What exactly happens during a ransomware attack?
During a ransomware attack, malicious software encrypts the files on your computer, server, or across your entire network. A ransom demand is then displayed, typically requiring payment in cryptocurrency (usually Bitcoin or Monero). A typical attack follows a recurring pattern:
Phase 1: Infiltration (days to weeks before encryption)
- Attackers gain access through phishing emails, compromised RDP connections, or software vulnerabilities
- They move laterally through the network, collecting credentials
- Backup systems are identified and deliberately compromised or deleted
- In double extortion attacks, sensitive data is also exfiltrated
Phase 2: Encryption (minutes to hours)
- The actual encryption is often triggered at night or on weekends
- Files receive new extensions (e.g.,
.locked,.encrypted,.crypted) - A ransom note is left as a text file or screen display
- Windows Shadow Copies and local backups are often automatically deleted
Phase 3: Extortion
- Ransom demands range from a few hundred dollars (individuals) to millions (enterprises)
- A time limit is set after which the amount increases or data is published
- Payment instructions direct to Tor-based websites
Important: Not every encryption is immediately visible. Some ransomware variants encrypt data gradually over weeks, meaning even older backups may already be compromised.
What immediate steps are critical during an attack?
The first minutes and hours after discovering a ransomware attack are decisive. Every second counts, as encryption may still be in progress:
Immediate action checklist:
- Disconnect from the network immediately
- Physically unplug network cables - Disable Wi-Fi - Disconnect VPN connections - But: Do NOT shut down systems (the encryption key may still be in RAM)
- Stop the spread
- Disconnect all other devices in the network - Shut down network switches if necessary - Immediately disable cloud synchronization (OneDrive, Dropbox, Google Drive)
- Preserve evidence
- Take screenshots of the ransom note - Document the ransomware file extension and name - Note timestamps of encrypted files - Save log files (Windows Event Log, firewall logs)
- Initiate communication
- Inform IT security personnel - Notify executive management - Contact external incident response specialists - Involve the data protection officer (GDPR notification obligations)
- File a police report
- Contact your national cyber crime unit - In the US: Report to the FBI's IC3 (ic3.gov) - In the EU: Report to your national CERT and law enforcement - In the UK: Report to Action Fraud and the NCSC
Learn more about forensic evidence preservation methods at How is evidence preserved in IT forensics?.
Should you pay the ransom?
The answer from international security authorities is unequivocal: No, do not pay. This position is jointly held by Europol, the FBI, Interpol, and national security agencies worldwide. The reasons are compelling:
| Argument Against Payment | Explanation |
|---|---|
| No guarantee of decryption | Only about 65% of paying victims receive all their data back |
| Funding criminal structures | Ransoms fund malware development and finance further attacks |
| Risk of repeat attacks | Paying victims become preferred targets for future attacks |
| Faulty decryptors | Even provided decryption tools often malfunction and corrupt data |
| Legal risks | Payments to sanctioned groups can have criminal consequences |
| Backdoors remain | Even after decryption, attackers may retain system access |
Exception scenarios: In extreme individual cases – such as when lives are at stake (hospitals) or a company's existence is threatened – payment may be considered as a last resort. However, this should always involve law enforcement and specialized negotiation experts.
Reality: Studies show that companies that pay have on average twice the total costs compared to those that do not, since in addition to the ransom, full restoration and security hardening of the IT infrastructure is still required.
Professional data recovery needed?
Request a data recovery quote now.
What decryption tools exist and how do you find the right one?
Professional data recovery needed?
Request a data recovery quote now.
Before giving up, check whether a free decryption tool exists for your specific ransomware variant:
No More Ransom (nomoreransom.org): The most important resource is the No More Ransom project, a collaboration between Europol, Dutch police, and IT security firms. The platform offers:
- Over 170 free decryption tools for various ransomware families
- A Crypto Sheriff that identifies the ransomware variant based on an encrypted file
- Regular updates when security researchers discover new vulnerabilities in ransomware
Additional sources for decryptor tools:
- Kaspersky NoRansom: Specialized decryption tools for variants like Rakhni, CoinVault, and Bitcryptor
- Emsisoft Decryptors: Large collection of decryptors, including for STOP/Djvu (the most common ransomware worldwide)
- Avast Free Ransomware Decryption Tools: Tools for various variants such as AES_NI, Babuk, or BTCWare
- Trend Micro Ransomware File Decryptor: Supports multiple ransomware families
Procedure:
- Identify the ransomware variant (file extension, ransom note, ransomware ID)
- Check nomoreransom.org via the Crypto Sheriff
- Download the appropriate tool if available
- Create a backup copy of the encrypted files first (a failed decryption attempt can further damage data)
- Perform the decryption
If no tool is available, preserve the encrypted files. New decryptors are regularly released when security researchers find vulnerabilities in the ransomware.
