What to Do If You Get Ransomware

A calm, step-by-step incident-response guide for suspected ransomware: validate, contain, avoid mistakes, report, identify, clean, recover, and finish the aftermath checklist.

Updated July 2026Reviewed by StaySecureHub Editorial TeamEditorial review

Why this matters

If you think ransomware has locked your files or device, you need immediate response steps—not a lesson on how ransomware works. Acting under pressure without a clear path can lead to unsafe choices such as paying, calling a fake support number, or downloading a random “unlock” tool.

What you should do

Use this guide as a step-by-step response path. Start by checking whether what you are seeing is really ransomware. Then follow the sections in order.

What you should avoid

  • Do not pay anyone yet.
  • Do not call a number shown on the screen.
  • Do not download a random decryptor or cleaner from search ads.
  • Do not leave this page to chase quick fixes before you validate and contain the problem.

What happens next

First, check whether this is really ransomware.

1. Is It Really Ransomware?

Not every scary screen is ransomware. Checking first can stop you from paying a scammer or taking the wrong cleanup steps.

Why this matters

If you treat a fake warning as ransomware, you may call a fraud number or pay for nothing. If you ignore real ransomware, the damage can keep spreading. A short check helps you choose the right path.

What you should do

Compare what you see with these common situations:

What you are seeingMore likely meaningWhat to do next
Many files renamed or unreadable, plus a note demanding paymentLikely encrypting ransomwareContinue this response guide
A full-screen browser warning telling you to call a number or pay for “support”Likely fake support scam or browser scare pageDo not call. Close the browser carefully. Do not pay. Then go to Section 6 for browser cleanup and scanning
A lock screen or pop-up with no clear mass file encryption and a pressure to call or payPossible locker or scarewareDo not call or pay. Contain the device, then verify whether files are actually encrypted
An official-looking recovery screen asking for a recovery key, without a criminal ransom notePossible BitLocker or other legitimate system recovery screenUse your official account or recovery-key process. Do not follow random pop-up phone numbers
Files missing or changed mainly in synced folders, with sync errors or a paused sync noticePossible cloud sync problemCheck the same files in the web version of OneDrive or Google Drive from another device if you can. Pause sync if ransomware also seems possible
Files unreadable with system errors, drive warnings, or no ransom notePossible storage corruption or disk failureStop using the drive. Do not follow ransomware payment logic. Seek hardware or data-recovery help if needed
Mixed signals and you cannot tellUncertainIf the device is still online and the message looks like a ransom demand, contain first, then reassess

Also ask one early question: is this a personal device, or a work/school managed device?

If it is a work or school device, preserve what you can see and contact IT or security promptly. Do not run random cleanup tools unless your organization tells you to.

What you should avoid

  • Do not call phone numbers shown on the warning screen.
  • Do not assume every lock screen means all of your files are encrypted forever.
  • Do not ignore a ransom note plus a sudden mass change to your files.
  • Do not stop here to read a long explanation of what ransomware is. You need the next action.

What happens next

If this still looks like ransomware, or you are unsure and the device is connected, contain the infection next.

If it clearly looks like a fake browser warning or support scam, do not enter the full ransomware payment path. Close the scare page carefully, avoid the phone number, and go to Section 6 for the browser-cleanup branch. If the device is still online, isolate it first using Section 2, then continue with Section 6.

2. Contain the Infection

Your first job is to stop the problem from spreading.

Why this matters

If the infected device stays online, ransomware may keep encrypting files or reach shared folders, external drives, or cloud sync. Containing the incident protects any copies that may still be recoverable.

What you should do

Work through these decisions in order.

1. Is this a personal device or a work/school device?

  • Work/school device: disconnect it from the network if you can, preserve the ransom note or screen details, and contact IT or security. Pause DIY cleanup unless they instruct you.
  • Personal device: continue with the steps below.

2. Is the computer or phone still connected to a network?

  • On a computer: turn off Wi-Fi and unplug the Ethernet cable.
  • On a phone or tablet: turn on Airplane Mode, or turn off Wi-Fi and mobile data.
  • Prefer disconnecting from the network over shutting the device down immediately, when that is possible.
  • If file names are still changing, isolate the device immediately.

