sua empresa foi atacada por ransomware: o que fazer?

Ransomware Attack: What to Do? Complete Guide for Businesses

Imagine this scenario: you arrive at work, turn on your computer, and find yourself facing a locked screen demanding a ransom in cryptocurrency to release your files. Unfortunately, this nightmare is an increasingly common reality for companies of all sizes. Did you know that, in 2023, Brazil was the 5th most attacked country in the world by ransomware? And that the average cost of a ransomware attack for companies can exceed millions of dollars, considering operational downtime, data recovery, and reputational damage? If your company were the next victim, would you know how to act? In this article, we will guide you through the crucial steps to respond to a ransomware attack, from initial identification to recovery and the prevention of future incidents. Get ready to protect your business and turn it into a digital fortress against this growing cyber threat.

Confirmation and isolation: critical first steps when facing ransomware

When there is a suspected ransomware attack, speed and accuracy in the first actions are decisive for minimizing damage and containing the spread of the threat. Do not panic, but act quickly and methodically. The first moments are crucial for incident response.

Identifying a ransomware attack: initial signs

Recognizing a ransomware attack as quickly as possible is the first step toward an effective response. Pay attention to the signs that may indicate a possible infection:

  • Files with strange extensions: Suddenly, your files have unknown extensions such as “.locky”, “.crypt”, “.encrypted”, or other variations. This is a strong indication of ransomware encryption.
  • Ransom messages: Text files (.txt, .html) or pop-up windows appear with instructions on how to pay a ransom to recover your data. These messages usually contain alarming language and deadlines.
  • Unusual system slowness: Your computers and servers start operating extremely slowly, even for simple tasks. Background encryption consumes a large amount of system resources.
  • Difficulty accessing files: You or your employees can no longer open documents, spreadsheets, images, or other important files that were previously accessible.
  • Antivirus alerts: Your antivirus software may detect and alert you about a malicious file or suspicious behavior related to ransomware. Do not ignore these alerts!

If you notice one or more of these signs, consider the possibility of a ransomware attack and proceed with caution. Confirmation and isolation are the next essential steps.

To deepen your knowledge about threat identification, explore resources such as the CERT.br Malware Guide, which provides valuable information about various types of malware, including ransomware.

your company was attacked by ransomware: what to do?

Isolating infected systems: containing the spread of ransomware

Once you suspect or confirm a ransomware attack, immediately isolating the affected systems is essential to prevent the malware from spreading to other devices and to the network as a whole. Follow these actions to isolate compromised systems:

  1. Network disconnection: Immediately disconnect infected computers and servers from the network. This means unplugging network cables (Ethernet) and disabling Wi-Fi. The goal is to prevent the ransomware from spreading through the local network and the internet.
  2. Shutdown (with caution): In many cases, shutting down the infected system may be necessary to interrupt encryption. However, before shutting it down, document everything you can: take photos of the screen, copy error messages, and note the names of affected files. Avoid restarting the infected system, as this can make subsequent forensic analysis more difficult.
  3. Physical isolation: If possible, move infected devices to a physically isolated location, away from the common work area, to avoid any accidental connection or contamination of other equipment.
  4. User account deactivation: If you identify user accounts that have been compromised, temporarily disable them to prevent the attacker from accessing other systems.

Remember: rapid isolation is your first line of defense against a ransomware attack. By containing the spread, you gain time to assess the situation and plan the next steps.

Damage assessment and notification: measuring the impact and communicating the incident

After isolating the affected systems, the next crucial step is to assess the extent of the damage caused by the ransomware attack and notify the relevant parties. This stage is essential for understanding the impact of the incident and initiating recovery and legal response processes.

Assessing the scope of the ransomware attack: identifying the real impact

With the systems isolated, focus on assessing the scope of the ransomware attack. This detailed evaluation will help determine the severity of the situation and prioritize recovery actions. Consider the following points:

  • Identification of affected systems: Which computers, servers, laptops, and devices were hit by the ransomware? Create an accurate inventory of the compromised systems.
  • Types of encrypted data: What types of files were encrypted? Important documents, databases, emails, customer files, financial data? Identifying the affected data is crucial for assessing the operational and financial impact.
  • Extent of encryption: What percentage of the data was encrypted? Was the attack contained in time, or were most critical data assets compromised?
  • Attack vector: How did the ransomware enter your network? Was it through a phishing email, a software vulnerability, a weak password, or another method? Understanding the attack vector is essential for preventing future incidents.
  • Log analysis: Examine system logs, firewalls, and other security tools to obtain more information about the attack, such as timestamps, source IPs, if possible, and other relevant details.

