What to Do in Case of a Cyberattack
Learn the immediate steps to contain a cyberattack, isolate affected systems, protect critical credentials, and report the incident safely.
Quick answer
5 steps — read this before anything else
-
1
Disconnect affected devices from Wi-Fi and Ethernet immediately.
-
2
Change passwords for critical accounts using a secure, uncompromised device.
-
3
Notify your IT security team or financial institutions right away.
-
4
Document the incident by capturing error messages, ransom notes, and timestamps.
-
5
Report the attack to official government cybersecurity agencies.
Experiencing a cyberattack, whether it involves ransomware, malware, phishing, or an unauthorized account takeover, requires swift action. Taking the correct initial steps can limit data loss, prevent the compromise from spreading across networks, and preserve evidence for recovery.
What to do first
- Disconnect from the network: Immediately turn off Wi-Fi and unplug Ethernet cables from any affected computer, server, or device. This prevents malware from spreading to other systems on the network or communicating with remote command servers.
- Isolate without powering down: Avoid shutting down or rebooting the device unless necessary, as volatile memory (RAM) contains critical forensic evidence. Simply disconnect network interfaces and keep the machine powered on.
- Change passwords from a safe device: Use a separate, uncompromised computer or phone to change passwords for your primary email, cloud services, and financial accounts. Enable multi-factor authentication (MFA) on all accounts.
- Notify key parties: If the incident occurs at work, notify your IT or cybersecurity department immediately. If personal banking details or identity information are involved, alert your financial institutions to freeze affected accounts or cards.
- Preserve evidence: Take photos or screenshots of ransomware notices, suspicious pop-up messages, phishing emails, or unexpected system logs. Note the exact date and time you noticed the activity.
What NOT to do
- Do not pay ransom demands right away: Paying a ransom does not guarantee data restoration and funds criminal activity. Consult law enforcement or security experts before considering any payment.
- Do not wipe systems prematurely: Deleting files or formatting drives destroys evidence needed by security responders to determine how the breach occurred.
- Do not use compromised devices: Avoid entering credentials, logging into personal accounts, or conducting financial transactions on any machine suspected of infection.
- Do not forward malicious emails: Forwarding phishing emails to colleagues can accidentally spread the threat within your organization.
When to report and seek assistance
For personal identity theft or financial loss, notify your local law enforcement and national reporting centers. In the United States, report incidents to the FBI Internet Crime Complaint Center (IC3) or the Cybersecurity and Infrastructure Security Agency (CISA). In the United Kingdom, submit a report to Action Fraud and the National Cyber Security Centre (NCSC). Businesses should engage professional incident response services to audit systems before bringing them back online.
How to recover and prevent future incidents
- Restore from verified backups: Rebuild infected systems using clean operating system images and restore data from backups created before the breach occurred.
- Patch all software: Ensure all operating systems, web browsers, and applications are updated with the latest security patches.
- Review account access: Audit account permissions, remove unrecognized user profiles, and revoke active login sessions across all services.
Taking prompt containment steps and securing your credentials helps minimize damage and ensures a safer recovery process.
Sources & references
Information verified with official organizations.
Spotted an error? Report it — we correct factual mistakes promptly.
Read next
What to Do If You Receive a Scam Email
Receiving a phishing or scam email can be alarming. Follow these immediate steps to secure your accounts, report the message, and protect your personal information.
What to Do in Case of a Website Hack
Learn how to quarantine your site, change credentials, clean malware, and restore your web application safely after a security breach.
What to Do in Case of a Server Outage
A practical step-by-step incident response guide for diagnosing, communicating, and resolving server outages quickly and safely.
What to Do if You Lose All Your Data
Discover immediate, safe steps to recover lost files and prevent permanent data loss across your devices and storage drives.