Confirmation and isolation: critical first steps when facing ransomware
When there is a suspected ransomware attack, speed and accuracy in the first actions are decisive for minimizing damage and containing the spread of the threat. Do not panic, but act quickly and methodically. The first moments are crucial for incident response.
Identifying a ransomware attack: initial signs
Recognizing a ransomware attack as quickly as possible is the first step toward an effective response. Pay attention to the signs that may indicate a possible infection:
- Files with strange extensions: Suddenly, your files have unknown extensions such as “.locky”, “.crypt”, “.encrypted”, or other variations. This is a strong indication of ransomware encryption.
- Ransom messages: Text files (.txt, .html) or pop-up windows appear with instructions on how to pay a ransom to recover your data. These messages usually contain alarming language and deadlines.
- Unusual system slowness: Your computers and servers start operating extremely slowly, even for simple tasks. Background encryption consumes a large amount of system resources.
- Difficulty accessing files: You or your employees can no longer open documents, spreadsheets, images, or other important files that were previously accessible.
- Antivirus alerts: Your antivirus software may detect and alert you about a malicious file or suspicious behavior related to ransomware. Do not ignore these alerts!
If you notice one or more of these signs, consider the possibility of a ransomware attack and proceed with caution. Confirmation and isolation are the next essential steps.
To deepen your knowledge about threat identification, explore resources such as the CERT.br Malware Guide, which provides valuable information about various types of malware, including ransomware.
Isolating infected systems: containing the spread of ransomware
Once you suspect or confirm a ransomware attack, immediately isolating the affected systems is essential to prevent the malware from spreading to other devices and to the network as a whole. Follow these actions to isolate compromised systems:
- Network disconnection: Immediately disconnect infected computers and servers from the network. This means unplugging network cables (Ethernet) and disabling Wi-Fi. The goal is to prevent the ransomware from spreading through the local network and the internet.
- Shutdown (with caution): In many cases, shutting down the infected system may be necessary to interrupt encryption. However, before shutting it down, document everything you can: take photos of the screen, copy error messages, and note the names of affected files. Avoid restarting the infected system, as this can make subsequent forensic analysis more difficult.
- Physical isolation: If possible, move infected devices to a physically isolated location, away from the common work area, to avoid any accidental connection or contamination of other equipment.
- User account deactivation: If you identify user accounts that have been compromised, temporarily disable them to prevent the attacker from accessing other systems.
Remember: rapid isolation is your first line of defense against a ransomware attack. By containing the spread, you gain time to assess the situation and plan the next steps.
Damage assessment and notification: measuring the impact and communicating the incident
After isolating the affected systems, the next crucial step is to assess the extent of the damage caused by the ransomware attack and notify the relevant parties. This stage is essential for understanding the impact of the incident and initiating recovery and legal response processes.
Assessing the scope of the ransomware attack: identifying the real impact
With the systems isolated, focus on assessing the scope of the ransomware attack. This detailed evaluation will help determine the severity of the situation and prioritize recovery actions. Consider the following points:
- Identification of affected systems: Which computers, servers, laptops, and devices were hit by the ransomware? Create an accurate inventory of the compromised systems.
- Types of encrypted data: What types of files were encrypted? Important documents, databases, emails, customer files, financial data? Identifying the affected data is crucial for assessing the operational and financial impact.
- Extent of encryption: What percentage of the data was encrypted? Was the attack contained in time, or were most critical data assets compromised?
- Attack vector: How did the ransomware enter your network? Was it through a phishing email, a software vulnerability, a weak password, or another method? Understanding the attack vector is essential for preventing future incidents.
- Log analysis: Examine system logs, firewalls, and other security tools to obtain more information about the attack, such as timestamps, source IPs, if possible, and other relevant details.
An accurate assessment of the scope of the ransomware attack will provide a solid basis for making informed decisions about data recovery, negotiation, if considered, and future security measures. In many cases, it may be useful to rely on cybersecurity specialists to perform a detailed forensic analysis.
Notifying authorities and partners: responsibility and transparency
After assessing the damage, it is crucial to notify the competent authorities and relevant partners about the ransomware attack. Notification demonstrates responsibility and transparency, in addition to being fundamental for combating cybercrime and protecting your stakeholders.
Who should be notified?
