MYTHOSAI

Security basics / PRACTICAL GUIDE

What to do when you suspect ransomware

Contain the affected device, preserve useful evidence and protect unaffected backups.

Before you start

Access to the affected device and a separate trustworthy device for communications.

Recognise the situation

Suddenly unreadable files, changed extensions and a ransom note are strong warning signs. A slow computer alone is not enough to diagnose ransomware. Your first objective is to stop further damage and keep recovery options available, not to identify the malware family by opening more files.

Contain without destroying evidence

  1. Disconnect Ethernet and turn off Wi-Fi on the affected computer. Disconnect external backup media if it is attached. Avoid plugging it into another computer until assessed.
  2. At work, contact the responsible IT or incident-response person immediately using a separate device. Explain which computer, what time and what you observed.
  3. Photograph the ransom note and record filenames or symptoms without opening suspicious attachments. Do not upload business documents to public analysis sites.
  4. Do not reconnect simply to see whether the problem disappeared. An isolated computer can still encrypt its local files; urgent professional containment may be needed if encryption continues.

Keep power-state decisions deliberate. Restarting or powering off can lose volatile evidence, while leaving an active system running can permit continued damage. Follow the organisation's incident plan or responder's advice rather than treating one choice as universal.

Protect the recovery path

From a clean device, review whether other systems and accounts are affected. Secure administrative and remote-access credentials according to your incident process. Preserve a known clean backup before starting restoration. A synced cloud folder may contain the encrypted versions too; check version history and retention rather than assuming sync is a backup.

Recover in a controlled order

Identify and close the entry point, rebuild or clean systems using a trusted recovery process, then restore verified unaffected data. Restoring immediately to a still-compromised machine risks a repeat incident. Before returning to normal operations, test a representative file, a business application and its data dependencies.

Common mistakes

Paying does not guarantee decryption, removal of access or deletion of stolen data. Random decryptors can cause further harm; use only a verified tool matched to the incident with expert guidance. Do not discard logs or overwrite the only backup while experimenting.

Report and document

Use Australia's official cybercrime reporting route where appropriate. For a business, record service disruption, potentially exposed information and decisions made. Encryption and data theft can occur together; a successful restore does not answer whether information was stolen.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.