π¨ IMMEDIATE ACTION REQUIRED
Time is critical. Every minute the infected device stays connected, the ransomware can spread to more systems. The first 15 minutes determine whether you lose one computer or your entire network.
Step 1: Isolate β Disconnect Immediately (First 5 Minutes)
- 1Disconnect the infected computer from the network. Unplug the Ethernet cable. Turn off WiFi. Do NOT shut down the computer yet β memory forensics may recover your encryption key if you decide to investigate.
- 2Disconnect ALL network-attached storage (NAS) devices and backup drives. If the ransomware reaches your backups, you lose everything.
- 3Disconnect cloud storage sync. Pause Google Drive, Dropbox, OneDrive syncing β ransomware encrypts local files, and the encrypted versions will overwrite your clean cloud copies if syncing continues.
- 4Check other computers. Are other machines showing the ransom note? If not, disconnect them from the network anyway until you confirm the ransomware has not spread.
Step 2: Photograph Everything
Take clear photos of the ransom note with your phone. Capture: the ransom amount, the cryptocurrency wallet address, any deadline/threat, and any "support" email or chat link the attackers provide. This information helps law enforcement track the attackers and may match known ransomware strains with available decryption tools.
Step 3: Identify the Ransomware Strain
Go to nomoreransom.org (a joint project by Europol, law enforcement agencies, and security companies). Use their Crypto Sheriff tool β upload one encrypted file and the ransom note. It will identify the ransomware strain and tell you if a free decryption tool exists. Many older ransomware strains have publicly available decryptors.
Step 4: Decide β To Pay or Not to Pay
Law enforcement (FBI, CISA, Europol) uniformly recommends not paying. Paying funds criminal enterprises, marks you as a target for future attacks, and there is no guarantee you will get your data back. However, for a small business without backups, the calculation is brutally practical: pay or go out of business.
Step 5: Restore from Backups (What You SHOULD Be Doing)
If you have clean, offline backups (and you tested them!), restoring is straightforward:
- 1. Wipe the infected systems completely. Do not attempt to clean them β reformat the drives and reinstall the operating system from scratch.
- 2. Restore data from your last clean backup. Verify the backup is not also encrypted before proceeding.
- 3. Scan the restored data with updated antivirus before bringing systems back online.
- 4. Update all software, change all passwords, and enable MFA before reconnecting to the internet.
Small Business Backup Strategy Guide
Never be in this position again. Exactly what to back up, how to set up automated off-site backups, and how to test they actually work.
Set Up Proper Backups βStep 6: Report to Authorities
- FBI IC3: File a complaint at ic3.gov
- CISA: Report at cisa.gov/report
- Local FBI field office: Find yours at fbi.gov/contact-us/field-offices
- State/local law enforcement: May be required for breach notification purposes
Step 7: Prevent It from Happening Again
- 1. Implement 3-2-1 backups: 3 copies, 2 different media, 1 off-site. Test restores quarterly.
- 2. Enable MFA on everything. Ransomware often enters through compromised credentials.
- 3. Keep all software updated. Enable automatic updates for your OS, browser, and business applications.
- 4. Deploy endpoint protection with anti-ransomware. See our antivirus/EDR comparison.
- 5. Train your team. Most ransomware enters through phishing. Quarterly training is cheap insurance.
- 6. Segment your network. The office network should not be able to reach backup systems directly.