- Law enforcement authorities: File a police report at a police station or a unit specialized in cybercrime. At the national level, you may consider notifying the Federal Police (NUCCIBER). Notifying the authorities is important for investigations and for the broader mapping of cyberattacks.
- Data protection authorities: If the ransomware attack involved personal data from customers or employees, you may have legal obligations to notify the National Data Protection Authority (ANPD), in accordance with the General Data Protection Law (LGPD).
- Business partners: Inform relevant business partners, especially if the ransomware attack could affect them in any way, such as in cases involving data sharing or dependence on interconnected systems.
- Customers and users: Depending on the nature of the attack and the affected data, it may be necessary to communicate the incident to your customers and users, especially if personal information has been compromised. Transparency builds trust.
- Insurance provider: If your company has cyber insurance, notify the insurance provider as soon as possible. They may offer financial and technical support for the incident response.
- Internal team and stakeholders: Keep your internal team informed about the situation, especially the IT, legal, communications, and senior management departments. Also communicate with relevant stakeholders, such as investors and board members.
Timely and transparent notification shows that your company is acting responsibly and proactively in response to the ransomware attack. Cooperate with the authorities and follow their guidance to mitigate impacts and strengthen security.
Data recovery and restoration: strategies to minimize losses
After confirming, isolating, and assessing the damage caused by the ransomware attack, the top priority is data recovery and the restoration of normal company operations. This is a delicate process that requires planning and technical expertise.
Exploring data recovery options after a ransomware attack
Recovering data encrypted by ransomware is a challenge, but there are some options to consider. The best strategy will depend on the nature of the attack, the availability of backups, and other specific circumstances.
- Restoration from backups: If your company has regular, up-to-date backups that are isolated from the network (offline backups), this is the most recommended and effective option. Restore the data from the most recent and intact backup. Make sure the backups were not affected by the ransomware. Verify backup integrity before starting the restoration.
- Decryption tools: In some cases, free decryption tools may be available for certain ransomware variants. Organizations such as No More Ransom!, a joint initiative by Europol, the Dutch National Police, McAfee, and Kaspersky, offer useful tools and information. Check whether a decryption tool exists for the ransomware variant that affected your company.
- Negotiation and ransom payment (last resort and with caution): Paying the ransom is a controversial decision and is generally not recommended. There is no guarantee that you will receive the decryption key, even after payment. In addition, paying the ransom funds cybercrime and may make you a future target. If, after evaluating all other options, paying the ransom is considered the last resort, consult specialists in cybersecurity and ransomware negotiation. Use secure channels and document the entire process.
- Professional data recovery services: Companies specialized in data recovery may have advanced techniques and tools to recover data even in complex situations. Consider hiring a professional service if the other options are not viable or if the data is extremely critical. RansomHunter offers specialized services in incident response and data recovery for ransomware attacks, helping companies minimize impacts and resume operations.
Important: Before starting any recovery process, create a forensic copy (image) of the infected systems. This preserves evidence for later analysis and makes it possible to test different recovery methods without risking data loss.
Restoring operations: resuming company activities
Restoring normal company operations after a ransomware attack goes beyond simply recovering data. It is a process that involves rebuilding systems, verifying security, and gradually returning to business activities.
- System rebuilding: After data recovery, or in parallel if possible, begin rebuilding the infected systems. Format the hard drives of the compromised systems and reinstall operating systems and applications from secure and up-to-date sources. Avoid reusing systems that were directly infected without a complete format.
- Gradual service restoration: Restore services and systems gradually and in a controlled manner. Prioritize services that are critical to the company’s operation. Test each restored service before putting it into production.
- Security verification: Before reconnecting restored systems to the network, thoroughly verify the security of all systems and of the network as a whole. Apply security patches, configure firewalls, review access policies, and implement additional security measures to prevent new infections.
- Continuous monitoring: After restoration, implement continuous monitoring of the network and systems to detect any suspicious activity or remnants of the ransomware. Use security monitoring tools and perform log analysis regularly.
- Training and awareness: Reinforce team training and awareness regarding cybersecurity and ransomware. Conduct phishing simulations and other exercises to prepare employees to identify and avoid threats.
Restoring operations is a process that requires time, care, and attention to detail. Prioritize security at every stage to ensure a safe and resilient return to your company’s normal activities. RansomHunter offers consulting and specialized support to assist your company through every phase of post-attack recovery, from forensic analysis to the complete restoration of systems.



