What to Do If You Get Ransomware
A calm, step-by-step incident-response guide for suspected ransomware: validate, contain, avoid mistakes, report, identify, clean, recover, and finish the aftermath checklist.
Updated July 2026Reviewed by StaySecureHub Editorial TeamEditorial review
Why this matters
If you think ransomware has locked your files or device, you need immediate response steps—not a lesson on how ransomware works. Acting under pressure without a clear path can lead to unsafe choices such as paying, calling a fake support number, or downloading a random “unlock” tool.
What you should do
Use this guide as a step-by-step response path. Start by checking whether what you are seeing is really ransomware. Then follow the sections in order.
What you should avoid
- Do not pay anyone yet.
- Do not call a number shown on the screen.
- Do not download a random decryptor or cleaner from search ads.
- Do not leave this page to chase quick fixes before you validate and contain the problem.
What happens next
First, check whether this is really ransomware.
1. Is It Really Ransomware?
Not every scary screen is ransomware. Checking first can stop you from paying a scammer or taking the wrong cleanup steps.
Why this matters
If you treat a fake warning as ransomware, you may call a fraud number or pay for nothing. If you ignore real ransomware, the damage can keep spreading. A short check helps you choose the right path.
What you should do
Compare what you see with these common situations:
| What you are seeing | More likely meaning | What to do next |
|---|---|---|
| Many files renamed or unreadable, plus a note demanding payment | Likely encrypting ransomware | Continue this response guide |
| A full-screen browser warning telling you to call a number or pay for “support” | Likely fake support scam or browser scare page | Do not call. Close the browser carefully. Do not pay. Then go to Section 6 for browser cleanup and scanning |
| A lock screen or pop-up with no clear mass file encryption and a pressure to call or pay | Possible locker or scareware | Do not call or pay. Contain the device, then verify whether files are actually encrypted |
| An official-looking recovery screen asking for a recovery key, without a criminal ransom note | Possible BitLocker or other legitimate system recovery screen | Use your official account or recovery-key process. Do not follow random pop-up phone numbers |
| Files missing or changed mainly in synced folders, with sync errors or a paused sync notice | Possible cloud sync problem | Check the same files in the web version of OneDrive or Google Drive from another device if you can. Pause sync if ransomware also seems possible |
| Files unreadable with system errors, drive warnings, or no ransom note | Possible storage corruption or disk failure | Stop using the drive. Do not follow ransomware payment logic. Seek hardware or data-recovery help if needed |
| Mixed signals and you cannot tell | Uncertain | If the device is still online and the message looks like a ransom demand, contain first, then reassess |
Also ask one early question: is this a personal device, or a work/school managed device?
If it is a work or school device, preserve what you can see and contact IT or security promptly. Do not run random cleanup tools unless your organization tells you to.
What you should avoid
- Do not call phone numbers shown on the warning screen.
- Do not assume every lock screen means all of your files are encrypted forever.
- Do not ignore a ransom note plus a sudden mass change to your files.
- Do not stop here to read a long explanation of what ransomware is. You need the next action.
What happens next
If this still looks like ransomware, or you are unsure and the device is connected, contain the infection next.
If it clearly looks like a fake browser warning or support scam, do not enter the full ransomware payment path. Close the scare page carefully, avoid the phone number, and go to Section 6 for the browser-cleanup branch. If the device is still online, isolate it first using Section 2, then continue with Section 6.
2. Contain the Infection
Your first job is to stop the problem from spreading.
Why this matters
If the infected device stays online, ransomware may keep encrypting files or reach shared folders, external drives, or cloud sync. Containing the incident protects any copies that may still be recoverable.
What you should do
Work through these decisions in order.
1. Is this a personal device or a work/school device?
- Work/school device: disconnect it from the network if you can, preserve the ransom note or screen details, and contact IT or security. Pause DIY cleanup unless they instruct you.
- Personal device: continue with the steps below.
2. Is the computer or phone still connected to a network?
- On a computer: turn off Wi-Fi and unplug the Ethernet cable.
- On a phone or tablet: turn on Airplane Mode, or turn off Wi-Fi and mobile data.
- Prefer disconnecting from the network over shutting the device down immediately, when that is possible.
- If file names are still changing, isolate the device immediately.
3. Are backup drives or shared storage connected?
- Unplug external hard drives and USB backups.