3. Are backup drives or shared storage connected?

  • Unplug external hard drives and USB backups.
  • Disconnect from shared folders or network storage if you can do that safely.

4. Is cloud sync running?

  • Pause OneDrive, Google Drive, or similar sync tools if they are active.
  • This helps stop encrypted files from overwriting or syncing into the cloud.

5. Should you power the device off?

  • Power off only if you cannot disconnect it from the network another way.
  • CISA response guidance prefers network isolation first when possible, because shutting down can erase useful temporary evidence.

What you should avoid

  • Do not keep opening files “just to see what still works.”
  • Do not leave backup drives connected for convenience.
  • Do not restore files yet.
  • Do not download cleanup tools before the device is isolated.

What happens next

Once the device is isolated and backups or sync are protected, stop the high-cost mistakes attackers rely on.

3. Avoid Common Mistakes

Before you clean anything or try to recover files, make sure you do not create a second problem.

Why this matters

Ransom notes are designed to create panic. The most expensive mistakes often happen here: paying, calling fake support, deleting evidence, or wiping the device before you understand your options.

What you should do

DecisionAction
Are you being pressured to pay now?Do not pay.
Does the screen tell you to call a number?Do not call it.
Do you still have the ransom note and some encrypted files?Keep them for now.
Are you about to wipe the computer immediately?Pause until you assess recovery options.
Did you already pay?Contact your bank or card issuer through a trusted channel, then continue this guide.

Official guidance from the FBI, CISA, No More Ransom, and Microsoft advises against paying. Payment does not guarantee that you will get a working key, and it can encourage more attacks. Microsoft also advises contacting your bank and local authorities if you already paid.

If you already paid, you are not done. Contact your bank or card issuer, report the incident, and continue cleanup and recovery. Do not assume the decryptor will work or that the threat is over.

What you should avoid

  • Do not pay cryptocurrency or any other ransom demand.
  • Do not call “support” numbers from the screen.
  • Do not download random “free decryptors” from search ads.
  • Do not delete the ransom note yet.
  • Do not delete all encrypted files yet if you may need them for identification or a later decryptor.
  • Do not wipe the device before you understand whether a backup, cloud version history, or trusted decryptor may help.

What happens next

With payment and panic mistakes blocked, report the incident while evidence is still available.

4. Report the Incident

Reporting will not unlock your files by itself. It still matters.

Why this matters

A report creates an official record. It can support investigation and, in some cases, help you reach law-enforcement assistance about possible decryptor pathways. It does not replace cleanup or restore steps.

What you should do

Choose the path that matches your situation.

SituationWhere to report
Work or school device/accountReport to IT or security immediately, in addition to any external report they request
Personal incident in the United StatesReport through FBI IC3, CISA, or U.S. Secret Service channels as applicable. CISA notes that reporting once can notify partner agencies
You already paidStill report, and include payment details
Outside the United StatesUse your local cybercrime or consumer-protection authority. US portals are not universal

If you can, include these details in the report, as FBI IC3 requests for ransomware complaints:

  • ransomware name, if known;
  • encrypted file extension;
  • cryptocurrency type and wallet address;
  • attacker email addresses or websites/URLs;
  • ransom amount;
  • whether you paid, and how much.

Keep the ransom note and screenshots if they help you capture those details.

What you should avoid

  • Do not treat a report as proof that your files will be restored.
  • Do not discard the ransom note before reporting.
  • Do not assume one agency replaces your bank, card issuer, or employer IT team.
  • Do not present US reporting sites as the only valid option for every country.

What happens next

After reporting is handled, identify the ransomware family if trusted clues or tools can help later recovery choices.

5. Identify the Ransomware Variant

You do not need a perfect name before you clean the device. Identification still helps when a free decryptor exists.

Why this matters

Some ransomware families have free decryption tools released through trusted law-enforcement and security partnerships, including the No More Ransom project. Knowing the family can change your recovery path. Not knowing it does not stop you from cleaning the device or restoring from backup. CISA also notes that law enforcement may be able to advise on possible decryptors for some variants.

