A ransom note can be a real encryption attack or a frightening page. If files have new extensions, will not open, or multiple devices are affected, treat it as an incident. Do not rush to pay, run a random decryptor or attach your backup drive to the affected machine.
First-hour actions
- Disconnect the affected PC from Wi-Fi and wired networks. Unplug external backup drives that are connected, but do not move them between computers until they are checked. If this is a work device, contact your IT or incident-response team immediately.
- Record the note, affected file examples and approximate start time. Do not delete everything before a trusted professional can assess what happened. Avoid signing in to sensitive accounts on the suspect PC.
- From a clean device, secure important accounts if credentials on the PC may have been exposed. Check whether cloud storage synced damaged files; pause or contain affected sync before it overwrites recoverable versions.
- Assess recovery with known-good backups or version history. Scan and rebuild or restore the PC using a trusted process before reconnecting it to normal accounts and storage.