- Disconnect from shared folders or network storage if you can do that safely.
4. Is cloud sync running?
- Pause OneDrive, Google Drive, or similar sync tools if they are active.
- This helps stop encrypted files from overwriting or syncing into the cloud.
5. Should you power the device off?
- Power off only if you cannot disconnect it from the network another way.
- CISA response guidance prefers network isolation first when possible, because shutting down can erase useful temporary evidence.
What you should avoid
- Do not keep opening files “just to see what still works.”
- Do not leave backup drives connected for convenience.
- Do not restore files yet.
- Do not download cleanup tools before the device is isolated.
What happens next
Once the device is isolated and backups or sync are protected, stop the high-cost mistakes attackers rely on.
3. Avoid Common Mistakes
Before you clean anything or try to recover files, make sure you do not create a second problem.
Why this matters
Ransom notes are designed to create panic. The most expensive mistakes often happen here: paying, calling fake support, deleting evidence, or wiping the device before you understand your options.
What you should do
| Decision | Action |
|---|---|
| Are you being pressured to pay now? | Do not pay. |
| Does the screen tell you to call a number? | Do not call it. |
| Do you still have the ransom note and some encrypted files? | Keep them for now. |
| Are you about to wipe the computer immediately? | Pause until you assess recovery options. |
| Did you already pay? | Contact your bank or card issuer through a trusted channel, then continue this guide. |
Official guidance from the FBI, CISA, No More Ransom, and Microsoft advises against paying. Payment does not guarantee that you will get a working key, and it can encourage more attacks. Microsoft also advises contacting your bank and local authorities if you already paid.
If you already paid, you are not done. Contact your bank or card issuer, report the incident, and continue cleanup and recovery. Do not assume the decryptor will work or that the threat is over.
What you should avoid
- Do not pay cryptocurrency or any other ransom demand.
- Do not call “support” numbers from the screen.
- Do not download random “free decryptors” from search ads.
- Do not delete the ransom note yet.
- Do not delete all encrypted files yet if you may need them for identification or a later decryptor.
- Do not wipe the device before you understand whether a backup, cloud version history, or trusted decryptor may help.
What happens next
With payment and panic mistakes blocked, report the incident while evidence is still available.
4. Report the Incident
Reporting will not unlock your files by itself. It still matters.
Why this matters
A report creates an official record. It can support investigation and, in some cases, help you reach law-enforcement assistance about possible decryptor pathways. It does not replace cleanup or restore steps.
What you should do
Choose the path that matches your situation.
| Situation | Where to report |
|---|---|
| Work or school device/account | Report to IT or security immediately, in addition to any external report they request |
| Personal incident in the United States | Report through FBI IC3, CISA, or U.S. Secret Service channels as applicable. CISA notes that reporting once can notify partner agencies |
| You already paid | Still report, and include payment details |
| Outside the United States | Use your local cybercrime or consumer-protection authority. US portals are not universal |
If you can, include these details in the report, as FBI IC3 requests for ransomware complaints:
- ransomware name, if known;
- encrypted file extension;
- cryptocurrency type and wallet address;
- attacker email addresses or websites/URLs;
- ransom amount;
- whether you paid, and how much.
Keep the ransom note and screenshots if they help you capture those details.
What you should avoid
- Do not treat a report as proof that your files will be restored.
- Do not discard the ransom note before reporting.
- Do not assume one agency replaces your bank, card issuer, or employer IT team.
- Do not present US reporting sites as the only valid option for every country.
What happens next
After reporting is handled, identify the ransomware family if trusted clues or tools can help later recovery choices.
5. Identify the Ransomware Variant
You do not need a perfect name before you clean the device. Identification still helps when a free decryptor exists.
Why this matters
Some ransomware families have free decryption tools released through trusted law-enforcement and security partnerships, including the No More Ransom project. Knowing the family can change your recovery path. Not knowing it does not stop you from cleaning the device or restoring from backup. CISA also notes that law enforcement may be able to advise on possible decryptors for some variants.
What you should do
- Gather clues from the ransom note, unusual file endings, attacker emails, payment URLs, and wallet addresses.
- Use a trusted identification path such as the No More Ransom project and its Crypto Sheriff tool.
- If a family is identified, keep that result for the recovery-options step later.
