to protect yourself from cybercriminals.

How ransomware attacks work

While ransomware attacks have traditionally targeted computers, the ubiquity and increasingly powerful capabilities of mobile devices have spurred bad actors to create malicious software, or malware, designed to infiltrate and compromise smartphones. Just one wrong click can trigger a series of actions that encrypts data to make it inaccessible to the user — until they pay a ransom.  

All too often, consumers fall prey to phishing emails that can lead to a ransomware attack. Consumers unwittingly provide personal information or click a link when responding to communications that falsely claim to be from a known person or organization. For example, you might receive an email that appears to be from Fifth Third Bank asking you for personal information. (Since Fifth Third Bank would never send an email asking for personal information, you could report that communication using the mobile app’s Report Phishing feature found in the SmartShield® 1 dashboard.)

Another potential ransomware threat is a bad actor who lures an individual to an infected website that secretly downloads and executes malware. Search engine optimization poisoning is a technique that manipulates keywords to raise search rankings of malicious sites to make them seem legitimate. A user may click top search results without paying attention to the web address and, once there, may enter personal information or download malware.

Consequences of a ransomware attack

No matter the device, the consequences of a ransomware attack can be significant and deeply personal. A successful attempt can erase a user's digital life, leaving them with a blank hard drive. Irreplaceable personal data such as family photos and legal and financial records could disappear. To make matters worse, personal data could be sold on the dark web, opening the door for hazardous leaks of sensitive information that could enable credit card fraud and identity theft.

The basics of backups

For individual users, disciplined daily backups represent the most effective way to avoid losing data due to ransomware attacks. You have two primary backup strategies to consider: Use your own equipment to make and manage backups or upload your data to cloud services for automatic backups.

When developing any backup plan, following the tried-and-true 3-2-1 strategy is often recommended: storing three copies of all data files, with two copies on two different types of media such as an external hard drive and the cloud and one copy kept in another location such as a safe deposit box. Most technology companies offer built-in tools that automate backups to external storage or the cloud. The Windows 11 operating system, for instance, enables users to create a system image and automatically back up and restore all programs and files. Backups can be stored on an external hard drive, removable media, a local area network or Microsoft’s cloud-based OneDrive storage.

Another option is installing third-party backup software. These solutions often provide more advanced tools such as being able to centralize and remotely manage data, whether in the cloud or on a range of storage devices that include external drives, solid-state storage, recordable optical media and USB flash drives.

It’s also a good idea to utilize additional security resources from your bank, if available. Fifth Third Identity Alert®5 provides Fifth Third Bank customers with daily credit monitoring2, Social Security monitoring3, email and text alerts and more.  Every Fifth Third Bank account also comes with a SmartShield®1 dashboard, found on the mobile app, which lets customers report suspicious emails, pause the usage of credit cards or sign up for Fifth Third Identity Alert®5.

Making a case for cloud storage

Established cloud service providers offer a range of tools that consolidate secure storage, automated data backups, data management capabilities and built-in security precautions.

Whether used as a primary or secondary backup, cloud storage offers several advantages. For one, you only need an internet connection to access data from anywhere. Cloud services can store and encrypt all types of files, photos and content. Most cloud providers let you schedule full and incremental backups to help you preserve your data. Popular cloud service providers include Microsoft OneDrive, IDrive, Google Drive, Dropbox, iCloud and Sync.com.

In addition, established cloud providers offer built-in cybersecurity protections against data breaches. You’ll pay a monthly fee for cloud storage, depending on the quantity of data stored and the services used.

What to always remember

In the end, much of the responsibility for data protection lies with you and other users within your digital domain. Here are some strategies you can put in place:

  • Stay up to date with evolving phishing and social engineering tactics associated with ransomware.
  • Think twice before clicking email attachments from unknown recipients, websites and social networking profiles. Fifth Third banking customers can report phishing attempts using the mobile app’s Report Phishing feature found in the SmartShield®1 dashboard. Suspicious emails from other entities should be sent to reportphishing@antiphishing.org.
  • Never disclose personal information to unauthorized individuals.
  •  Make sure your devices are backed up at least once a day to ensure your information is safe and up to date.

Technology can make it easier to store and access your personal and financial assets. Take advantage of Fifth Third Bank's security tools to help keep your data safe.

Data protection FAQs:

1.    What are some common characteristics of phishing emails?

A phishing attempt might have an unusual email subject line, spelling and grammar errors, or the improper use of a logo. You might also notice that the email conveys a sense of urgency to act and includes claims of suspicious activity related to your account or direct requests for personal information.

2.    What is two-factor authentication?

Two-factor authentication, also known as 2FA and multifactor authentication, is a method of identifying yourself to access your account. It uses two different pieces of information such as a password and a code that is sent to you via text or email. This additional step provides an extra layer of protection in case your password is ever compromised.

3.    What should I do if I think I’m experiencing a cyberattack?

To report fraudulent or suspicious activity with your account, call 800-972-3030, Monday through Friday, 8 a.m.-6 p.m. and Saturday, 10 a.m.-4 p.m. ET. To report activity on your card, follow the prompts to dispute a transaction or report a card lost or stolen. You may also report your card as lost or stolen at any time online or via the Fifth Third Mobile App.

Three things to do: