Emsisoft
A New Zealand-based cybersecurity company known for anti-malware software, ransomware intelligence, and data-recovery decryption tools.
Last updated August 22, 2026
Overview
Emsisoft is a cybersecurity software and consulting company whose best-known work combines endpoint protection with practical assistance for organizations and individuals affected by ransomware. The business was founded in Austria in 2003 by Christian Mairoll and later became headquartered in New Zealand after Mairoll relocated there in 2014. Although the company’s headquarters moved, Emsisoft retained a geographically distributed workforce spanning Europe, Asia, and the United States, reflecting a remote-oriented operating model. The company’s core commercial offering is anti-malware protection for home users, businesses, and larger organizations. Its product portfolio has included Emsisoft Anti-Malware in home, business, and enterprise configurations, together with browser protection intended to block malicious and phishing websites in Chrome, Firefox, and Microsoft Edge. The products are positioned around malware detection, ransomware defense, web protection, and relatively light system impact. Emsisoft also provides cybersecurity consulting and publishes research and reporting on ransomware activity. Emsisoft has developed a particularly visible public role through ransomware decryption. Its researchers create or contribute decryption tools that can help victims recover files encrypted by particular ransomware families without paying an extortion demand, where a technical weakness, recovered key, or other breakthrough makes recovery possible. The company donated decryption tools to Europol’s No More Ransom project in 2019, making selected recovery capabilities available through a broader law-enforcement and cybersecurity partnership. Emsisoft tools were also associated with recovery efforts following major ransomware incidents, including the 2021 Kaseya VSA attack and attacks linked to DarkSide and BlackMatter. Ireland’s National Cyber Security Centre used an Emsisoft decryption tool in connection with the May 2021 ransomware attack affecting the country’s health service. The ransomware work has helped distinguish Emsisoft from antivirus vendors focused solely on prevention. Its public communications track ransomware campaigns, explain victim-recovery options, and document the operational impact of attacks. This research and incident-response orientation gives the brand visibility beyond its retail software products and places it within the wider ecosystem of security researchers, law-enforcement agencies, and nonprofit initiatives. Emsisoft experienced a security incident in early 2021 when a configuration error exposed a database containing log records, including email addresses generated by the company. At least one unauthorized person accessed the information. Emsisoft stated that it disconnected the affected system, used forensic analysis to investigate, introduced additional security measures, notified customers, and publicly apologized. The incident is significant to the brand’s history because it concerned the security of Emsisoft’s own systems rather than a customer endpoint. Emsisoft remains an active independent cybersecurity brand with a portfolio spanning consumer and organizational endpoint protection, browser-based web safety, ransomware intelligence, consulting, and free or publicly shared decryption resources. Its identity is therefore built on two complementary propositions: preventing malicious software from compromising devices and helping victims recover when prevention fails.
History
Emsisoft was established in Austria in 2003 by Christian Mairoll as an anti-malware software company. Its original business centered on protecting computers from malicious software, but the company’s scope expanded as ransomware became a defining threat to businesses, public institutions, and individual users. Alongside endpoint protection, Emsisoft developed expertise in analyzing ransomware families and producing decryption tools when technical circumstances made file recovery possible. The company’s product strategy developed around multiple customer segments. Emsisoft Anti-Malware was offered in home, business, and enterprise versions, allowing the brand to serve individual users as well as organizational environments. It also produced browser extensions for Chrome, Firefox, and Microsoft Edge to block malicious and phishing websites. These products complemented the company’s wider consulting and research work, which included monitoring ransomware campaigns and publishing analysis of attacks. A major organizational change occurred in 2014, when Mairoll relocated to rural New Zealand and moved Emsisoft’s headquarters there. The company continued to operate with employees distributed across Europe, Asia, and the United States. This international and remote structure became part of the company’s operating identity while its commercial and research activities remained global. Emsisoft became especially prominent through public-interest ransomware recovery. In 2019, it donated decryption tools to Europol’s No More Ransom project. That initiative connects law-enforcement agencies, cybersecurity companies, and other partners to help victims identify ransomware and recover encrypted data where tools are available. Emsisoft’s participation extended the reach of its technical research beyond paying customers. During 2021, Emsisoft decryption tools were connected with response efforts involving several high-profile ransomware events. They were used to help address consequences of the Kaseya VSA attack and attacks attributed to the DarkSide and BlackMatter ransomware groups, which affected organizations in the United States, Europe, and the United Kingdom. In Ireland, the National Cyber Security Centre used an Emsisoft tool in recovery work following the ransomware attack on the country’s health service in May 2021. These cases reinforced Emsisoft’s reputation as a specialist provider of practical post-incident assistance rather than solely a preventive antivirus vendor. Emsisoft also faced a breach of its own systems in early 2021. A configuration error exposed a database containing log records, including email addresses generated by the company. At least one unauthorized person accessed the exposed information. Emsisoft responded by disconnecting the compromised system, conducting a forensic investigation, adding security mechanisms, notifying customers, and issuing a public apology. The episode became an important part of the company’s corporate history because it demonstrated the operational and reputational risks faced by a cybersecurity provider handling customer-related records. Today, Emsisoft’s identity spans commercial anti-malware and endpoint security, web protection, ransomware research, consulting, and decryption assistance. Its history reflects the broader evolution of cybersecurity from traditional virus detection toward a more integrated model involving endpoint defense, threat intelligence, incident response, and victim recovery.