- If you cannot identify it, continue anyway. Preserve the clues.
Crypto Sheriff is a trusted helper for identification. It is not a magic unlock key.
What you should avoid
- Do not upload sensitive disks or private data to unknown websites.
- Do not trust random “free decryptor” ads from search results.
- Do not stall the whole response waiting for a perfect identification.
- Do not turn this step into a long study of ransomware families.
What happens next
Whether you identified the family or not, remove the malware or rebuild the system before you restore files.
6. Remove the Malware Safely
Cleanup and unlocking files are different jobs.
Why this matters
If you restore files onto a system that is still infected, those files can be encrypted again. Microsoft and Google both advise cleaning devices before restoring files. Security software may remove the ransomware program without restoring already encrypted files.
What you should do
Use the branch that matches your device.
| Platform | First cleanup focus |
|---|---|
| Work/school device | Stop DIY and follow IT |
| Windows PC | Trusted scan or offline scan; rebuild if trust is low |
| macOS | Trusted scan; restore from clean backup only after cleanup |
| Android | Safe Mode, remove suspicious apps, Play Protect |
| iPhone/iPad | Official Apple account/settings path; no invented decryptor ritual |
| Browser scare page | Close carefully, remove extensions, reset browser if needed, then scan |
If this is a work or school device
Stop DIY cleanup. Follow IT or security instructions.
If this is a personal Windows PC and you can still use it
- Keep the device isolated.
- Run a full scan with Windows Security or another trusted security tool you already trust.
- If the malware seems persistent, use a deeper option such as Microsoft Defender Offline when available.
- If you no longer trust the system, plan a clean reinstall or rebuild instead of stacking random tools.
If this is a personal Mac
- Keep the Mac disconnected from Wi-Fi and unplug external disks.
- Run a scan with a reputable macOS security tool you already trust, or follow Apple’s guidance for removing unwanted software.
- Do not download unverified “Mac cleaner” or “ransomware unlock” apps from search results.
- If you no longer trust the system, plan a clean reinstall.
- Restore files only from a clean backup, such as a Time Machine disk that was not connected during the attack, and only after cleanup.
If this is mainly a browser scare page
- Force-close the browser if needed.
- Remove suspicious extensions.
- Reset browser settings if the browser was hijacked.
- Still consider a device scan if you are unsure whether anything else changed.
If this is an Android phone or tablet
- Keep Airplane Mode on if the device is still locked or suspicious.
- Try Safe Mode.
- Remove unknown apps, especially apps with device-admin rights.
- Run Google Play Protect.
- Use a factory reset only as a last resort, and avoid restoring unknown apps or APK files afterward.
If this is an iPhone or iPad
- Do not follow on-screen payment or remote-support instructions.
- If Apple Account access or credentials are involved, use Apple’s official account recovery path.
- Review unknown apps or configuration profiles.
- Do not invent a system-wide “iPhone decryptor” process.
When cleanup is done, or when you have decided to rebuild, do not restore files yet.
What you should avoid
- Do not expect antivirus alone to decrypt your files.
- Do not download random cleanup tools from ads.
- Do not restore backups yet.
- Do not assume one scan proves every possible threat is gone in every case.
- Do not treat iPhone scare screens as if they require desktop-style decryptor tools.
- Do not use unverified Mac cleaner apps.
What happens next
With a clean or intentionally rebuilt system decided, assess which recovery option is realistic.
7. Assess Your Recovery Options
Choose one primary path. Do not try every idea at once.
Why this matters
Recovery options are not equal. CISA emphasizes offline backups as a core recovery path. Cloud version history can help after devices are clean, as Microsoft OneDrive and Google Drive document. Trusted decryptors help only for some families through projects such as No More Ransom. Paying is not a recovery method.
What you should do
Work down this ladder and stop at the first realistic option:
| Priority | Option | Choose it when |
|---|---|---|
| 1 | Restore from a trusted offline backup | You have a backup that was disconnected or otherwise protected from the attack |
| 2 | Restore previous cloud versions | OneDrive, Google Drive, or a similar service still has older clean versions |
| 3 | Use a trusted decryptor | The family is identified and a decryptor is available from No More Ransom or another known trusted source |
| 4 | No reliable recovery right now | None of the above is available |
Also ask:
- Did the attackers claim they stole a copy of your data?
