Ransomware is a data loss problem with a countdown timer attached, and the timer is designed to stop you thinking clearly. There is more to try than most victims realise, and several of the options disappear if you take the obvious first steps in the wrong order.
The first hour
- Disconnect from the network. Unplug the cable, turn off Wi-Fi. Encryption spreads to network shares, NAS boxes and connected cloud folders. Stopping the spread protects what is not yet lost.
- Do not reboot. Some families keep keys in memory, and some leave recoverable artefacts that a reboot clears. A running infected machine is worth more to a responder than a rebooted one.
- Photograph the ransom note with your phone, including the file extension used on encrypted files. This identifies the family, which determines whether a free decryptor exists.
- Disconnect backup drives. If a backup drive is attached, it is being encrypted too.
- Do not delete the encrypted files. If a decryptor is released later, you need them. People clean up in frustration and remove the only thing a future fix could work on.
Identify the family before anything else
This determines everything that follows. The No More Ransom project, run by Europol with a number of security vendors, maintains free decryptors for a substantial list of families and will identify yours from a sample file and the ransom note.
It is genuinely free, and it is the single highest-value thing to try. Where a decryptor exists, the problem is solved without paying anyone. Do this before buying software, before contacting the attackers, and before writing anything off.
Shadow copies and snapshots
Windows keeps Volume Shadow Copies for System Restore, and macOS keeps Time Machine local snapshots. Most ransomware deletes these deliberately, which is why the advice is often dismissed — but “most” is not “all”, and the check takes minutes.
On Windows, right-click a folder and look at Previous Versions, or check whether System Restore points survive. On macOS, tmutil listlocalsnapshots / lists local snapshots. On a NAS, check for filesystem snapshots — and note that snapshots on a properly configured NAS are frequently immutable, which is exactly the scenario they exist for.
Where recovery software genuinely helps
This part is not widely understood, and it is the most useful thing in this article.
Many ransomware families do not encrypt a file in place. They read the original, write an encrypted copy as a new file, then delete the original. From the file system’s point of view that is an ordinary deletion — which means the original may still be sitting in unallocated space, exactly like any other deleted file.
So a recovery scan is worth running. Not on the encrypted files, which are genuinely encrypted, but on the free space where the deleted originals may remain.
The rules are the same as any recovery, with more urgency:
- Stop using the machine. Every write reduces what survives.
- Image the drive first. Create a sector-level copy with an appropriate disk-imaging utility, then scan the copy and preserve the original device.
- Scan the image, not the machine.
Success varies enormously by ransomware family, storage type and how long the machine continued writing data. SSDs with active TRIM are especially difficult, while a spinning disk that was disconnected quickly may retain more deleted originals. EaseUS Data Recovery Wizard and MiniTool Power Data Recovery both let you scan and inspect results before deciding whether a paid recovery is worthwhile.
On paying
We are not going to advise you either way, because it is a decision about your business, your obligations and your risk, and anyone offering a confident universal answer is not thinking about your situation.
What we will say factually: payment does not guarantee a working decryptor; in some jurisdictions payments to sanctioned entities carry legal consequences; and if you have cyber insurance or a regulatory reporting duty, involve those people before making any decision. Report the incident to your national cybercrime body regardless, because that reporting is part of how decryptors eventually get built.
Afterwards, properly
Do not restore onto the infected machine. Rebuild from clean media, then restore data. Restoring onto a compromised system reinfects the restore, and this happens to people twice.
Change passwords from a different, clean device, prioritising email and anything reused. Assume credentials on the machine were taken, because increasingly they are — modern ransomware often exfiltrates before encrypting.
The only real defence
- Keep one backup copy offline or immutable. An always-connected external drive is not a ransomware backup, it is a second victim.
- Enable snapshots with retention on any NAS, and make them immutable if the unit supports it.
- Test a restore. Discovering your backup does not restore during an incident is the worst possible timing.
- Keep versioned cloud storage, which usually allows rolling back to pre-encryption versions.
If it is happening right now: disconnect the network, do not reboot, photograph the note, and check No More Ransom before you do anything else.
Recovery tools to check after a ransomware incident
These are paid-product links from active UrRecover affiliate relationships. Use the free scan or preview first where available, compare what each tool actually finds, and do not buy if the files you need are not visible.
- EaseUS Data Recovery Wizard — Scan and preview recoverable deleted originals.
- MiniTool Power Data Recovery — A second scan option for Windows storage.
- AOMEI FastRecovery — Another tracked Windows recovery option.
Recovery results depend on the device, the failure and whether new data has overwritten the missing files. Save recovered files to a different drive. For physical damage, unusual noises or an unstable RAID, stop and consult a professional recovery laboratory.
Recovering from shadow copies and older versions
Before anything else: do not pay, and do not overwrite the encrypted files. Some ransomware misses shadow copies and older file versions entirely, and those are recoverable with ordinary tools. EaseUS will scan for previous versions without touching the encrypted originals.