Ransomware is malicious activity that can deny access to data or systems, often by encryption, and may include theft or threats to release information. A household might first notice a ransom note, changed file extensions, files that no longer open, unusual account alerts, unknown remote-control activity, or many devices behaving unexpectedly.

Those signs are not a do-it-yourself diagnosis. Hardware failure, ordinary corruption, account lockout, and other malware can look similar. The first objective is to limit additional damage without destroying evidence or contaminating recovery copies. This critical draft requires qualified cybersecurity review before publication.

A closed laptop on a desk beside a disconnected network cable and an external drive kept physically apart.
Ransomware finds every drive it can reach. The only backup that survives is the one that was unplugged when it hit.

If ransomware is suspected now

  1. Stop normal work. Do not keep opening files, entering credentials, synchronizing folders, or running backups from the affected device.
  2. Disconnect the suspected device from networks when this can be done safely: unplug Ethernet and disable Wi-Fi and Bluetooth. Do not start exploring other devices to see what the malware can reach.
  3. Leave backup media disconnected. Do not attach an external drive, phone, camera card, or archive to test whether files can be copied.
  4. Do not power-cycle reflexively. Whether to leave a device on or turn it off can affect containment and evidence. Ask qualified incident-response help, employer IT, insurer, or law enforcement when available.
  5. Use a separate known-clean device to contact help through verified channels.
  6. Notify the owner. Employer or school IT controls managed devices and accounts; do not attempt personal cleanup first.
  7. Protect money and identity. Contact affected financial institutions promptly and use IdentityTheft.gov if personal information was misused.
  8. Document what was observed. Record time, device, visible message, affected accounts, recent alerts, and actions already taken. Photograph a screen only if safe; do not click through it.
  9. Report appropriately. The FBI directs online scam and internet-crime victims to the real IC3 site. Manually enter the known .gov address; the FBI has warned about spoofed IC3 sites.

Call 911 for a physical threat, stalking, swatting threat, fire, medical emergency, or immediate danger. Digital extortion can overlap real-world risk.

Protect recovery options from the first hour

Keep the response on verified channels and preserve the evidence that qualified responders may need:

  • Do not pay or negotiate based on generic advice. Payment does not guarantee recovery and can create legal, financial, sanctions, safety, and repeat-targeting concerns.
  • Do not treat the phone number in a ransom note as support.
  • Do not install a “decryptor,” antivirus, cleanup tool, or remote-support application offered by an unsolicited message.
  • Do not delete the note, suspicious files, logs, user accounts, or applications before qualified guidance.
  • Do not change every password from the suspected device or restore a backup onto a system whose integrity is unknown.
  • Do not assume one unaffected-looking device or cloud folder is clean.
  • Do not publicly post the household’s evidence, identity records, or negotiation details.

Prepare before an incident

Maintain isolated, tested backups

NIST emphasizes secure, isolated backups and a tested restoration strategy. Use the 3-2-1 household backup guide to keep multiple copies, an off-site path, version history, and at least one copy that is not continuously writable from the primary device.

Record backup status and retention without exposing keys. Test low-risk restoration samples. A backup can preserve already encrypted files if the problem predates the backup; version history and identifying the last known good copy matter.

Harden ordinary access

  • Keep operating systems, browsers, applications, routers, and security tools supported and updated.
  • Use unique credentials in a reputable password manager.
  • Enable MFA, prioritizing email, backup, financial, remote-access, and administrator accounts.
  • Remove unused applications, accounts, browser extensions, and remote-access tools.
  • Use non-administrator accounts for ordinary work where practical.
  • Treat unexpected links, attachments, login prompts, invoices, delivery notices, and support calls as untrusted.
  • Keep device locks and official lost-device features configured.

Know what connects to what

Draw a simple household dependency map:

Asset Can reach Recovery owner Isolation action
primary computer cloud files, printer, backup service named adult disconnect network
external backup selected computer backup owner keep disconnected
phone email, MFA, photos, payment apps account holder carrier and platform plan
router all household devices household admin official reset and update plan
work device employer services employer IT notify; follow policy
smart device vendor cloud or local network owner vendor guidance

This is not a network-defense manual. It tells responders what may share a failure domain and who has authority.

Prepare clean contact paths

On paper or a separately controlled device, keep:

  • employer or school IT contact;
  • insurer incident number and policy reference;
  • bank and card fraud numbers from statements or official apps;
  • device and backup provider names;
  • local qualified IT or incident-response contact if preselected;
  • FBI/IC3 and IdentityTheft.gov reporting references;
  • household decision owner and communication lead.

Do not rely on search advertisements during an incident. Verify domains and phone numbers independently.

Triage impact without investigating the attacker

Help a professional scope the event by listing:

  • devices showing symptoms;
  • accounts reporting unknown access;
  • whether work, school, health, financial, or identity data was present;
  • backup locations and whether they were connected;
  • approximate first symptom and last known normal use;
  • recent unusual messages, downloads, software installs, or remote-support sessions;
  • whether the same credentials were reused elsewhere;
  • whether money or cryptocurrency moved;
  • whether a threat names the household or claims stolen data.

Do not hunt for malware, open samples, visit attacker sites, or search underground services. Those activities create additional risk and are outside household preparedness.

Recovery is a controlled rebuild

Qualified responders may need to preserve evidence, determine scope, identify a clean recovery point, rebuild or replace systems, reset accounts from clean devices, and validate restored data. The household’s role is to provide accurate inventory and avoid contaminating backups.

Before any restoration, confirm:

  1. who decided the device or environment is clean enough;
  2. which backup version is believed to predate the incident;
  3. whether the backup was isolated and scanned or validated appropriately;
  4. where recovery keys and installation media come from;
  5. which credentials must change and in what order;
  6. whether provider, employer, insurer, or law-enforcement requirements apply;
  7. how restored files will be checked before normal synchronization resumes.

After access is restored, secure primary email first, review recovery methods and sessions, replace exposed passwords with unique ones, re-enroll MFA, issue new backup codes, update systems, and monitor accounts. Follow the password recovery plan and offline credentials guide.

Include people, not just computers

Ransomware can interrupt income, school, medical records, assistive technology, communication, family photos, and household administration. Assign roles for contacting institutions, caring for dependents, preserving routine, and communicating without speculation. Do not shame the person who clicked or disclosed something; rapid, accurate reporting is more useful than blame.

Provide an offline path for critical care and communication records that does not require restoring the entire digital environment. The digital continuity hub helps prioritize those functions.

Keep public communication factual and limited. Do not repeat an attacker’s claims as confirmed facts, disclose whose personal data may be involved, or promise a restoration time before responders establish scope. One named household contact should update affected people through a channel that is not controlled by the suspected account.

Sources reviewed

  • CISA, FBI, NSA, and MS-ISAC: StopRansomware Guide
  • NIST: Data Integrity, Detecting and Responding to Ransomware and Other Destructive Events; Ransomware Tips and Tactics
  • FBI: Contact Us; Warning About Spoofed IC3 Websites
  • Federal Trade Commission: IdentityTheft.gov

Sources reviewed July 14, 2026. This page is not incident-response authorization. Current provider, employer, insurer, law-enforcement, legal, and qualified responder instructions control the actual incident.