What should you do if you suspect a ransomware attack?

A ransom note appearing, or many files stopping at the same time, calls for handling the case in an organised way. If the devices belong to a business, involve the IT lead before making changes to servers or storage.

Start by protecting what has not been affected

Isolate the suspected devices from the network if possible, and use a clean device to get in touch. Keep healthy backups separate from the damaged environment.

Keep a clear description of what happened

Write down when the problem was discovered, which services stopped, which devices were affected, and any actions taken afterwards. Keep the ransom note and the logs unmodified, and leave collecting technical samples to the responsible team when you are not sure how to handle them.

Reduce unnecessary changes

Do not start formatting devices, deleting case files or trying unknown tools on the source. Do not publish the ransom note or company data on public websites to ask for a diagnosis.

Prepare this information before getting in touch

  • The type of affected device or system.
  • The approximate time the problem was discovered.
  • Has work stopped completely or partially?
  • Are there any known backups?
  • Which data do you need first?

FAQ

No. The form sends a contact and assessment request; dealing with an active incident needs a team responsible for response inside the organisation, or a specialist body.

Call about an urgent case

Contact hours: Sat — Thu · 10:00 AM — 10:00 PM · +966 53 101 0903

Send a case description

Need help arranging the next step?