Resource icon

A ransomware note appeared on your PC. What should you do first?

A ransom note can be a real encryption attack or a frightening page. If files have new extensions, will not open, or multiple devices are affected, treat it as an incident. Do not rush to pay, run a random decryptor or attach your backup drive to the affected machine.

First-hour actions​

  1. Disconnect the affected PC from Wi-Fi and wired networks. Unplug external backup drives that are connected, but do not move them between computers until they are checked. If this is a work device, contact your IT or incident-response team immediately.
  2. Record the note, affected file examples and approximate start time. Do not delete everything before a trusted professional can assess what happened. Avoid signing in to sensitive accounts on the suspect PC.
  3. From a clean device, secure important accounts if credentials on the PC may have been exposed. Check whether cloud storage synced damaged files; pause or contain affected sync before it overwrites recoverable versions.
  4. Assess recovery with known-good backups or version history. Scan and rebuild or restore the PC using a trusted process before reconnecting it to normal accounts and storage.

What payment cannot promise​

Paying does not guarantee a working decryptor or deletion of copied data. A backup may restore files but cannot undo data theft. CISA's ransomware response guide recommends isolation and recovery planning. Our backup restore drill explains how to verify a copy after the immediate incident is contained. If personal or regulated data may have been copied, seek appropriate professional and local reporting advice.

Before restoring anything​

Confirm the backup predates the incident and can be opened safely from a clean environment. Restore a small sample first. Do not overwrite the only backup copy while experimenting. If several devices are involved, keep them isolated until the entry point and shared accounts have been reviewed; otherwise a restored computer may be exposed again.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack