PanicStation.org
us Technology & digital loss

What to do if…
you find a ransom note or encrypted files on your computer

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Disconnect the computer from Wi-Fi and ethernet now, then use a different, clean device to get help and report what happened. Do not follow instructions in the note.

Do not do these things

  • Don’t rush to pay the ransom or message the attacker before getting help.
  • Don’t click links, open attachments, or run “decryptor” tools mentioned in the note.
  • Don’t plug in backup drives or USB sticks to “save what you can”; ransomware may spread to attached storage.
  • Don’t restore from backups yet.
  • Don’t sign in to email, banking, work, school, cloud, or password-manager accounts from the affected computer.
  • Don’t wipe or reinstall the computer right away if you may need professional help, insurance records, work instructions, or reporting details.

What to do now

  1. Disconnect the computer from the network. Turn off Wi-Fi and unplug ethernet. If files are rapidly changing, renaming, or disappearing and you cannot disconnect quickly, power the device down.

  2. Keep backups and shared storage away from it. Unplug external drives only if they are already connected. Do not connect any new USB drive, backup disk, phone, camera card, or network storage to the affected computer.

  3. Reduce spread to other devices. If the computer uses shared folders, a home NAS, or a work or school network, disconnect it from those connections. Leave other devices off that shared storage until you get advice.

  4. Record the ransom note without engaging. From a phone or another clean device, take photos of the note, file names, ransom instructions, contact details, wallet addresses, new file extensions, affected folders, and the date and time you found it.

  5. Use a clean device to secure key accounts. Start with the email account that resets your other passwords. Then change passwords for banking, Apple, Google, Microsoft, work, school, cloud storage, and any password manager. Turn on multi-factor authentication where available.

  6. If this is a work or school device, stop DIY cleanup. Contact the IT or security team immediately. Tell them the device is disconnected, what note you saw, and whether shared folders or external drives were connected.

  7. Report the incident in the USA. Individuals can report ransomware to the FBI through IC3 or a local FBI field office. Organizations may also use StopRansomware or CISA reporting routes.

  8. Get help before recovery. A reputable security or IT professional can help check what was affected, remove malware safely, and restore from backups only when the device and backups are believed to be clean.

  9. Protect finances if credentials may have been exposed. If you used banking, shopping, tax, payroll, or payment accounts on that computer, contact the bank or card issuer’s fraud line from a clean device and ask what monitoring or replacement steps are appropriate.

What can wait

  • You do not have to decide about payment now; focus first on containment, records, account security, and reporting.
  • You do not have to restore files today; restore only after the infected device and the backup source are checked.
  • You do not have to identify the exact ransomware strain right now.
  • You do not have to notify every contact immediately unless a work, school, client, or regulated-data process requires it.

Important reassurance

A ransom note is meant to create urgency. Disconnecting the device, not following the note, and moving to a clean device are useful first steps that can limit further harm while you get support.

Scope note

These are first steps only. Full recovery may involve malware removal, rebuilding the system, checking backups, reviewing accounts, and deciding whether specialist cybersecurity, legal, insurance, or workplace help is needed.

Important note

This guide is general information, not professional cybersecurity, legal, financial, insurance, or forensic advice. If sensitive personal data, workplace systems, school systems, client data, health data, or financial access may be involved, get qualified help and follow any formal incident process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us