- 2021Decryption tools used in ransomware recovery
Emsisoft tools supported recovery efforts related to the Kaseya VSA, DarkSide, and BlackMatter incidents and were used by Ireland’s National Cyber Security Centre after the health-service attack.
- 2021Company discloses data exposure
A configuration error exposed a database containing log records and email addresses; Emsisoft investigated, notified customers, strengthened controls, and apologized.
- 2019Decryption tools contributed to No More Ransom
Emsisoft donated ransomware decryption tools to Europol’s No More Ransom project.
- 2014Headquarters moved to New Zealand
After Mairoll relocated to rural New Zealand, Emsisoft moved its headquarters there while retaining a distributed international workforce.
- 2003Company founded in Austria
Christian Mairoll founded Emsisoft in Austria as an anti-malware software company.
Products and positioning
Specialist cybersecurity provider combining lightweight anti-malware protection with ransomware research, incident assistance, and decryption capabilities.
Emsisoft Anti-Malware HomeConsumer endpoint security
The home-user edition of Emsisoft’s anti-malware offering, designed to protect personal computers against malicious software and related online threats. It represents the consumer-facing part of the company’s endpoint-security portfolio and is associated with the brand’s emphasis on malware detection, ransomware defense, and low system overhead.
Emsisoft Business SecurityBusiness endpoint security
A business-oriented version of Emsisoft’s anti-malware technology for organizational endpoints. The product extends the company’s core protection proposition from individual users to commercial environments, where malware prevention and ransomware resilience are central operational concerns.
Emsisoft Enterprise SecurityEnterprise endpoint security
The enterprise tier of Emsisoft’s anti-malware portfolio. It is intended for larger organizations requiring protection across managed computing environments and forms part of the company’s broader enterprise-security and consulting activities.
Emsisoft Browser SecurityBrowser protection
A browser extension for Google Chrome, Mozilla Firefox, and Microsoft Edge that helps block access to malicious and phishing websites. The extension complements endpoint protection by addressing web-based delivery routes for malware and credential theft.
Emsisoft ransomware decryption toolsRansomware recovery
A collection of tools created for particular ransomware families when recovery is technically feasible. These utilities can help victims restore encrypted files without paying an attacker and have been shared through public-interest initiatives, including No More Ransom, as well as used in incident-recovery work.
Flagship businesses
- Emsisoft Anti-Malware Home
- Emsisoft Business Security
- Emsisoft Enterprise Security
- Emsisoft ransomware decryption tools
Marketing campaigns
- 2019No More Ransom decryption-tool contribution
Global
Emsisoft contributed ransomware decryption tools to Europol’s No More Ransom project, supporting the initiative’s goal of helping victims recover files and avoid financing extortion through ransom payments.
Outcome. The tools became available through a wider law-enforcement and cybersecurity collaboration.
Brand decisions
- 2021Respond to internal data exposureOther
A configuration error exposed a database containing log records and email addresses, and an unauthorized individual accessed the information.
What changed. Emsisoft disconnected the affected system, commissioned forensic investigation, added security mechanisms, notified customers, and issued a public apology.
Aftermath. The incident became a documented security and trust issue for the cybersecurity provider, although no financial impact is specified in the available sources.
- 2019Share decryption tools through No More RansomStrategy
Ransomware victims and public institutions needed ways to recover encrypted files without paying attackers.
What changed. Emsisoft donated selected decryption tools to Europol’s No More Ransom project.
Aftermath. The company’s recovery technology reached victims through a broader public-interest cybersecurity initiative.
- 2014Move headquarters to New ZealandStrategy
Founder and chief executive Christian Mairoll relocated to rural New Zealand.
What changed. Emsisoft moved its headquarters to New Zealand while maintaining employees across Europe, Asia, and the United States.
Aftermath. The company continued operating as an internationally distributed cybersecurity business.
Leadership
| Name | Title | Tenure |
|---|---|---|
| Christian Mairoll | Chief Executive Officer and founder | — |
Controversies
- 2021Emsisoft database exposureControversy
A configuration error exposed a database containing log records, including email addresses generated by Emsisoft. At least one unauthorized individual accessed the information. The company disconnected the affected system, conducted forensic analysis, implemented additional security measures, notified customers, and apologized publicly.
Recent events
- 2021Emsisoft decryption tools support recovery from major 2021 ransomware incidents
Emsisoft decryption tools were used or associated with recovery efforts involving the Kaseya VSA, DarkSide, and BlackMatter ransomware incidents affecting organizations in several countries.
Other - 2021Emsisoft tools used in Irish health-service ransomware recovery
Ireland’s National Cyber Security Centre used an Emsisoft decryption tool in May 2021 to assist recovery from a ransomware attack affecting the country’s health service.
Other - 2019Emsisoft donates ransomware decryption tools to the No More Ransom project
Emsisoft contributed decryption capabilities to Europol’s No More Ransom initiative, expanding access to tools intended to help ransomware victims recover files without paying attackers.
CampaignOther
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/emsisoft · Editorial policy · How profiles are compiled