Skip to main content

After ransomware

Preserve the original data first.

Disconnect the affected device from the network. Keep the ransom note and encrypted files. Do not run unverified decryptors on your only copy before analysis.

If this is a work device, notify your administrator or incident-response team. Do not connect backup drives to it. Record when the incident was discovered and which devices were affected.

There is no universal decryptor. Some ransomware variants have public recovery tools, but a matching extension does not establish compatibility. Verify the source and applicability of any tool. Before restoring a backup, contain the infection and prepare a safe environment.

Knowledge base