Skip to content
?
Tech & Cybersecurity

What to Do If Your Computer Is Infected with Ransomware

If your device is infected with ransomware, swift action is crucial to contain the spread. Learn the immediate steps to isolate infected systems and mitigate damage.

2 min read • Written by Editorial Lead • Reviewed by Administrator • • • 13 reads

Quick answer

5 steps — read this before anything else

  1. 1

    Immediately disconnect the infected device from Wi-Fi, Ethernet, and Bluetooth networks.

  2. 2

    Do not pay the ransom, as payment does not guarantee file recovery and funds criminal activity.

  3. 3

    Take photos or screenshots of the ransom note and evidence for law enforcement.

  4. 4

    Report the incident to official cybersecurity agencies such as CISA or the FBI IC3.

  5. 5

    Wipe the system completely and restore files from a clean, isolated backup.

Ransomware is malicious software that encrypts files or locks users out of their devices, demanding a ransom payment to restore access. Acting quickly can prevent the infection from spreading across your local network or cloud storage services.

What to Do First

  1. Disconnect from all networks immediately: Unplug Ethernet cables and turn off Wi-Fi and Bluetooth on the infected device. This prevents the ransomware from moving laterally to other computers, shared network drives, or connected backups.
  2. Isolate the device's power state carefully: If encryption is actively occurring in real time, powering off the machine immediately may save some unencrypted files. However, if the encryption process is already complete, keep the device powered on but disconnected, as shutting down can erase volatile memory (RAM) evidence needed by cybersecurity experts.
  3. Document the ransom note: Take a clear photo of the ransom screen using a phone or external camera. Record any ransom notes, contact email addresses, bitcoin wallet addresses, or transaction IDs provided. This evidence is vital for law enforcement and forensic analysts.
  4. Report the incident to authorities: Contact relevant national cybersecurity organizations or law enforcement bodies. File a report with official authorities like the FBI Internet Crime Complaint Center (IC3) or the Cybersecurity and Infrastructure Security Agency (CISA).
  5. Check for official decryption tools: Visit legitimate, verified repositories such as No More Ransom from an uninfected device to check if a public decryption key exists for your specific ransomware strain.

What NOT to Do

  • Do not pay the ransom: Security experts and law enforcement strongly advise against paying. Payment does not guarantee you will get your decryption key, marks you as a target for future attacks, and directly finances cybercrime.
  • Do not connect clean backup drives: Connecting an external hard drive or USB key to an infected machine will likely result in your backups being encrypted as well.
  • Do not run unverified decryption software: Downloading fake decryptors from untrusted websites can introduce secondary malware infections or permanently corrupt your files.

How to Recover and Secure Your System

Once the threat is isolated, wipe the infected machine completely by performing a full drive format and reinstalling the operating system from official installation media. Restore your files using clean backups created prior to the infection. Before reconnecting to your local network, update all operating systems, software, and security definitions, and change all account passwords from a separate, secure device.

Sources & references

Information verified with official organizations.

Fact-checked: Yes

Spotted an error? Report it — we correct factual mistakes promptly.

Tech & Cybersecurity 3 min read

What to Do If Your Computer Crashes

Learn immediate troubleshooting steps to handle a computer crash safely, recover unsaved work, and resolve system freezes.

Read the guide
Tech & Cybersecurity 3 min read

What to Do in Case of a Cyberattack

Learn the immediate steps to contain a cyberattack, isolate affected systems, protect critical credentials, and report the incident safely.

Read the guide
Tech & Cybersecurity 3 min read

What to Do in Case of a Data Breach

Learn immediate steps to secure your accounts, protect your financial information, and prevent identity theft after your personal data has been exposed.

Read the guide
Tech & Cybersecurity 3 min read

What to Do in Case of Identity Theft

If your personal information has been compromised, quick action is essential. Learn how to freeze your credit, notify financial institutions, and report identity theft effectively.

Read the guide

Based on your reads

Recommended for you

Guides that match your recent interests.

Cookies & advertising

We use cookies to measure traffic and show personalized ads through Google AdSense. You can accept or decline. Learn more