# Hit by Ransomware? What to Do First URL: https://www.mytechnician.tech/tips/what-to-do-if-hit-by-ransomware/ Published: 2026-07-26 | Updated: 2026-08-07 | Author: Ankit Kumar Tags: Security, Data Recovery, Online Safety, Privacy, Files Summary: Files encrypted and a ransom note on screen? Isolate the PC, identify the strain, check for a free decryptor, and recover safely without paying — step by step. Recommended app: RecoverPro — https://www.mytechnician.tech/apps/data-recovery-pro/ (Microsoft Store: https://apps.microsoft.com/detail/9MZ613NS5TNN?hl=en-us&cid=mytechnician-web). Optional; every step below uses built-in Windows tools. ## The Problem Your files have new extensions you do not recognise, none of them open, and there is a text file or full-screen note demanding payment in cryptocurrency for a decryption key. The next hour matters. Ransomware often continues encrypting while you read the note, and it actively hunts **attached backup drives and mapped network shares**. The first job is not recovery — it is **stopping the spread**. > **Not sure it's ransomware?** Fake "your PC is infected, call this number" pop-ups are far more common and encrypt nothing. See [remove fake antivirus and scareware](https://www.mytechnician.tech/tips/remove-fake-antivirus-scareware-windows-11/) and [avoid tech support scam calls](https://www.mytechnician.tech/tips/avoid-tech-support-scam-calls/). ## Step 1: Disconnect Immediately Do this before anything else, including reading the ransom note properly. 1. **Unplug the Ethernet cable** and turn off Wi-Fi — use the physical switch or `Win + A` → Wi-Fi tile. 2. **Unplug every external drive and USB stick.** Backup drives connected during an attack get encrypted too. 3. Disconnect mapped network drives and NAS shares. 4. If several PCs share the network, **disconnect all of them** until you know how far it spread. 5. Do **not** shut down. Some strains hold keys in memory, and a running system also preserves evidence. Leave it on but isolated. ## Step 2: Photograph the Evidence 1. Take a phone photo of the ransom note and any on-screen message. 2. Note the **file extension** appended to your files — `.lockbit`, `.phobos`, `.mallox`, or similar. 3. Note the ransom note's filename, often `README.txt`, `HOW_TO_DECRYPT.hta`, or `RESTORE-FILES.txt`. 4. Record the date and time you first noticed it, and what you were doing beforehand. 5. Keep one encrypted sample file and the note — free decryptors need both to confirm the strain. ## Step 3: Do Not Pay 1. Payment is a gamble: a substantial share of victims who pay never receive a working key, and paying marks you as a target for repeat attacks. 2. Depending on the group behind the attack, payment may also be illegal under sanctions rules in your country. 3. There is usually a better route — Steps 4 to 7 — and it costs nothing to check first. ## Step 4: Identify the Strain 1. Visit **ID Ransomware** (id-ransomware.malwarehunterteam.com) from a **clean device**, such as your phone. 2. Upload the ransom note and one encrypted file. It identifies most known families. 3. Then check **No More Ransom** (nomoreransom.org), a project run by Europol and major security vendors. 4. If a free decryptor exists for your strain, it is listed there with instructions. This works more often than people expect. ## Step 5: Check for Recoverable Copies Some strains do a sloppy job of removing recovery points. 1. Right-click an affected folder → **Properties** → **Previous Versions**. If entries appear, restore from there. 2. Check whether **File History** or **Windows Backup** was running: [back up your PC with Windows Backup and File History](https://www.mytechnician.tech/tips/backup-pc-windows-backup-file-history/). 3. Check **OneDrive** on the web — it keeps version history for 30 days and has a **Files Restore** feature that rolls your whole drive back to a point before the encryption. 4. Check cloud folders from Google Drive or Dropbox the same way. Both keep prior versions. 5. Do not run recovery tools that write to the affected drive — see [how to recover deleted files](https://www.mytechnician.tech/tips/how-to-recover-deleted-files-windows/) for the safe method. ## Step 6: Image the Drive Before Cleaning Even with no decryptor today, one may be released later — several families have been broken months or years after the fact. 1. Remove the drive, or connect it to a clean PC through a USB enclosure **as a secondary drive** — never boot from it. 2. Copy the encrypted files onto a separate external drive and store it offline. 