What to Do If Your Computer Is Infected with Ransomware
If your device is infected with ransomware, swift action is crucial to contain the spread. Learn the immediate steps to isolate infected systems and mitigate damage.
Quick answer
5 steps — read this before anything else
-
1
Immediately disconnect the infected device from Wi-Fi, Ethernet, and Bluetooth networks.
-
2
Do not pay the ransom, as payment does not guarantee file recovery and funds criminal activity.
-
3
Take photos or screenshots of the ransom note and evidence for law enforcement.
-
4
Report the incident to official cybersecurity agencies such as CISA or the FBI IC3.
-
5
Wipe the system completely and restore files from a clean, isolated backup.
Ransomware is malicious software that encrypts files or locks users out of their devices, demanding a ransom payment to restore access. Acting quickly can prevent the infection from spreading across your local network or cloud storage services.
What to Do First
- Disconnect from all networks immediately: Unplug Ethernet cables and turn off Wi-Fi and Bluetooth on the infected device. This prevents the ransomware from moving laterally to other computers, shared network drives, or connected backups.
- Isolate the device's power state carefully: If encryption is actively occurring in real time, powering off the machine immediately may save some unencrypted files. However, if the encryption process is already complete, keep the device powered on but disconnected, as shutting down can erase volatile memory (RAM) evidence needed by cybersecurity experts.
- Document the ransom note: Take a clear photo of the ransom screen using a phone or external camera. Record any ransom notes, contact email addresses, bitcoin wallet addresses, or transaction IDs provided. This evidence is vital for law enforcement and forensic analysts.
- Report the incident to authorities: Contact relevant national cybersecurity organizations or law enforcement bodies. File a report with official authorities like the FBI Internet Crime Complaint Center (IC3) or the Cybersecurity and Infrastructure Security Agency (CISA).
- Check for official decryption tools: Visit legitimate, verified repositories such as No More Ransom from an uninfected device to check if a public decryption key exists for your specific ransomware strain.
What NOT to Do
- Do not pay the ransom: Security experts and law enforcement strongly advise against paying. Payment does not guarantee you will get your decryption key, marks you as a target for future attacks, and directly finances cybercrime.
- Do not connect clean backup drives: Connecting an external hard drive or USB key to an infected machine will likely result in your backups being encrypted as well.
- Do not run unverified decryption software: Downloading fake decryptors from untrusted websites can introduce secondary malware infections or permanently corrupt your files.
How to Recover and Secure Your System
Once the threat is isolated, wipe the infected machine completely by performing a full drive format and reinstalling the operating system from official installation media. Restore your files using clean backups created prior to the infection. Before reconnecting to your local network, update all operating systems, software, and security definitions, and change all account passwords from a separate, secure device.
Sources & references
Information verified with official organizations.
Spotted an error? Report it — we correct factual mistakes promptly.