- If yes, file recovery can still proceed, but account and identity follow-up will still matter later.
Local Windows tools such as File History, shadow copies, or System Restore sometimes help, but many ransomware infections disable or delete them. Do not count on them as your main plan.
If no backup or trusted decryptor is available, keep the encrypted files for now. A decryptor may appear later for some families. Deeper edge cases belong in a dedicated file-recovery guide; this page’s job is to help you choose the safest path now.
What you should avoid
- Do not treat payment as option five.
- Do not rely on shadow copies as your primary strategy.
- Do not restore while the system is still unclean.
- Do not assume every cloud sync folder is a safe offline backup.
- Do not trust unknown decryptor downloads.
What happens next
Execute only the path you chose, and only on a clean system.
8. Restore Safely
A correct path still fails if you restore onto an infected device.
Why this matters
Restoring too early can encrypt recovered files again. CISA recovery guidance stresses restoring onto cleaned systems and avoiding re-infection. Microsoft and Google likewise advise cleaning devices before restoring cloud files. Deleting encrypted copies too early can remove your last chance if the restore is incomplete.
What you should do
- Confirm the device is clean or rebuilt.
- Execute only the path you chose in the previous section.
- Verify that important restored files open correctly.
- Keep encrypted originals until that verification succeeds.
- If you used cloud restore, re-enable sync only after all devices used with that account are clean.
If your path is offline backup
Restore onto the clean system from the protected backup. Do not plug that backup into an infected machine first.
If your path is cloud version history
Use OneDrive or Google Drive restore/version tools after every related device is clean. Then check that the restored versions are usable before you rely on them.
If your path is a trusted decryptor
Use only the trusted tool for the identified family. Verify files. Keep encrypted copies until you are sure the decryptor worked.
If no recovery path exists right now
Rebuild the device so it is usable again, preserve encrypted files if storage allows, and move to the Recovery Roadmap so future backups are in place.
What you should avoid
- Do not restore onto a still-infected system.
- Do not delete encrypted originals before verification.
- Do not mix in untrusted decryptor tools.
- Do not assume the incident is fully over the moment files reopen.
What happens next
File or system restore is not the end of recovery. Continue with the Recovery Roadmap.
9. Recovery Roadmap
Restored files do not automatically mean your accounts, backups, and sign-in security are safe.
Why this matters
Ransomware response has two layers. The first layer stops the active incident. The second layer closes the gaps that can lead to fraud, account takeover, or another infection. If attackers also claim they stole data, that second layer matters even after files are restored.
What you should do
Work through this aftermath checklist in order.
| Aftermath stage | What to do |
|---|---|
| Regain account control | From a clean device, change passwords for email, banking, work, cloud, and other important accounts. Review recent sign-ins and remove unknown sessions. |
| Strengthen sign-in | Turn on multifactor authentication (MFA), which means requiring a second proof of identity beyond the password. Prefer stronger options where available. |
| Rebuild backup posture | Make sure you have at least one backup copy that is offline or disconnected when not in use. |
| Update software | Update the operating system, browser, and apps. Remove tools you do not trust. |
| Monitor for follow-on harm | Watch bank and account activity. If personal data may have been stolen, use official identity-theft resources for your country. For US readers, FTC IdentityTheft.gov and related credit freeze or fraud alert guidance may apply. |
| Understand the likely entry path | At a shallow level only, note whether this likely started from a phishing message, a malicious download, exposed remote access, or weak backup exposure. |
| Reduce future risk | After the crisis is stable, use supporting guides for deeper learning or tool decisions. Do not interrupt cleanup with shopping. |
Useful next reads after the crisis is stable:
- If a phishing click or fake login may have started this: What to Do If You Clicked a Phishing Link
- For later learning about the threat itself: What Is Ransomware?
- For how infections commonly start: How Ransomware Infects Your Computer
- For deeper restore edge cases: Can You Recover Files After a Ransomware Attack?
- For later protection shopping: The Best Ransomware Protection Software and Best Backup Software for Ransomware Recovery
- For scanning and protection education: Is Free Antivirus Good Enough? and antivirus hub
This article remains the place to start during an active ransomware incident. Those supporting pages add depth after you are stable.
What you should avoid
- Do not treat restored files as the finish line.
- Do not skip password and MFA checks if credentials may have been exposed.
