Emergency IT guide

What to Do Immediately After a Ransomware Attack

The first hour matters. Avoid rushed cleanup, preserve evidence, and protect backups before recovery attempts.

1. Disconnect affected computers from the network

Unplug Ethernet cables and turn off Wi-Fi. Do not delete files or run random cleanup tools before the scope is understood.

2. Do not log into business accounts from infected machines

Email, banking, Microsoft 365, Google Workspace, and vendor portals should be accessed only from a known-clean device.

3. Protect backups before restoring anything

Backups can be encrypted too. Check backup dates and keep at least one copy isolated before reconnecting drives or cloud sync tools.

4. Photograph or save ransom notes and error messages

Those details can help identify the ransomware family and recovery options. They also help with insurance or incident records.

5. Change passwords from a clean device

Start with email, Microsoft or Google accounts, banking, remote access, and admin accounts. Add MFA where possible.

6. Get a recovery plan before wiping systems

Wiping too soon can destroy clues and recovery options. A technician should check drive health, infection scope, backups, and account exposure first.

Need ransomware triage in Northeast Houston?

Atascocita IT can help contain the spread, review backups, and plan clean recovery steps.

View ransomware help