Your Files Are Encrypted and There Is a Countdown. Now What?
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Ransomware announces itself. Your files are renamed, they will not open, and a note appears explaining where to send money. Unlike most security incidents, there is no ambiguity about whether something has happened.
What you do in the first hour matters more than anything you do afterwards.
First: disconnect, do not shut down
Disconnect the machine from the network. Pull the ethernet cable, turn off Wi-Fi, unplug any external drives. Ransomware spreads to network shares and attached storage, and encryption that is still running is still doing damage.
Do not immediately power off if you can avoid it. Some ransomware keeps encryption keys in memory, and a specialist may be able to recover them from a running machine. Disconnecting stops the spread; shutting down can destroy the one thing that might have helped.
Photograph the ransom note with your phone, including any ID or reference string. That string often identifies which family of ransomware you are dealing with, which determines whether a free decryptor exists.
Second: find out what you are dealing with
Not all ransomware is unbreakable. Security researchers and law enforcement have published free decryption tools for a number of families, usually after seizing infrastructure or finding a flaw in the encryption.
The No More Ransom project, run jointly by Europol and industry partners, hosts a collection of free decryptors and a service that identifies a strain from a sample file and the ransom note. It costs nothing to check, and it is the first thing to try before considering anything else.
Third: restore, if you can
If you have a backup that was not connected to the infected machine, this is the moment it pays for itself.
- Wipe the machine completely before restoring. Do not restore onto a system you have not rebuilt — you risk re-encrypting your own recovery.
- Check the backup is clean. If the infection sat quietly for a while, recent backups may contain it.
- Restore from the oldest known-good point you can tolerate losing work back to, rather than the newest.
This is also the argument for the backup rule that sounds excessive until you need it: at least one copy kept offline or otherwise disconnected. Ransomware encrypts what it can reach, and a backup drive left permanently plugged in is simply another folder.
On paying
The honest position is that this is a genuinely difficult decision and anyone who presents it as simple is not being straight with you.
Law enforcement agencies broadly advise against paying, for reasons that hold up: payment funds the operation, marks you as someone who pays, and buys a promise from a criminal. Recovery after payment is frequently partial — decryptors are often slow, buggy, or fail on some files.
At the same time, organisations do pay, usually when the alternative is losing something irreplaceable. If you reach that point, it is a decision for someone senior with legal advice, not a technical call — and in some jurisdictions payments to sanctioned entities carry their own legal exposure.
For an individual with family photos and no backup, the answer is uncomfortable, and it is the strongest possible argument for setting up a backup before you ever need one.
Afterwards
Rebuild the machine from scratch rather than cleaning it. Change every password from a different, known-clean device — assume anything typed on the infected machine is compromised. Report the incident to your national cybercrime reporting body; it costs little and feeds the intelligence that produces future decryptors.
Then set up the backup you did not have.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Sources
Factual claims above were checked against these primary sources. Verify directly on the source for anything time-sensitive before relying on it.