How to identify and safely handle a ransomware attack on your business computer
Summary
This guide helps you troubleshoot and resolve: How to identify and safely handle a ransomware attack on your business computer. Follow the steps below to fix the issue.
Common Causes
Ransomware is one of the most damaging cyber threats facing Australian small businesses. It encrypts files on your computer or server and demands payment, usually in cryptocurrency, to restore access. Acting quickly and calmly in the first few minutes can make the difference between a contained incident and a full-blown data loss event. This guide walks you through how to recognise an attack, isolate affected devices, and start the recovery process safely.
Recognising the Warning Signs
Ransomware does not always announce itself with a dramatic lock screen. Many strains begin quietly in the background before fully executing. Watch for these early indicators:
- Files suddenly become inaccessible or have strange extensions such as
.locked,.crypt, or random characters - Your computer becomes unusually slow or the hard drive is constantly active when you are not doing anything
- You receive unexpected pop-ups demanding payment, often with a countdown timer
- Antivirus or Windows Security alerts report that a threat has been blocked or quarantined
- You cannot open documents that were previously fine, or they appear corrupted
- Other staff members report similar symptoms on their devices
Immediate Containment Steps
- Disconnect from the network. Unplug the Ethernet cable or turn off Wi-Fi on the affected device straight away. This stops the ransomware from spreading to file shares, cloud sync folders, and other machines on the same network.
- Disable shared drives. If you can safely access another device on the same network, disconnect any mapped network drives or pause sync services such as OneDrive, Dropbox, or Google Drive until the situation is assessed.
- Isolate, do not power off. Leave the infected machine running but disconnected. Some recovery tools and forensic investigations rely on the device remaining in its current state.
- Document what you see. Take photos or screenshots of any ransom messages, unusual file extensions, or pop-ups. Note the time the issue was first noticed and which user reported it.
- Notify your team. Ask other staff to stop using their devices until the scope is understood. A quick message on your team chat is enough at this stage.
- Open a support ticket. Log in to the support portal and submit a high-priority ticket describing the symptoms, the time of discovery, and the steps you have already taken. Our security team will guide you through the next stage.
Assessing the Scope
Once the immediate threat is contained, you need to understand how far the attack has spread before attempting any recovery.
Check Connected Devices
- Look for the same symptoms on other computers, laptops, and servers on the same network
- Check whether shared folders, NAS devices, or backup appliances show signs of encrypted files
- Review cloud storage accounts for unexpected file modifications or new files you did not create
Identify the Entry Point
Common entry points include phishing emails, compromised remote desktop credentials, unpatched software, and malicious browser downloads. If you can identify the entry point, you can prevent reinfection during recovery.
Review Your Backups
- Confirm when your most recent clean backup was taken
- Verify that backups are stored offline or in an immutable cloud service that ransomware cannot reach
- Do not connect backup drives to the infected machine to test them
Recovery Steps
- Wait for guidance. Do not attempt to run antivirus scans, decryption tools, or recovery software until a technician has assessed the situation. Well-meaning cleanup can destroy evidence and complicate recovery.
- Prepare a clean device. Recovery is safest when performed from a machine that was never connected to the affected network. Use a known-clean computer to download any tools or restore data.
- Reset credentials. Once the technician confirms it is safe, change passwords for all accounts that were accessible from the infected device. Start with email, VPN, and administrator accounts. See our guide to password reset (Windows login) for step-by-step instructions.
- Restore from backup. Working with your technician, restore files from your most recent verified clean backup. Restore to a clean device or a freshly rebuilt system rather than over the infected one.
- Rebuild the affected system. In most cases, the safest path is a full wipe and reinstall of the operating system rather than attempting to clean the infection in place.
- Patch and update. Before reconnecting the recovered device to the network, ensure the operating system, browsers, and all applications are fully updated.
Preventing Future Incidents
Once your business is back online, take these steps to reduce the risk of a repeat attack:
- Enable multi-factor authentication on every account that supports it, especially email and remote access tools
- Keep automatic updates turned on for Windows, macOS, and all installed software
- Maintain regular offline backups following the 3-2-1 rule: three copies, on two different media, with one stored offsite
- Provide ongoing security awareness training for all staff, with a focus on recognising phishing emails
- Restrict administrator privileges so staff only have the access they need to do their job
- Segment your network so that a compromise on one device cannot easily reach critical systems
When to Escalate
Contact us immediately through the support portal if any of the following apply:
- Multiple devices are affected or the infection appears to be spreading
- Customer data, financial records, or personal information may have been accessed
- Your business operations are halted and you need urgent assistance
- You are unsure whether your backups are clean or safe to use
Time is the most critical factor in any ransomware incident. The faster you disconnect affected devices and engage our security team, the better your chances of a full recovery without data loss.
Still Having Issues?
💻 Open a Ticket