The invoicing software on the shop’s front-desk computer had expired, and a paid license felt like money the two-person flower shop did not have. So the owner did what a lot of us have done at least once: she searched for a free version, clicked the top result, and installed it.

That program even worked, sort of. It also carried a passenger. Within three days, the shop’s card reader stopped syncing, files started renaming themselves, and a message appeared demanding payment to release the files. This is what one bad download can do, told as a composite of cases I have seen play out the same way.

Key takeaways

  • Free “cracked” software is one of the most common ways malware gets onto small-business computers.
  • The real cost is rarely the ransom. It is the downtime, the lost records, and the scramble to recover.
  • A handful of cheap habits would have stopped the whole thing before it started.
  • Backups turn a business-ending event into an annoying afternoon.

What actually happened

The download bundled a piece of malware that quietly sat waiting. It watched for a couple of days, mapped the shop’s files, then encrypted them and demanded around 900 dollars in cryptocurrency.

computer screen showing a ransom payment demand
One download turned the shop's own files into a hostage note.

That front-desk machine ran everything: appointments, the customer list, supplier invoices, and the card reader software. When it locked up, the shop could still sell flowers, but it could not look up who had ordered what, and it could not print the receipts a few corporate clients required.

The owner had no backup. The customer list existed in exactly one place, and that place was now scrambled.

The bill nobody expected

The ransom was the smallest number on the list. Here is roughly how the costs stacked up.

Cost Rough amount Notes
Ransom demanded $900 Never pay; paying rarely returns clean files
IT help to clean and rebuild $1,200 Two visits from a local technician
Lost sales during downtime $2,000+ Four days of partial operation
Rebuilding the customer list Weeks Reconstructed from email and memory
Reputation with two clients Hard to price Late orders, awkward apologies

She did not pay the ransom, which was the right call. Paying funds the criminals and often returns nothing usable. Instead she paid a technician to wipe the machine and start fresh, and she spent weeks rebuilding records from scraps.

Watch out

Free versions of paid software are a classic malware delivery method. The download works just well enough to seem legitimate, which is exactly what keeps you from suspecting it while it does its real job in the background.

The warning signs she missed

Looking back, the computer told her something was wrong before the lockout. She just did not know the language it was speaking.

The machine ran hot and slow for two days. A security warning popped up during install and she clicked through it. A browser extension she never added appeared in the corner. Each of these is a flag, and the guide on the 8 warning signs your device has malware covers the ones worth watching for.

None of this required expert knowledge to catch. It required knowing that a slow, hot, suddenly-strange computer is often trying to tell you something.

Why the two-day wait matters

The delay was not an accident. Modern ransomware often sits quietly at first, learning the layout of your files and, in a shop, waiting to see whether the machine gets backed up. If it strikes before any backup exists, there is nothing to restore from.

That patient behavior is exactly why the early warning signs are worth learning. The window between “something feels off” and “everything is locked” is often a day or two, and that window is when a quick reaction can save you.

What would have stopped it

The frustrating part is how ordinary the fixes are. Not one of them is technical or expensive.

Do not install cracked software

One single decision started everything: chasing a free copy of paid software. A legitimate free alternative, or the actual paid product on a payment plan, would have carried no passenger. When a download comes from a random search result rather than the maker’s own site, treat it as a stranger.

Keep real protection running

The built-in antivirus on the computer had been switched off months earlier because it “slowed things down.” Left on, it very likely would have flagged the installer. Leaving these defenses active is one of the simplest steps in the basics of securing your phone and computer.

Back up automatically

This is the big one. If the customer list and invoices had been backed up to the cloud or an external drive, the whole crisis shrinks to “wipe the machine and restore.” Instead of weeks of rebuilding, it becomes an afternoon.

Tip

Set backups to run automatically so no one has to remember. A backup that depends on a busy shop owner remembering to plug in a drive is the backup that will not exist on the day you need it.

How the recovery finally went

The technician wiped the computer completely and reinstalled a clean system, which is the reliable way to remove ransomware. The steps for doing this yourself, when the situation is simpler, are laid out in the guide to removing malware from your computer yourself.

The shop now runs its backups automatically, keeps the antivirus on, and buys software only from official sources. It was an expensive lesson for a small business, but the habits that came out of it cost almost nothing. The FTC keeps a plain small-business ransomware guide at consumer.ftc.gov that echoes the same handful of steps.

Your afternoon checklist

  • Only download software from the maker’s official website or an official app store.
  • Never install cracked or “free” versions of paid programs.
  • Turn your built-in antivirus back on and leave it running.
  • Set up automatic backups of your important files to the cloud or an external drive.
  • Test that you can actually restore a file from your backup.
  • Learn to read the early warning signs: a hot, slow, suddenly-strange computer.
  • If you are ever hit with ransomware, do not pay; wipe and restore from backup instead.

A florist is not a tech company, and she never should have needed to become one. The whole ordeal came down to a single click and the absence of a backup, and both of those are fixable in an afternoon by anyone reading this.