RansomwareSecurity incident

Hit by Ransomware? Do Not Pay or Reinstall

6 min read

What separates ransomware from every other security incident is that it announces itself. A message appears saying your files are encrypted, you have a few days to pay, and after that they are gone. The countdown is deliberate. It exists so that you decide before you understand. This is about what can actually be done in those few days, and about the two decisions that feel most natural at the time and are regretted most afterwards: paying, and rushing to wipe the machine.

1. Establish whether anything is actually encrypted

Not every "your files are locked" screen is real. There is a category of scareware that does nothing but cover the screen with a window you cannot close. The files are untouched. It works because you are too alarmed to check. Telling them apart takes about five minutes and is worth doing first.

What you seeGenuinely encryptedOnly a scare
Do files still openNo, or the contents are garbageYes, everything is normal
File extensionsAn unfamiliar ending has been addedUnchanged
How the message arrivedText files appear inside your foldersOne full-screen window that will not close
After closing the windowFiles are still brokenNothing is wrong at all

To check, open something you use often and do not care about. A document full of garbage, an image that will not display: that is real. If everything opens normally, what you have is harassment rather than a disaster, and it is far easier to deal with.

2. The first hour: disconnect, then stop

Once you know it is real, unplug the network. That does two things: it cuts the path to shared drives, backup servers and colleagues' machines, and it breaks the connection to whoever is running this. The value of this step falls away by the minute, so the sooner it happens the more survives.

After that, do nothing. Do not delete the ransom note files, do not throw away the encrypted files, do not run a cleaner, and do not reinstall. Those files may be unreadable now and recoverable later, and a cleanup tool will wash away the evidence of which family this is.

If the company has more than one machine, the next thing to establish is scope. Who touched the same shared folder, who signed in with the same administrator account, whether the backup server sits on the same network. Ransomware rarely hits only one machine.

3. What can still be recovered

A hard fact first: modern ransomware uses standard encryption, and without the key it does not come open. There is no shortcut. So recovery is not about breaking anything. It is about finding a copy that was not reached. In rough order of how often it works:

Work down in this order

  • An offline backup. The copy that was not on the same network. An external drive normally left unplugged, or cloud storage with version history, usually survives. This is the only reliable answer.
  • Version history in cloud storage. A syncing folder will happily upload the encrypted files, but most services keep older versions for a while, so files can be rolled back to before it happened.
  • System restore points or shadow copies. Ransomware usually deletes these first, but not every family does it thoroughly, and it costs nothing to look.
  • A free public decryptor. For some families the keys have been seized by law enforcement or broken by researchers. No More Ransom, run by Europol together with security companies, exists for exactly this: upload a sample and it will tell you whether a decryptor exists.
  • Nothing at all. Then be honest about it: this data is gone. What matters from here is stopping the spread and rebuilding, not hunting for a miracle.

The fourth item deserves a note. It is not a cure. Only a minority of families are covered, and you need to know which one you have. But it is free and takes minutes, and it is absolutely worth checking before you consider paying anything.

4. Whether to pay

Law enforcement and the security industry agree on the advice: do not pay. Saying only that, without the reasoning, persuades nobody whose company is currently stopped, so here is the reasoning.

First, paying does not guarantee a key. There is nothing holding them to the deal, and some ransomware is written badly enough that even a genuine key will not restore everything. Second, paying marks you as an organisation that pays. The same people, or others who bought the list, coming back a few months later is common. Third, the money funds an entire industry, and the next company on its list may be your client.

5. Reporting it, and notifying

Reporting a crime and notifying a regulator are different things and often get merged into one. Reporting goes to the police and concerns a criminal act. Notification goes to a data protection authority and concerns your responsibility for other people's information. You may need both, or only one.

On reporting: ransomware is a criminal matter and can be reported to the police where you are. In practice do not expect it to bring the files back. Its value is a formal record, which matters for an insurance claim, for explaining yourself to clients, and if the same group is caught later.

On notification: it depends on whether that machine held personal data belonging to customers or staff. If it did, this is not only your loss. In Taiwan the Personal Data Protection Act governs this, and the amended version tightens both the threshold and the deadline. Elsewhere the shape is similar but the specifics are not, so check what applies where you operate. The point that transfers everywhere: the clock starts when you become aware, not when you finish investigating.

6. Rebuild, then close the way in

Rebuild in this order: establish a clean environment first, restore data second. Putting a backup straight back onto an infected machine starts the whole thing again. Before either, answer one question: how did it get in? The answer is usually one of a few. Somebody opened an attachment, a machine had remote desktop exposed with a weak password, or a public-facing service had gone a long time without updates.

Once the entry point is known, what genuinely lowers the risk next time is the backup strategy, not another antivirus subscription. Antivirus matches known samples, and ransomware families are updated faster than almost anything else. A reliable backup does not have to guess what technique will be used. It only has to exist, and not be on the same network.

Testing the backup is the step most often skipped. The difference between a backup nobody has ever restored and no backup at all only becomes visible on the day it matters. Actually restoring one every so often is the highest-return half hour in this entire subject.

The countdown exists to make you decide in a hurry, and the two most expensive decisions both feel obvious at the time: pay, or wipe the machine clean. Either one removes your options. The order that works is disconnect, stop, establish scope, find out what copies exist, and only then rebuild. As for whether the files come back, that was settled before any of this happened, by whether you kept a backup somewhere offline.

Common questions

If I pay, will I actually get a working key?
Not necessarily. Nothing holds them to the deal, and some ransomware is written badly enough that a genuine key will not restore everything. Paying also marks you as an organisation that pays, and repeat visits are common. Law enforcement and the security industry advise against it. If you have no backup at all and being stopped costs far more than the demand, that becomes a commercial judgement, but go into it knowing the risk.
Will reinstalling bring my files back?
No. Reinstalling cleans the system; it does not decrypt anything. It also destroys the evidence of which family you were hit by, so if a free decryptor exists for it you will no longer be able to use it. The right order is to keep the encrypted files and the ransom notes, work out what usable copies exist, and only then talk about rebuilding.
Antivirus did not stop it. Did I buy the wrong one?
Not necessarily. Antivirus matches known sample signatures, and ransomware variants are updated extremely fast, so a new variant simply is not blocked until it has been catalogued. That does not make antivirus useless, but it cannot be the only line. What decides how much you lose is whether a backup exists offline, and that does not depend on guessing the technique.

Read next