Home › Knowledgebase › KB-411

How to identify and safely handle a ransomware attack on your business computer

Summary

This guide helps you troubleshoot and resolve: How to identify and safely handle a ransomware attack on your business computer. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Ransomware is one of the most damaging cyber threats facing Australian small businesses. It encrypts files on your computer or server and demands payment, usually in cryptocurrency, to restore access. Acting quickly and calmly in the first few minutes can make the difference between a contained incident and a full-blown data loss event. This guide walks you through how to recognise an attack, isolate affected devices, and start the recovery process safely.

Recognising the Warning Signs

Ransomware does not always announce itself with a dramatic lock screen. Many strains begin quietly in the background before fully executing. Watch for these early indicators:

If you see a ransom note on your screen, do not click anything, do not pay, and do not attempt to restart the machine. Powering off can sometimes destroy forensic evidence and interfere with recovery options.

Immediate Containment Steps

  1. Disconnect from the network. Unplug the Ethernet cable or turn off Wi-Fi on the affected device straight away. This stops the ransomware from spreading to file shares, cloud sync folders, and other machines on the same network.
  2. Disable shared drives. If you can safely access another device on the same network, disconnect any mapped network drives or pause sync services such as OneDrive, Dropbox, or Google Drive until the situation is assessed.
  3. Isolate, do not power off. Leave the infected machine running but disconnected. Some recovery tools and forensic investigations rely on the device remaining in its current state.
  4. Document what you see. Take photos or screenshots of any ransom messages, unusual file extensions, or pop-ups. Note the time the issue was first noticed and which user reported it.
  5. Notify your team. Ask other staff to stop using their devices until the scope is understood. A quick message on your team chat is enough at this stage.
  6. Open a support ticket. Log in to the support portal and submit a high-priority ticket describing the symptoms, the time of discovery, and the steps you have already taken. Our security team will guide you through the next stage.

Assessing the Scope

Once the immediate threat is contained, you need to understand how far the attack has spread before attempting any recovery.

Check Connected Devices

Identify the Entry Point

Common entry points include phishing emails, compromised remote desktop credentials, unpatched software, and malicious browser downloads. If you can identify the entry point, you can prevent reinfection during recovery.

Review Your Backups

Modern ransomware often lies dormant for days or weeks before activating. A backup from yesterday may already be compromised if it was connected to the network during the attack. Always verify backup integrity before relying on it.

Recovery Steps

  1. Wait for guidance. Do not attempt to run antivirus scans, decryption tools, or recovery software until a technician has assessed the situation. Well-meaning cleanup can destroy evidence and complicate recovery.
  2. Prepare a clean device. Recovery is safest when performed from a machine that was never connected to the affected network. Use a known-clean computer to download any tools or restore data.
  3. Reset credentials. Once the technician confirms it is safe, change passwords for all accounts that were accessible from the infected device. Start with email, VPN, and administrator accounts. See our guide to password reset (Windows login) for step-by-step instructions.
  4. Restore from backup. Working with your technician, restore files from your most recent verified clean backup. Restore to a clean device or a freshly rebuilt system rather than over the infected one.
  5. Rebuild the affected system. In most cases, the safest path is a full wipe and reinstall of the operating system rather than attempting to clean the infection in place.
  6. Patch and update. Before reconnecting the recovered device to the network, ensure the operating system, browsers, and all applications are fully updated.

Preventing Future Incidents

Once your business is back online, take these steps to reduce the risk of a repeat attack:

Never pay the ransom. Paying does not guarantee you will regain access to your files, marks your business as a willing target for future attacks, and may have legal implications under Australian regulations.

When to Escalate

Contact us immediately through the support portal if any of the following apply:

Time is the most critical factor in any ransomware incident. The faster you disconnect affected devices and engage our security team, the better your chances of a full recovery without data loss.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket