First, Limit the Damage; Do Not Attempt to Decrypt Right Away

When files suddenly become inaccessible, have their extensions changed, or a ransom notification appears on your desktop, your first goal should not be to restore your computer immediately but to stop further impacts. By the time the ransom notice appears, encryption may have already been in progress for some time; if the device is still connected to the company network, NAS, external hard drives, or cloud sync folders, the affected area could continue to expand.

Stage One: Isolate the Affected Device

If the computer is still operational, first disconnect the network cable, turn off the Wi-Fi, and disconnect unnecessary external storage devices. Do not take any suspicious computers to connect to more hard drives, nor should you plug in new backup devices for testing. If the screen shows that files are still being renamed or encrypted in large quantities, whether to shut down the device should be assessed based on the importance of the data and the need for evidence; personal devices should prioritize damage limitation, while business environments should have decisions made by incident response or digital forensics personnel.

Cloud syncing also needs to be addressed. OneDrive, Google Drive, Dropbox, or other syncing tools may upload encrypted files, overwriting the original versions. You should first log in to your account from a clean device, pause syncing or protect your account, and then check version history and recycle bins.

Stage Two: Preserve Necessary Evidence

Do not rush to delete ransom notifications, encrypted files, or suspicious attachments. You should preserve the ransom message, payment address, encrypted file extensions, timestamps, suspicious emails, download records, remote login logs, and a small sample of encrypted files. This information will help determine the ransomware family, infection entry points, and whether there are any trustworthy decryption tools available.

If the incident involves company data, client data, or multiple devices, it is not recommended to directly reinstall all devices. Reinstalling could result in losing some login records, malicious sample files, or intrusion paths, which would impact the subsequent assessment of whether any backdoors still exist.

Stage Three: Handle Accounts with a Clean Device

Do not change passwords on a potentially infected computer. Use a confirmed clean device to prioritize managing Email, Microsoft 365, Google accounts, cloud drives, remote desktops, VPN, NAS management accounts, and other administrator accounts.

If ransomware could have entered through remote desktop connections, weak passwords, stolen credentials, or phishing attachments, simply cleaning local files is not sufficient. You need to check login activities, unusual IP addresses, administrator accounts, shared folder permissions, and any recently added users or scheduled tasks.

Stage Four: Verify Backups First, Then Restore Data

To determine if backups are usable, you need to assess whether they have been isolated from the infected environment. Long-term connected external hard drives, writable NAS, or continuously synced cloud storage folders could already contain encrypted versions. A safer method is to retrieve a small number of files from offline backups, snapshots, version history, or historical versions, and test them in a clean environment.

Do not initially connect all backups back to the original network. You should first confirm that the infection source has been addressed, the system and applications are updated, unnecessary remote services are shut down, and passwords have been changed before restoring data in batches.

To Pay or Not, Reinstall or Preserve Disk Images

Paying the ransom does not guarantee results; you may not receive effective decryption tools, nor does it prove that leaked data will be deleted. The decision to pay involves legal, insurance, operational, and data breach risks, and should not be made solely based on a countdown screen.

For personal devices with trusted backups, it is usually okay to reinstall and restore after preserving necessary records. For businesses, servers, multi-device infections, or suspected data breaches, you should first consider preserving disk images and logs before deciding on clean-up and recovery methods.

In these types of incidents, the worst mistake is to act out of panic; deleting evidence, connecting backups, installing unfamiliar decryption tools, or entering new passwords on infected devices. Isolate, preserve evidence, protect accounts, verify backups, and then restore data is usually more important than quickly trying to ‘rescue the display’.