3. Label it clearly with the strain name and date. ## Step 7: Wipe and Rebuild the PC Assume the machine is fully compromised. "Removing" ransomware does not restore files and does not guarantee the attacker's access is gone. 1. Perform a **clean install**, deleting the existing partitions: [how to clean install Windows 11](https://www.mytechnician.tech/tips/how-to-clean-install-windows-11/). 2. Do not restore a full system image made after the infection date — it may contain the payload. 3. Restore **data files only**, from a backup you are confident predates the attack. 4. Scan restored files before opening them: [remove viruses and malware](https://www.mytechnician.tech/tips/remove-virus-malware-windows-11/). ## Step 8: Change Your Passwords from a Clean Device Most ransomware groups steal credentials before encrypting anything. 1. Using a **phone or another clean PC**, change the passwords for email, banking, and any account saved in your browser. 2. Start with email — it is the reset route for everything else: [recover a hacked email account](https://www.mytechnician.tech/tips/recover-hacked-email-account/). 3. Turn on two-factor authentication everywhere it is offered: [set up two-factor authentication](https://www.mytechnician.tech/tips/set-up-two-factor-authentication-2fa/). 4. Move to a proper vault so browser-stored passwords are not a single point of failure: [use a password manager safely](https://www.mytechnician.tech/tips/use-a-password-manager-safely/). ## Step 9: Report It 1. In the UK, report to **Action Fraud**; in the US, to the **FBI's IC3**; elsewhere, to your national cybercrime unit. 2. If personal data about other people was on the machine, you may have a legal duty to notify them or a regulator — particularly for a business. 3. Notify your bank if financial details were stored on the PC. 4. Reporting also feeds the intelligence that produces future free decryptors. ## Step 10: Close the Door Behind You 1. Set up backups that ransomware cannot reach — the rule is **three copies, two media types, one offline or immutable**: [set up automatic backups](https://www.mytechnician.tech/tips/set-up-automatic-backups/). 2. Keep one backup drive **physically disconnected** except while backing up. 3. Turn on **Controlled folder access**: **Windows Security** → **Virus & threat protection** → **Ransomware protection**. 4. Patch promptly: [keep your devices updated safely](https://www.mytechnician.tech/tips/keep-your-devices-updated-safely/). 5. Most infections arrive by email or a fake download: [spot and avoid phishing emails](https://www.mytechnician.tech/tips/spot-avoid-phishing-emails-scams/) and [avoid malware and fake downloads](https://www.mytechnician.tech/tips/avoid-malware-fake-downloads/). 6. Harden the network too: [secure your home Wi-Fi router](https://www.mytechnician.tech/tips/secure-your-home-wifi-router/). ## What Not to Do * **Don't pay before checking No More Ransom.** A free decryptor may already exist. * **Don't reconnect backup drives** to the infected PC to "check if they're okay". That is how the last clean copy gets encrypted. * **Don't rename or "repair" encrypted files.** It breaks decryptors that could otherwise work. * **Don't install random "ransomware removal" tools** found by searching the extension name. That search result page is itself targeted by attackers. * **Don't trust the attacker's countdown timer.** Pressure is the product; take the time to check your options. ## Still Not Working? If no decryptor exists and no backup predates the attack, keep the imaged drive offline and check No More Ransom every few months — families do get broken. Meanwhile rebuild and restore what you can from cloud version history and email attachments. Related: [enable BitLocker drive encryption](https://www.mytechnician.tech/tips/enable-bitlocker-drive-encryption-windows-11/), [organize and back up important documents](https://www.mytechnician.tech/tips/organize-and-back-up-important-documents/), and [fix Windows Defender not working](https://www.mytechnician.tech/tips/fix-windows-defender-not-working/). Once you are clean, close the door behind it: [enable Controlled Folder Access](https://www.mytechnician.tech/tips/enable-controlled-folder-access-ransomware-protection-windows-11/) so unknown apps cannot write to your documents, and [remove any rootkit or bootkit](https://www.mytechnician.tech/tips/remove-rootkit-bootkit-windows-11/) if the infection survives a scan. --- Source: https://www.mytechnician.tech/tips/what-to-do-if-hit-by-ransomware/ — My Technician, free Windows 10/11 troubleshooting guides. Related tool: RecoverPro (Windows data recovery software to recover deleted files, restore formatted drives, and rescue data from corrupted partitions on Windows 10 and 11.) — https://www.mytechnician.tech/apps/data-recovery-pro/ More guides: https://www.mytechnician.tech/llms.txt