Your Files Are Encrypted and There Is a Countdown. Now What?
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Ransomware announces itself. Your files are renamed, they will not open, and a note appears explaining where to send money. Unlike most security incidents, there is no ambiguity about whether something has happened.
What you do in the first hour matters more than anything you do afterwards.
First: disconnect, do not shut down
Disconnect the machine from the network. Pull the ethernet cable, turn off Wi-Fi, unplug any external drives. Ransomware spreads to network shares and attached storage, and encryption that is still running is still doing damage.
Do not immediately power off if you can avoid it. Some ransomware keeps encryption keys in memory, and a specialist may be able to recover them from a running machine. Disconnecting stops the spread; shutting down can destroy the one thing that might have helped.
Photograph the ransom note with your phone, including any ID or reference string. That string often identifies which family of ransomware you are dealing with, which determines whether a free decryptor exists.
Second: find out what you are dealing with
Not all ransomware is unbreakable. Security researchers and law enforcement have published free decryption tools for a number of families, usually after seizing infrastructure or finding a flaw in the encryption.
The No More Ransom project, run jointly by Europol and industry partners, hosts a collection of free decryptors and a service that identifies a strain from a sample file and the ransom note. It costs nothing to check, and it is the first thing to try before considering anything else.
Third: restore, if you can
If you have a backup that was not connected to the infected machine, this is the moment it pays for itself.
- Wipe the machine completely before restoring. Do not restore onto a system you have not rebuilt — you risk re-encrypting your own recovery.
- Check the backup is clean. If the infection sat quietly for a while, recent backups may contain it.
- Restore from the oldest known-good point you can tolerate losing work back to, rather than the newest.
This is also the argument for the backup rule that sounds excessive until you need it: at least one copy kept offline or otherwise disconnected. Ransomware encrypts what it can reach, and a backup drive left permanently plugged in is simply another folder.
On paying
The honest position is that this is a genuinely difficult decision and anyone who presents it as simple is not being straight with you.
Law enforcement agencies broadly advise against paying, for reasons that hold up: payment funds the operation, marks you as someone who pays, and buys a promise from a criminal. Recovery after payment is frequently partial — decryptors are often slow, buggy, or fail on some files.
At the same time, organisations do pay, usually when the alternative is losing something irreplaceable. If you reach that point, it is a decision for someone senior with legal advice, not a technical call — and in some jurisdictions payments to sanctioned entities carry their own legal exposure.
For an individual with family photos and no backup, the answer is uncomfortable, and it is the strongest possible argument for setting up a backup before you ever need one.
A worked example of the first hour
It is a Sunday evening. You open a folder of photographs and every filename has an unfamiliar extension appended. A text file sits in the same folder explaining the situation.
The instinct is to open more folders to see how bad it is, and that instinct costs you. Every second the machine stays connected, the encryption continues and reaches further into whatever it can see — including the network drive holding the household's shared files and the external disk you leave permanently plugged in for backups.
The better sequence is mechanical. Unplug the network cable or switch off Wi-Fi from the physical switch if there is one. Unplug the external drive. Photograph the ransom note with your phone. Only then start assessing.
Notice what that ordering assumes: that you will act before you understand. That is deliberate. Understanding takes minutes, and the damage is being done in those minutes. Disconnecting costs nothing if you turn out to be wrong.
Now consider the same evening with one difference — a backup drive that is only connected on Sundays and was unplugged at the time. The photographs are still encrypted, the machine still has to be rebuilt, and the weekend is still ruined. But nothing is lost, no decision about payment ever has to be made, and the incident becomes an inconvenience rather than a catastrophe. That single habit is the difference between the two versions.
What a backup has to survive to actually help
Most people who believe they have a backup have something that would not have helped here, and the reasons are specific.
- A permanently connected external drive is another folder from the ransomware's point of view. It gets encrypted alongside everything else.
- A folder-sync service is not a backup. It faithfully synchronises the encrypted versions over your good ones. Many such services keep version history that can be rolled back, which does help — but check that yours does, and check how far back it goes, before relying on it.
- A backup you have never restored from is an assumption. File-permission problems, a forgotten passphrase and a partially corrupt archive all look exactly like a working backup until the moment you need it.
- A backup with no offline or immutable copy protects against a failed disk, not against something actively hostile that has your credentials.
The practical version for a household is unglamorous: a cloud backup with version history for convenience, plus a drive that spends most of its life unplugged in a drawer. Our guide to backing up your data covers the mechanics.
The complication nobody mentions in the ransom note
Many ransomware operations now copy data out before encrypting it, then threaten to publish what they took if payment is not made.
This changes the arithmetic in an uncomfortable way. A perfect backup solves the encryption problem completely — you restore, you refuse, you move on. It does nothing whatsoever about a copy of your files already sitting on someone else's server.
For a household, that mostly means being realistic about what was on the machine and treating anything sensitive as potentially exposed: change passwords, warn anyone whose personal information was in your files, and watch for follow-up fraud that uses those details to sound convincing. For an organisation it may trigger legal notification duties, which is one of the reasons this becomes a decision for people with legal advice rather than a technical judgement.
It is also why the pressure to pay does not disappear even with good backups, and why anyone who says "just have backups and ignore them" is describing only half the problem.
What actually prevents this
Recovery advice is what you need at the worst moment. Prevention is what stops the moment arriving, and the routes in are boringly consistent.
- Attachments and links in email. The document that asks you to enable content, the invoice from a supplier you do not use. Our guide to spotting phishing covers the patterns.
- Cracked or pirated software, which is a well-established delivery route precisely because the user has already agreed to disable warnings.
- Unpatched systems and exposed remote access. Keeping updates current is dull and effective.
- Reused passwords on services with remote access, which give an attacker a legitimate way in.
Reputable security software catches a share of this before it runs, and it is worth having, but treat it as one layer. The reason the backup advice keeps coming back is that a backup is the only control that works no matter how the thing got in.
Afterwards
Rebuild the machine from scratch rather than cleaning it. A cleaner that removes the ransomware does not tell you what else was installed alongside it, and the cost of being wrong is another incident weeks later.
Change every password from a different, known-clean device — assume anything typed on the infected machine is compromised, including anything saved in a browser. Where an account offers it, revoke existing sessions as well, since a changed password does not always log out a session that is already open.
Report the incident to your national cybercrime reporting body. It costs little, and it feeds the intelligence work that produces the free decryptors described above — the tool that rescues someone next year is built from reports like yours.
Then set up the backup you did not have. If you do one thing after reading this, that is the one, and doing it this week costs an hour. Backup and anti-ransomware tools are compared in our security tool shortlist.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Sources
Factual claims above were checked against these primary sources. Verify directly on the source for anything time-sensitive before relying on it.
Continue reading
antivirus
Bitdefender vs Avast in 2026: Which to Trust?
Both scored full marks at AV-TEST in June 2026 and one test case apart at AV-Comparatives. So the choice is not about detection. Here is what it is about.
privacy
They Did Not Steal Your Phone. They Stole Your Number.
A SIM swap moves your phone number to someone else, and every code sent to it goes with it. How the attack works, the warning sign, and why SMS is the weakest second factor.
guides
Best Antivirus 2026: Bitdefender, Norton, Avast, Webroot
Bitdefender vs Norton vs Avast vs Webroot: a research-led 2026 antivirus comparison on independent lab results, features, speed and price.