An accurate assessment of the scope of the ransomware attack will provide a solid basis for making informed decisions about data recovery, negotiation, if considered, and future security measures. In many cases, it may be useful to rely on cybersecurity specialists to perform a detailed forensic analysis.

your company was attacked by ransomware: what to do?

Notifying authorities and partners: responsibility and transparency

After assessing the damage, it is crucial to notify the competent authorities and relevant partners about the ransomware attack. Notification demonstrates responsibility and transparency, in addition to being fundamental for combating cybercrime and protecting your stakeholders.

Who should be notified?

  • Law enforcement authorities: File a police report at a police station or a unit specialized in cybercrime. At the national level, you may consider notifying the Federal Police (NUCCIBER). Notifying the authorities is important for investigations and for the broader mapping of cyberattacks.
  • Data protection authorities: If the ransomware attack involved personal data from customers or employees, you may have legal obligations to notify the National Data Protection Authority (ANPD), in accordance with the General Data Protection Law (LGPD).
  • Business partners: Inform relevant business partners, especially if the ransomware attack could affect them in any way, such as in cases involving data sharing or dependence on interconnected systems.
  • Customers and users: Depending on the nature of the attack and the affected data, it may be necessary to communicate the incident to your customers and users, especially if personal information has been compromised. Transparency builds trust.
  • Insurance provider: If your company has cyber insurance, notify the insurance provider as soon as possible. They may offer financial and technical support for the incident response.
  • Internal team and stakeholders: Keep your internal team informed about the situation, especially the IT, legal, communications, and senior management departments. Also communicate with relevant stakeholders, such as investors and board members.

Timely and transparent notification shows that your company is acting responsibly and proactively in response to the ransomware attack. Cooperate with the authorities and follow their guidance to mitigate impacts and strengthen security.

Data recovery and restoration: strategies to minimize losses

After confirming, isolating, and assessing the damage caused by the ransomware attack, the top priority is data recovery and the restoration of normal company operations. This is a delicate process that requires planning and technical expertise.

Exploring data recovery options after a ransomware attack

Recovering data encrypted by ransomware is a challenge, but there are some options to consider. The best strategy will depend on the nature of the attack, the availability of backups, and other specific circumstances.

  1. Restoration from backups: If your company has regular, up-to-date backups that are isolated from the network (offline backups), this is the most recommended and effective option. Restore the data from the most recent and intact backup. Make sure the backups were not affected by the ransomware. Verify backup integrity before starting the restoration.
  2. Decryption tools: In some cases, free decryption tools may be available for certain ransomware variants. Organizations such as No More Ransom!, a joint initiative by Europol, the Dutch National Police, McAfee, and Kaspersky, offer useful tools and information. Check whether a decryption tool exists for the ransomware variant that affected your company.
  3. Negotiation and ransom payment (last resort and with caution): Paying the ransom is a controversial decision and is generally not recommended. There is no guarantee that you will receive the decryption key, even after payment. In addition, paying the ransom funds cybercrime and may make you a future target. If, after evaluating all other options, paying the ransom is considered the last resort, consult specialists in cybersecurity and ransomware negotiation. Use secure channels and document the entire process.
  4. Professional data recovery services: Companies specialized in data recovery may have advanced techniques and tools to recover data even in complex situations. Consider hiring a professional service if the other options are not viable or if the data is extremely critical. RansomHunter offers specialized services in incident response and data recovery for ransomware attacks, helping companies minimize impacts and resume operations.

Important: Before starting any recovery process, create a forensic copy (image) of the infected systems. This preserves evidence for later analysis and makes it possible to test different recovery methods without risking data loss.

Restoring operations: resuming company activities

Restoring normal company operations after a ransomware attack goes beyond simply recovering data. It is a process that involves rebuilding systems, verifying security, and gradually returning to business activities.