What you should do

  1. Gather clues from the ransom note, unusual file endings, attacker emails, payment URLs, and wallet addresses.
  2. Use a trusted identification path such as the No More Ransom project and its Crypto Sheriff tool.
  3. If a family is identified, keep that result for the recovery-options step later.
  4. If you cannot identify it, continue anyway. Preserve the clues.

Crypto Sheriff is a trusted helper for identification. It is not a magic unlock key.

What you should avoid

  • Do not upload sensitive disks or private data to unknown websites.
  • Do not trust random “free decryptor” ads from search results.
  • Do not stall the whole response waiting for a perfect identification.
  • Do not turn this step into a long study of ransomware families.

What happens next

Whether you identified the family or not, remove the malware or rebuild the system before you restore files.

6. Remove the Malware Safely

Cleanup and unlocking files are different jobs.

Why this matters

If you restore files onto a system that is still infected, those files can be encrypted again. Microsoft and Google both advise cleaning devices before restoring files. Security software may remove the ransomware program without restoring already encrypted files.

What you should do

Use the branch that matches your device.

PlatformFirst cleanup focus
Work/school deviceStop DIY and follow IT
Windows PCTrusted scan or offline scan; rebuild if trust is low
macOSTrusted scan; restore from clean backup only after cleanup
AndroidSafe Mode, remove suspicious apps, Play Protect
iPhone/iPadOfficial Apple account/settings path; no invented decryptor ritual
Browser scare pageClose carefully, remove extensions, reset browser if needed, then scan

If this is a work or school device

Stop DIY cleanup. Follow IT or security instructions.

If this is a personal Windows PC and you can still use it

  1. Keep the device isolated.
  2. Run a full scan with Windows Security or another trusted security tool you already trust.
  3. If the malware seems persistent, use a deeper option such as Microsoft Defender Offline when available.
  4. If you no longer trust the system, plan a clean reinstall or rebuild instead of stacking random tools.

If this is a personal Mac

  1. Keep the Mac disconnected from Wi-Fi and unplug external disks.
  2. Run a scan with a reputable macOS security tool you already trust, or follow Apple’s guidance for removing unwanted software.
  3. Do not download unverified “Mac cleaner” or “ransomware unlock” apps from search results.
  4. If you no longer trust the system, plan a clean reinstall.
  5. Restore files only from a clean backup, such as a Time Machine disk that was not connected during the attack, and only after cleanup.

If this is mainly a browser scare page

  1. Force-close the browser if needed.
  2. Remove suspicious extensions.
  3. Reset browser settings if the browser was hijacked.
  4. Still consider a device scan if you are unsure whether anything else changed.

If this is an Android phone or tablet

  1. Keep Airplane Mode on if the device is still locked or suspicious.
  2. Try Safe Mode.
  3. Remove unknown apps, especially apps with device-admin rights.
  4. Run Google Play Protect.
  5. Use a factory reset only as a last resort, and avoid restoring unknown apps or APK files afterward.

If this is an iPhone or iPad

  1. Do not follow on-screen payment or remote-support instructions.
  2. If Apple Account access or credentials are involved, use Apple’s official account recovery path.
  3. Review unknown apps or configuration profiles.
  4. Do not invent a system-wide “iPhone decryptor” process.

When cleanup is done, or when you have decided to rebuild, do not restore files yet.

What you should avoid

  • Do not expect antivirus alone to decrypt your files.
  • Do not download random cleanup tools from ads.
  • Do not restore backups yet.
  • Do not assume one scan proves every possible threat is gone in every case.
  • Do not treat iPhone scare screens as if they require desktop-style decryptor tools.
  • Do not use unverified Mac cleaner apps.

What happens next

With a clean or intentionally rebuilt system decided, assess which recovery option is realistic.

7. Assess Your Recovery Options

Choose one primary path. Do not try every idea at once.

Why this matters

Recovery options are not equal. CISA emphasizes offline backups as a core recovery path. Cloud version history can help after devices are clean, as Microsoft OneDrive and Google Drive document. Trusted decryptors help only for some families through projects such as No More Ransom. Paying is not a recovery method.

