Ransomware: What to Do in the First Hour
You sit down, and instead of your files you see a ransom note demanding payment in cryptocurrency. Your stomach drops. What you do in the next sixty minutes matters more than almost anything else — it determines how far the infection spreads, whether you keep any clean data, and whether you preserve the evidence investigators and insurers will need. This is not legal advice, and every situation is different, but here is a sound general playbook.
Minute 0 to 5: Do not panic, and do not pay yet
Take a breath. Panic leads to the two worst mistakes: paying immediately, or wiping the machine to “make it go away.” Do neither yet. Paying does not guarantee you get your files back, may violate sanctions rules, and marks you as a target for the next attack. Wiping destroys the evidence you may legally need. Leave the ransom note on screen and take a photo of it with your phone.
Minute 5 to 15: Contain it — pull it off the network
Ransomware spreads across networks, shared drives, and cloud sync folders. Your single most important action is to stop the spread:
- Disconnect the infected computer from the network. Unplug the Ethernet cable and turn off Wi-Fi. If it is a laptop, turn off Wi-Fi in airplane mode.
- Do not shut the computer down unless you have no other way to isolate it. Some ransomware keeps encryption keys in memory that are lost on shutdown, and powering off can destroy forensic evidence. Disconnecting from the network is enough to stop the spread while keeping the machine intact.
- Isolate other devices. If you have a business network, disconnect shared servers and unplug the network switch or unplug other machines showing the same behavior. Turn off automatic cloud sync (OneDrive, Dropbox, Google Drive) so encrypted files do not overwrite your clean cloud copies.
Minute 15 to 30: Assess the scope
Now figure out how bad it is, without touching the infected machine more than necessary.
- Which devices are affected? Walk to each computer and look. One machine or twenty?
- What got encrypted? Local files only, or network shares and backups too?
- Are your backups intact? Check whether your backups are on a device that was disconnected (good) or on an always-connected drive that also got encrypted (bad). This single fact often decides whether you recover in a day or a month.
- Do not log in with admin credentials on the infected machine — attackers watch for those to spread further.
Minute 30 to 45: Notify the right people
You do not have to handle this alone, and in many cases you are legally required to involve others.
- Report to law enforcement. File with the FBI’s Internet Crime Complaint Center at ic3.gov. For attacks on a business, you can also contact your local FBI field office.
- Notify your cyber-insurance provider immediately. Most policies require prompt notification and have a hotline with an approved response team. Acting without them can void coverage.
- Understand your legal duties. If personal data (customer records, health information, employee data) may have been stolen, Indiana’s data-breach notification law and possibly federal rules may require you to notify affected people and the Indiana Attorney General. This guide is not legal advice — talk to an attorney about your specific obligations.
- Tell your IT provider or a security professional. If you do not have one, this is the moment to call one. In the Seymour and Indianapolis area, That Computer Guy can help you triage: 812-414-9097.
Minute 45 to 60: Preserve evidence and plan recovery
- Document everything. The photo of the ransom note, the file names and extensions, the time you noticed it, and every step you have taken. Keep a written timeline.
- Do not delete the ransom note or reformat anything. Investigators and decryption tools may need it. The free service No More Ransom (nomoreransom.org) can sometimes identify the strain and even provide a free decryptor.
- Plan the clean rebuild. Recovery means wiping infected machines completely, reinstalling the operating system from trusted media, and restoring data only from a backup you have confirmed is clean. Never restore onto a machine you have not wiped, and never plug a clean backup into an infected computer.
Mistakes that make it worse
- Paying the ransom on impulse.
- Wiping or reimaging before preserving evidence and checking for a free decryptor.
- Restoring from a backup that was connected during the attack (it may be encrypted too).
- Reconnecting an infected machine to the network to “check something.”
- Not telling your insurer, which can void your policy.
After it is over: prevent the next one
The only real defense is preparation. Keep offline, tested backups following the 3-2-1 rule (three copies, two media types, one off-site and disconnected). Turn on multi-factor authentication everywhere. Patch your systems. Train your team to spot phishing, which is how most ransomware gets in. A recovery plan you have actually tested is worth more than any ransom you could pay.
Reminder: This is general guidance, not legal advice. For your legal obligations, consult an attorney or the Indiana Attorney General’s office, and report the crime to the FBI at ic3.gov.
⚠ Safety note: This guide is general information, not legal advice. Ransomware may involve reporting obligations under Indiana and federal law. Contact law enforcement (FBI IC3 at ic3.gov), and for guidance on your legal duties consult an attorney or the Indiana Attorney General’s office. When in doubt, call a professional before acting.