- Do not leave your only backup connected full time.
- Do not turn this roadmap into a long product comparison.
- Do not delay basic hardening while researching ransomware history.
What happens next
If you still have edge questions, use the FAQ below. Then confirm any open steps you have not finished.
10. FAQ
How do I know if ransomware is real or a fake warning?
Look for mass file changes plus a ransom note. A browser page telling you to call a number is often a scare tactic. If you are unsure and the device is online, contain it first. See section 1.
Could BitLocker or a sync error look like ransomware?
Yes. A legitimate recovery-key screen is different from a criminal ransom note. Sync problems can also make files look missing or changed. Section 1 covers those lookalikes.
What should I do first if I get ransomware?
Isolate the device from the network, protect backups, pause sync, and do not pay. Then report, identify if possible, clean, and restore only after cleanup.
Should I turn off my computer if I get ransomware?
Disconnect from the network first if you can. Power off only if you cannot isolate the device another way.
Should I pay the ransom?
No. Official guidance advises against paying because payment does not guarantee recovery.
What if I already paid the ransom?
Contact your bank or card issuer, report the incident, and continue cleanup and recovery. Payment does not end the process.
What if this is my work computer?
Contact IT or security immediately. Preserve evidence. Do not run unsanctioned tools unless instructed.
Does antivirus decrypt ransomware files?
Usually no. Security software may remove the malware. Unlocking files usually requires backups or a trusted variant-specific decryptor.
Can I recover files without paying?
Sometimes yes, through offline backups, cloud version history, or a trusted decryptor. Sometimes no reliable recovery exists right now.
Should I delete encrypted files?
Not immediately. Keep them until you have verified a successful restore or confirmed that no trusted decryptor path remains useful.
What is No More Ransom?
It is a trusted public project that helps victims identify some ransomware families and find free decryptors when available. Not every family has a solution.
Will System Restore or File History get my files back?
Maybe, but many ransomware infections disable or delete those local recovery points. Do not rely on them as your main plan.
What if OneDrive or Google Drive was syncing?
Pause sync, clean every related device, then restore older versions if available.
What if attackers say they stole my data?
Continue cleanup and file recovery, then harden accounts and monitor for fraud. Stolen-data threats can remain even after files are restored.
Should I change my passwords after ransomware?
Yes for important accounts, especially if credentials may have been exposed. Change them from a clean device.
When is the incident actually over?
When the device is clean, recovery has been handled as far as possible, accounts are secured, backups are improved, and monitoring is in place. Restored files alone are not the full finish line.
Conclusion
If ransomware hits, the safest path is a sequence of decisions: validate what you are seeing, contain the damage, refuse payment and fake support, report the incident, identify the family if useful, clean before you restore, choose one realistic recovery path, restore carefully, then finish the aftermath checklist.
You do not need to solve every cybersecurity topic at once. You need the next correct decision.
If you are still in the crisis, return to the first unfinished step above. If your files are already restored, complete the Recovery Roadmap before you assume the incident is over.
This page is the immediate-response hub. Use supporting guides later for deeper learning, file-recovery edge cases, protection choices, and backup planning once you are stable.
Sources
Primary authorities and platform documentation supporting the material recommendations in this guide:
Official response and reporting
- CISA — I've Been Hit By Ransomware!
- CISA — #StopRansomware Guide
- CISA — Report Ransomware
- FBI IC3 — Ransomware
- FBI IC3 complaint portal
- No More Ransom
- No More Ransom — Decryption tools
- FTC — Ransomware guidance for small businesses
- FTC IdentityTheft.gov
- FTC — Credit Freezes and Fraud Alerts
Platform recovery and cleanup
- Microsoft — Protect your PC from ransomware
- Microsoft — Ransomware detection and recovering your files (OneDrive)
- Microsoft Defender Offline
- Google Drive — Restore files affected by harmful software
- Google Drive — Restore files in bulk / ransomware recovery
- Google Play Protect
- Google Chrome — Remove unwanted ads, pop-ups & malware
- Apple — If you think your Apple Account has been compromised
- Apple — Recognize and avoid social engineering schemes
Vendor technical notes on cleanup-versus-decryption limits and shadow-copy unreliability informed recovery realism in this guide, but government and platform sources remain the primary authorities for response decisions.