What you should do

Work down this ladder and stop at the first realistic option:

PriorityOptionChoose it when
1Restore from a trusted offline backupYou have a backup that was disconnected or otherwise protected from the attack
2Restore previous cloud versionsOneDrive, Google Drive, or a similar service still has older clean versions
3Use a trusted decryptorThe family is identified and a decryptor is available from No More Ransom or another known trusted source
4No reliable recovery right nowNone of the above is available

Also ask:

  • Did the attackers claim they stole a copy of your data?
  • If yes, file recovery can still proceed, but account and identity follow-up will still matter later.

Local Windows tools such as File History, shadow copies, or System Restore sometimes help, but many ransomware infections disable or delete them. Do not count on them as your main plan.

If no backup or trusted decryptor is available, keep the encrypted files for now. A decryptor may appear later for some families. Deeper edge cases belong in a dedicated file-recovery guide; this page’s job is to help you choose the safest path now.

What you should avoid

  • Do not treat payment as option five.
  • Do not rely on shadow copies as your primary strategy.
  • Do not restore while the system is still unclean.
  • Do not assume every cloud sync folder is a safe offline backup.
  • Do not trust unknown decryptor downloads.

What happens next

Execute only the path you chose, and only on a clean system.

8. Restore Safely

A correct path still fails if you restore onto an infected device.

Why this matters

Restoring too early can encrypt recovered files again. CISA recovery guidance stresses restoring onto cleaned systems and avoiding re-infection. Microsoft and Google likewise advise cleaning devices before restoring cloud files. Deleting encrypted copies too early can remove your last chance if the restore is incomplete.

What you should do

  1. Confirm the device is clean or rebuilt.
  2. Execute only the path you chose in the previous section.
  3. Verify that important restored files open correctly.
  4. Keep encrypted originals until that verification succeeds.
  5. If you used cloud restore, re-enable sync only after all devices used with that account are clean.

If your path is offline backup

Restore onto the clean system from the protected backup. Do not plug that backup into an infected machine first.

If your path is cloud version history

Use OneDrive or Google Drive restore/version tools after every related device is clean. Then check that the restored versions are usable before you rely on them.

If your path is a trusted decryptor

Use only the trusted tool for the identified family. Verify files. Keep encrypted copies until you are sure the decryptor worked.

If no recovery path exists right now

Rebuild the device so it is usable again, preserve encrypted files if storage allows, and move to the Recovery Roadmap so future backups are in place.

What you should avoid

  • Do not restore onto a still-infected system.
  • Do not delete encrypted originals before verification.
  • Do not mix in untrusted decryptor tools.
  • Do not assume the incident is fully over the moment files reopen.

What happens next

File or system restore is not the end of recovery. Continue with the Recovery Roadmap.

9. Recovery Roadmap

Restored files do not automatically mean your accounts, backups, and sign-in security are safe.

Why this matters

Ransomware response has two layers. The first layer stops the active incident. The second layer closes the gaps that can lead to fraud, account takeover, or another infection. If attackers also claim they stole data, that second layer matters even after files are restored.

What you should do

Work through this aftermath checklist in order.

Aftermath stageWhat to do
Regain account controlFrom a clean device, change passwords for email, banking, work, cloud, and other important accounts. Review recent sign-ins and remove unknown sessions.
Strengthen sign-inTurn on multifactor authentication (MFA), which means requiring a second proof of identity beyond the password. Prefer stronger options where available.
Rebuild backup postureMake sure you have at least one backup copy that is offline or disconnected when not in use.
Update softwareUpdate the operating system, browser, and apps. Remove tools you do not trust.
Monitor for follow-on harmWatch bank and account activity. If personal data may have been stolen, use official identity-theft resources for your country. For US readers, FTC IdentityTheft.gov and related credit freeze or fraud alert guidance may apply.
Understand the likely entry pathAt a shallow level only, note whether this likely started from a phishing message, a malicious download, exposed remote access, or weak backup exposure.
Reduce future riskAfter the crisis is stable, use supporting guides for deeper learning or tool decisions. Do not interrupt cleanup with shopping.