  1. System rebuilding: After data recovery, or in parallel if possible, begin rebuilding the infected systems. Format the hard drives of the compromised systems and reinstall operating systems and applications from secure and up-to-date sources. Avoid reusing systems that were directly infected without a complete format.
  2. Gradual service restoration: Restore services and systems gradually and in a controlled manner. Prioritize services that are critical to the company’s operation. Test each restored service before putting it into production.
  3. Security verification: Before reconnecting restored systems to the network, thoroughly verify the security of all systems and of the network as a whole. Apply security patches, configure firewalls, review access policies, and implement additional security measures to prevent new infections.
  4. Continuous monitoring: After restoration, implement continuous monitoring of the network and systems to detect any suspicious activity or remnants of the ransomware. Use security monitoring tools and perform log analysis regularly.
  5. Training and awareness: Reinforce team training and awareness regarding cybersecurity and ransomware. Conduct phishing simulations and other exercises to prepare employees to identify and avoid threats.

Restoring operations is a process that requires time, care, and attention to detail. Prioritize security at every stage to ensure a safe and resilient return to your company’s normal activities. RansomHunter offers consulting and specialized support to assist your company through every phase of post-attack recovery, from forensic analysis to the complete restoration of systems.

Frequently Asked Questions About Ransomware Recovery

Every day, ransomware attacks get
better and better. After a successful
attack attempt, ransomware quickly
maps the user’s most important files to
begin encryption. Microsoft Office files,
databases, PDFs and design are among
its main targets.

Yes, yet the ransomware is designed not to be identified by the firewall, so it can infiltrate the company’s internal system and disable defenses, move laterally, and alter backup routines. Get Expert Help to Decrypt Files › The user can identify the ransomware action, even if the system cannot identify it, the malware uses the system’s own resources for the encryption process, and may be slow to respond to user requests. The file extensions are changed, a specific extension is added that mentions the attacker group. Stay tuned for these signs.
Yes, it is possible. But there is a risk that some files will be corrupted. Once you identify the ransomware action on the system, disconnect the device from the internet, this will break the group communication with the malware, some ransomware can continue encryption even without internet access. You can also initiate antivirus countermeasures to isolate the malware and delete it, if the antivirus has not been disabled by the ransomware. Stopping the encryption is extremely difficult, the ransomware is designed to disable any system or user countermeasures, decreasing the chances of the process being interrupted. Get Expert Help to Decrypt Files ›
The attacks usually happen when there is a drop in the flow of users in the system, which happens on weekends and holidays, during the early hours of the morning, making these dates suitable for attacks. Get Expert Help to Decrypt Files ›
There are numerous encryption algorithms, but the most widely used are RSA [Rivest-Shamir-Adleman]-2048 and AES [Advanced Encryption Standard]. Get Expert Help to Decrypt Files ›
First of all, keep calm, criminals count on the victim’s desperation. Follow these tips:
  • Isolate the affected device – The ransomware can move laterally through the system and reach other devices, so it is important to isolate its field of action.
  • Verify backup – If the backup has not been reached by the ransomware, data can be quickly restored without major problems.
  • Avoid contact with criminals – Criminals use psychological tactics to extort as much money as possible in the shortest possible time, the fact that the victim is emotionally involved with the incident makes him an easy target.
  • Don’t negotiate with the criminals – The group gives no guarantee that the decryption key will be released after the ransom is paid, you have to take only the criminals’ word for it. Besides the payment will fund the group for further attacks.
  • Contact government authorities – The government has agencies that specialize in combating cyber attacks, which will investigate the case.
  • Contact a company that specializes in decrypting Ransomware files – RansomHunter is able to decrypt ransomware files without the need for the decryption key, their solutions are an option to paying the ransom.
Get Expert Help to Decrypt Files ›
After the first contact and sending of the data we will diagnose the files to check the extent of the damage caused by ransomware, with this we can project the duration of the process and provide the budget. After the client approves the budget, we start the decryption process, for this we have exclusive software that can, with the help of our specialists, reconstruct the data. After the end of the process we will do a double check so that the client can verify the integrity of the recovered files. Payment is only made after delivery of the files and validation of the same by the client. Get Expert Help to Decrypt Files ›

We Are Always Online

Fill in the form and we will make contact to you to start the decrypt of your files.
Always at your disposal, 24×7

The Latest Insights From Our Experts

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.