πŸ†˜ Emergency Guide Β· πŸ”΄ High Urgency

Ransomware Attack Response

Do not panic. Do not pay β€” at least not yet. Here is exactly what to do, step by step, when ransomware hits your business. Print this page and keep it somewhere you can find when your computer will not turn on.

🚨 IMMEDIATE ACTION REQUIRED

Time is critical. Every minute the infected device stays connected, the ransomware can spread to more systems. The first 15 minutes determine whether you lose one computer or your entire network.

Step 1: Isolate β€” Disconnect Immediately (First 5 Minutes)

  1. 1
    Disconnect the infected computer from the network. Unplug the Ethernet cable. Turn off WiFi. Do NOT shut down the computer yet β€” memory forensics may recover your encryption key if you decide to investigate.
  2. 2
    Disconnect ALL network-attached storage (NAS) devices and backup drives. If the ransomware reaches your backups, you lose everything.
  3. 3
    Disconnect cloud storage sync. Pause Google Drive, Dropbox, OneDrive syncing β€” ransomware encrypts local files, and the encrypted versions will overwrite your clean cloud copies if syncing continues.
  4. 4
    Check other computers. Are other machines showing the ransom note? If not, disconnect them from the network anyway until you confirm the ransomware has not spread.

Step 2: Photograph Everything

Take clear photos of the ransom note with your phone. Capture: the ransom amount, the cryptocurrency wallet address, any deadline/threat, and any "support" email or chat link the attackers provide. This information helps law enforcement track the attackers and may match known ransomware strains with available decryption tools.

Step 3: Identify the Ransomware Strain

Go to nomoreransom.org (a joint project by Europol, law enforcement agencies, and security companies). Use their Crypto Sheriff tool β€” upload one encrypted file and the ransom note. It will identify the ransomware strain and tell you if a free decryption tool exists. Many older ransomware strains have publicly available decryptors.

Step 4: Decide β€” To Pay or Not to Pay

Law enforcement (FBI, CISA, Europol) uniformly recommends not paying. Paying funds criminal enterprises, marks you as a target for future attacks, and there is no guarantee you will get your data back. However, for a small business without backups, the calculation is brutally practical: pay or go out of business.

⚠️ Before you pay: Check nomoreransom.org for a free decryptor. If none exists, contact your cyber insurance provider β€” paying may violate your policy if not coordinated through them. Engage a professional incident response firm to negotiate and handle the cryptocurrency transaction. Never attempt to negotiate with attackers yourself β€” you may make things worse.

Step 5: Restore from Backups (What You SHOULD Be Doing)

If you have clean, offline backups (and you tested them!), restoring is straightforward:

  1. 1. Wipe the infected systems completely. Do not attempt to clean them β€” reformat the drives and reinstall the operating system from scratch.
  2. 2. Restore data from your last clean backup. Verify the backup is not also encrypted before proceeding.
  3. 3. Scan the restored data with updated antivirus before bringing systems back online.
  4. 4. Update all software, change all passwords, and enable MFA before reconnecting to the internet.

Small Business Backup Strategy Guide

Never be in this position again. Exactly what to back up, how to set up automated off-site backups, and how to test they actually work.

Set Up Proper Backups β†’

Step 6: Report to Authorities

  • FBI IC3: File a complaint at ic3.gov
  • CISA: Report at cisa.gov/report
  • Local FBI field office: Find yours at fbi.gov/contact-us/field-offices
  • State/local law enforcement: May be required for breach notification purposes

Step 7: Prevent It from Happening Again

  1. 1. Implement 3-2-1 backups: 3 copies, 2 different media, 1 off-site. Test restores quarterly.
  2. 2. Enable MFA on everything. Ransomware often enters through compromised credentials.
  3. 3. Keep all software updated. Enable automatic updates for your OS, browser, and business applications.
  4. 4. Deploy endpoint protection with anti-ransomware. See our antivirus/EDR comparison.
  5. 5. Train your team. Most ransomware enters through phishing. Quarterly training is cheap insurance.
  6. 6. Segment your network. The office network should not be able to reach backup systems directly.