PanicStation.org
uk Technology & digital loss

What to do if…
you find a ransom note or encrypted files on your computer

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Stop using the computer and isolate it by disconnecting it from Wi-Fi, ethernet, mobile hotspot, and any shared network before you do anything else. Use a different, trusted device to get help, secure key accounts, and report it.

Do not do these things

  • Don’t pay or message the attackers in a rush; get advice first.
  • Don’t follow links, email addresses, Telegram contacts, “support” chats, or instructions in the note.
  • Don’t plug in backup drives, memory sticks, phones, or other storage devices to “copy things off”.
  • Don’t restore from backups yet.
  • Don’t randomly delete files, wipe the device, or run unknown “decryptor” or “cleaner” tools.
  • Don’t sign into email, banking, work, cloud storage, or password-manager accounts from the affected computer.
  • Don’t reconnect the computer to the internet just to check whether the problem has gone.

What to do now

  1. Isolate the device immediately.
    Turn off Wi-Fi, unplug any ethernet cable, disconnect from any mobile hotspot, and remove the device from shared folders or network storage if you can do that without reconnecting. If files are visibly changing fast and you cannot quickly disconnect it, shut the device down rather than continuing to use it.

  2. Disconnect attached storage and reduce spread.
    Unplug external hard drives, USB sticks, memory cards, phones, cameras, and any other storage devices. If you use a NAS, shared folder, or cloud-synced folder, leave it alone for now and make a note that it may have been exposed.

  3. Capture the minimum evidence safely.
    Do not click anything in the note. Take photos of the ransom note, the filename, any changed file extensions, and any message on the desktop or lock screen. Write down the date and time you first noticed it and which folders or drives look affected.

  4. Use a different, trusted device for accounts.
    From a clean phone, tablet, or computer, change the password for your main email first, then your bank, Apple, Google, Microsoft, cloud storage, and password manager accounts. Turn on multi-factor authentication where available, and do not reconnect the affected computer to do this.

  5. Do a quick offline impact check only if it is safe.
    While the affected computer stays offline, check only a few files in different folders to see whether they open normally or have strange names or extensions. Stop once you have enough information to describe what happened.

  6. If it is a work, school, or managed device, stop and escalate.
    Contact your IT or security team immediately using a phone or a different device. Do not attempt DIY cleanup, password changes on the managed device, or backup restoration unless they tell you to.

  7. Report it through the UK routes.
    For most people and small organisations, report cyber crime and fraud online through Report Fraud. The Report Fraud phone number is 0300 123 2040; public phone reporting is generally Monday to Friday, 8am to 8pm, while businesses, charities, and other organisations suffering a live cyber attack can call that number immediately at any time. UK organisations can also use the GOV.UK cyber incident signposting service and, where appropriate, the NCSC incident reporting portal.

  8. Consider personal data and money risk.
    If the device held customer, client, staff, patient, pupil, or other personal data, check whether a report to the ICO is needed. If a personal data breach is likely to risk people’s rights and freedoms, reporting to the ICO is generally required as soon as possible and, where feasible, within 72 hours. If banking, shopping, or card details may have been used or saved on the affected computer, contact your bank’s fraud line from a clean device.

What can wait

  • You do not need to decide today whether you will ever pay; focus on isolation, account security, and reporting first.
  • You do not need to reinstall, wipe, or replace the computer immediately.
  • You do not need to restore from backups yet; only restore once the device and backup are known to be clean.
  • You do not need to contact everyone at once; start with email, banking, work or school IT if relevant, and any account that can reset other accounts.
  • You do not need to understand the malware name before taking these first steps.

Important reassurance

A ransom note is designed to make you hurry. Disconnecting the device, avoiding the attacker’s instructions, and using a clean device are strong first moves that help stop the situation getting worse while you get proper help.

Scope note

These are first steps to reduce harm and buy time. Recovery, cleanup, file restoration, data-theft checks, and decisions about reporting or notification may need specialist cybersecurity, legal, insurance, or organisational support.

Important note

This guide is general information, not legal, financial, professional cybersecurity, or other professional advice. If the device contains sensitive personal data, belongs to an organisation, or affects work or school systems, get qualified help promptly and follow the relevant incident process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us