Emergency IT guide
What to Do Immediately After a Ransomware Attack
The first hour matters. Avoid rushed cleanup, preserve evidence, and protect backups before recovery attempts.
1. Disconnect affected computers from the network
Unplug Ethernet cables and turn off Wi-Fi. Do not delete files or run random cleanup tools before the scope is understood.
2. Do not log into business accounts from infected machines
Email, banking, Microsoft 365, Google Workspace, and vendor portals should be accessed only from a known-clean device.
3. Protect backups before restoring anything
Backups can be encrypted too. Check backup dates and keep at least one copy isolated before reconnecting drives or cloud sync tools.
4. Photograph or save ransom notes and error messages
Those details can help identify the ransomware family and recovery options. They also help with insurance or incident records.
5. Change passwords from a clean device
Start with email, Microsoft or Google accounts, banking, remote access, and admin accounts. Add MFA where possible.
6. Get a recovery plan before wiping systems
Wiping too soon can destroy clues and recovery options. A technician should check drive health, infection scope, backups, and account exposure first.
Need ransomware triage in Northeast Houston?
Atascocita IT can help contain the spread, review backups, and plan clean recovery steps.