The first thirty minutes
- Disconnect the machine from the network: unplug the cable, turn off Wi-Fi. Do not power it off yet; memory can hold the decryption key.
- Tell whoever runs IT, or if that is you, isolate every machine that shares a network or file share with the infected one.
- Photograph the ransom note and note the file extension the encrypted files now carry. Both identify the strain.
- Check whether backups are intact and disconnected. If backups are on the same network, take them offline now.
The next day
- Report to the national CERT and police before deciding anything about payment; in several countries they hold decryptors for known strains.
- Look up the strain on the No More Ransom project (nomoreransom.org), a police-run site that offers free decryptors where they exist.
- Rebuild from clean backups on freshly installed systems. Restoring onto the infected install brings the attacker back.
- Change every password that was used on the affected network, starting with administrator and remote-access accounts.
Keep this evidence
- The ransom note and one encrypted file, copied to a USB stick.
- Logs from the firewall, VPN and mail server for the previous 30 days.
- The list of what was encrypted and when it was first noticed.
Do not
- Do not pay before speaking to the CERT or police. Payment does not guarantee a working key, and it marks you as a payer.
- Do not run a decryptor from a random website.
- Do not wipe the machine before evidence is preserved.
Who to report to
National CERT first, then police. If personal data was taken, the data-protection regulator within 72 hours. Find the numbers and portals for your country in the reporting directory.
General guidance, not legal advice. If someone is in immediate danger, call your police emergency number.