What to Do When Ransomware Encrypts Your Files
A ransomware infection can turn a normal Windows or Mac computer into a locked-up mess within minutes. Files may gain unfamiliar extensions, open as unreadable data, and appear alongside a ransom note placed in nearly every directory. That repeated note usually means the malware has scanned many folders and automated its demand message.
Do not delete the notes or rush to pay. The message can help identify the ransomware family, while paying gives no guarantee that the criminals will provide a working decryptor. Some operators disappear, send defective tools, or demand another payment after receiving the first one.
The safest response is to contain the incident, preserve useful evidence, and work out what was affected. This applies to home users, sole traders, and Australian organisations connected through an NBN router, office server, NAS device, or cloud-synchronisation account.
If the computer belongs to a business in Sydney, Brisbane, Perth, or elsewhere, treat the event as a data breach as well as a file-recovery problem. Customer records, invoices, payroll files, and identity documents may have been copied before encryption.
Isolate the Infected Computer
Disconnect the affected device from Wi-Fi and unplug its Ethernet cable. Remove it from shared networks, VPN connections, mapped drives, and external storage. If several computers are showing encrypted files, disconnect them all and stop using the shared server or NAS until the scope is clearer.
Do not browse the ransom site, open unknown attachments, or log in to accounts from the infected machine. A ransomware strain may still be active, and some variants continue encrypting files on connected drives. If the device is a company asset, contact the person responsible for IT or an incident-response provider before making major changes.
Record the time the encryption was noticed, the filenames or extensions involved, and the wording of the note. Photographing the screen can be useful if the note disappears after cleanup. Keep one untouched copy of the ransom note and any suspicious email that may have started the infection.
Preserve Clues Before Cleaning
Ransom notes often contain a victim ID, email address, payment wallet, deadline, and instructions for uploading a sample file. These details can support ransomware identification. Never upload private documents to an unknown criminal portal; use a small, non-sensitive sample only with a reputable identification service.
Avoid running random “free decryptor” programs advertised in forums or pop-up pages. Some are fake tools designed to install a second trojan. Pc Malware Expert’s security tips and tricks can help with safer malware-handling practices, but a serious business incident may need professional forensic collection.
If the machine is still powered on, avoid experimenting with registry edits, system restores, or mass deletion. An expert may need logs, running-process information, and other evidence. If the computer is unstable or the attacker appears active, disconnect it from the network and follow advice from a qualified responder about whether to shut it down.
Identify the Ransomware Family
Search the note text, extension, contact address, and victim ID together, but rely on reputable sources. Tools such as ID Ransomware and recognised security vendors can sometimes match a note and encrypted file sample to a known family. Identification is important because decryptors are highly specific and a tool for one strain may damage files encrypted by another.
Check whether the files are actually encrypted or merely renamed, moved, hidden, or blocked by a damaged user profile. A ransom note in every folder can be created by a simple script, while the underlying damage may vary between drives. Look for untouched file types, recent backups, and files that open correctly on disconnected media.
A common entry route is a phishing email, cracked software package, exposed remote desktop service, or malicious browser download. Australian users should also check whether a fake parcel, myGov, bank, or Australia Post message led to the infection. Guidance on removing phishing redirects is relevant when a suspicious login page was part of the chain.
Check Backups and Recovery Options
Use backups made before the attack, but do not reconnect them to the infected computer until the malware has been removed. Test a small selection of files first. Offline USB backups, properly versioned cloud storage, and snapshots on a protected server are safer than a drive that was permanently attached to the PC.
Windows users may have File History, previous versions, or restore points, although ransomware often deletes shadow copies. Mac users can check Time Machine backups, provided the backup disk was disconnected or protected before the incident. Cloud services may offer file version history, but synced encrypted files can also propagate unless the account is paused quickly.
Useful recovery avenues include:
- A verified offline or immutable backup
- A reputable decryptor for the identified strain
- Previous versions or cloud file history
- Original files retained by clients, suppliers, or email attachments
Do not format the affected disk until recovery options and evidence have been assessed. If no decryptor exists today, preserving encrypted files may allow recovery if researchers release a key later.
Remove the Malware Safely
Recovery should begin only after containment and identification. A trusted security product, offline scanner, or specialist technician can inspect the computer and remove persistence mechanisms. On Windows, Safe Mode may help with certain threats, but it is not a universal fix; modern ransomware can use scheduled tasks, stolen administrator credentials, or compromised network devices.
Change passwords from a clean device, starting with email, banking, cloud storage, and administrator accounts. Enable multifactor authentication and revoke unknown sessions. If the infection involved Discord command traffic, review Discord malware indicators before allowing that application back onto the network.
For an Australian business, consult the Australian Cyber Security Centre and consider reporting the incident through ReportCyber. If personal information was exposed, assess obligations under the Notifiable Data Breaches scheme. Banks, insurers, managed service providers, and affected customers may also need prompt notification.
Decide Whether to Pay
Payment is a last-resort business decision, not a reliable technical solution. Criminals may fail to decrypt files, provide a tool that corrupts large databases, or demand more money. Paying also funds further attacks and may create legal, insurance, accounting, and sanctions-screening issues.
Compare the available paths before making a decision:
| Recovery path |
Likely benefit |
Main risk or limitation |
| Offline backup |
Fast, clean restoration |
Backup may be incomplete or infected |
| Official decryptor |
Can recover files without payment |
Available only for some ransomware |
| Specialist response |
Preserves evidence and limits spread |
Can be expensive |
| Paying the demand |
May produce a decryptor |
No guarantee, ongoing criminal contact |
Keep the ransom note, encrypted samples, logs, and incident timeline even after restoration. Rebuild compromised systems where practical, patch exposed services, disable unnecessary remote access, and separate backup accounts from everyday administrator accounts. A calm, documented response gives Australian households and businesses a better chance of recovering files without extending the attackers’ reach.