Useful next reads after the crisis is stable:

  • If a phishing click or fake login may have started this: What to Do If You Clicked a Phishing Link
  • For later learning about the threat itself: What Is Ransomware?
  • For how infections commonly start: How Ransomware Infects Your Computer
  • For deeper restore edge cases: Can You Recover Files After a Ransomware Attack?
  • For later protection shopping: The Best Ransomware Protection Software and Best Backup Software for Ransomware Recovery
  • For scanning and protection education: Is Free Antivirus Good Enough? and antivirus hub

This article remains the place to start during an active ransomware incident. Those supporting pages add depth after you are stable.

What you should avoid

  • Do not treat restored files as the finish line.
  • Do not skip password and MFA checks if credentials may have been exposed.
  • Do not leave your only backup connected full time.
  • Do not turn this roadmap into a long product comparison.
  • Do not delay basic hardening while researching ransomware history.

What happens next

If you still have edge questions, use the FAQ below. Then confirm any open steps you have not finished.

10. FAQ

How do I know if ransomware is real or a fake warning?

Look for mass file changes plus a ransom note. A browser page telling you to call a number is often a scare tactic. If you are unsure and the device is online, contain it first. See section 1.

Could BitLocker or a sync error look like ransomware?

Yes. A legitimate recovery-key screen is different from a criminal ransom note. Sync problems can also make files look missing or changed. Section 1 covers those lookalikes.

What should I do first if I get ransomware?

Isolate the device from the network, protect backups, pause sync, and do not pay. Then report, identify if possible, clean, and restore only after cleanup.

Should I turn off my computer if I get ransomware?

Disconnect from the network first if you can. Power off only if you cannot isolate the device another way.

Should I pay the ransom?

No. Official guidance advises against paying because payment does not guarantee recovery.

What if I already paid the ransom?

Contact your bank or card issuer, report the incident, and continue cleanup and recovery. Payment does not end the process.

What if this is my work computer?

Contact IT or security immediately. Preserve evidence. Do not run unsanctioned tools unless instructed.

Does antivirus decrypt ransomware files?

Usually no. Security software may remove the malware. Unlocking files usually requires backups or a trusted variant-specific decryptor.

Can I recover files without paying?

Sometimes yes, through offline backups, cloud version history, or a trusted decryptor. Sometimes no reliable recovery exists right now.

Should I delete encrypted files?

Not immediately. Keep them until you have verified a successful restore or confirmed that no trusted decryptor path remains useful.

What is No More Ransom?

It is a trusted public project that helps victims identify some ransomware families and find free decryptors when available. Not every family has a solution.

Will System Restore or File History get my files back?

Maybe, but many ransomware infections disable or delete those local recovery points. Do not rely on them as your main plan.

What if OneDrive or Google Drive was syncing?

Pause sync, clean every related device, then restore older versions if available.

What if attackers say they stole my data?

Continue cleanup and file recovery, then harden accounts and monitor for fraud. Stolen-data threats can remain even after files are restored.

Should I change my passwords after ransomware?

Yes for important accounts, especially if credentials may have been exposed. Change them from a clean device.

When is the incident actually over?

When the device is clean, recovery has been handled as far as possible, accounts are secured, backups are improved, and monitoring is in place. Restored files alone are not the full finish line.

Conclusion

If ransomware hits, the safest path is a sequence of decisions: validate what you are seeing, contain the damage, refuse payment and fake support, report the incident, identify the family if useful, clean before you restore, choose one realistic recovery path, restore carefully, then finish the aftermath checklist.

You do not need to solve every cybersecurity topic at once. You need the next correct decision.

If you are still in the crisis, return to the first unfinished step above. If your files are already restored, complete the Recovery Roadmap before you assume the incident is over.

This page is the immediate-response hub. Use supporting guides later for deeper learning, file-recovery edge cases, protection choices, and backup planning once you are stable.

Sources

Primary authorities and platform documentation supporting the material recommendations in this guide:

Official response and reporting

Platform recovery and cleanup

Vendor technical notes on cleanup-versus-decryption limits and shadow-copy unreliability informed recovery realism in this guide, but government and platform sources remain the primary authorities for response decisions.

Editorial Team at StaySecureHub

StaySecureHub's editorial team researches privacy, cybersecurity and digital safety topics to help readers make informed decisions.