What alternative recovery methods exist?
Even when no decryption tool is available, several alternative paths to data recovery exist:
1. Windows Shadow Copies (Volume Shadow Copies / VSS)
Not all ransomware variants delete Windows Shadow Copies. Using tools like ShadowExplorer or the command vssadmin list shadows, you can check whether shadow copies still exist. If they do, earlier file versions can be restored.
2. Backup restoration
- Check all existing backups: Time Machine, Windows File History, NAS snapshots, cloud backups
- Ensure the backup was created before the infection time
- NAS systems with snapshot functionality may have older, unencrypted versions
- Even fragmentary backups can be valuable
3. Forensic RAM analysis If the affected system was not shut down, the encryption key may still reside in RAM. IT forensics specialists can dump the RAM and extract the key. This is time-critical and requires specialized expertise. Learn more at What is IT forensics and when is it used?.
4. Cloud versioning Services like OneDrive, Dropbox, and Google Drive store file versions. If the ransomware encrypted synchronized files, you may be able to access the unencrypted originals through versioning.
5. Professional data recovery Specialized data recovery labs have methods that go beyond the standard procedures mentioned above:
- File system forensics: Reconstruction of deleted or overwritten files at the block level
- Analysis of unencrypted areas: Some ransomware does not encrypt all file types or skips large files
- Reconstruction from temporary files: Many applications create temporary copies that may not have been encrypted
For details on forensic reconstruction, see Can tampered or deleted data be reconstructed?.
Where and how do you file a report after a ransomware attack?
Filing a police report is not only a legal obligation in many cases but also supports investigative work and can help other victims:
Reporting contacts by region:
- United States: FBI Internet Crime Complaint Center (IC3) at ic3.gov, local FBI field office, CISA (cisa.gov)
- European Union: National CERT, Europol's European Cybercrime Centre (EC3)
- United Kingdom: Action Fraud, National Cyber Security Centre (NCSC)
- Germany: Zentrale Ansprechstellen Cybercrime (ZAC), BSI, BKA
- International: Interpol for cross-border incidents
GDPR notification obligations: When personal data is affected, Article 33 GDPR requires notification to the relevant data protection authority within 72 hours of becoming aware of the incident. When there is a high risk to affected individuals, they must also be notified under Article 34 GDPR.
What to report:
- Type and variant of ransomware (if known)
- Time of discovery and estimated infection time
- Affected systems and data types
- Amount of the ransom demand and payment instructions
- Whether data was exfiltrated (double extortion)
- Screenshots and log files as evidence
Tip: Filing a police report can also be relevant for insurance claims. Many cyber insurance policies require a police report as a prerequisite for claims processing.
How does professional incident response work?
For a serious ransomware incident, professional incident response specialists should be engaged. The process follows a structured approach:
Phase 1: Containment
- Immediate isolation of affected systems
- Identification of the attack vector (How did the attackers get in?)
- Assessment of whether encryption is still active
- Preservation of all evidence for forensic analysis
Phase 2: Analysis and forensics
- Identification of the ransomware variant and version
- Determination of the infection timeline and propagation path
- Assessment of whether data was exfiltrated
- Search for decryption possibilities (RAM dump, known vulnerabilities)
- Evaluation of backup integrity
Phase 3: Recovery
- Cleanup of all compromised systems
- Rebuilding IT infrastructure from trusted sources
- Data restoration from backups, shadow copies, or through decryption
- Gradual return to operations under monitoring
Phase 4: Post-incident review (Lessons Learned)
- Documentation of the entire incident
- Identification and remediation of exploited vulnerabilities
- Adjustment of security measures
- Revision of the backup concept
For details on how professional data recovery works, see How does professional data recovery work?.
How do you identify a trustworthy ransomware recovery provider?
In the ransomware recovery space, unfortunately, unscrupulous providers also exist. Look for the following quality indicators:
Identifying legitimate providers:
- Transparent pricing: No legitimate provider promises guaranteed decryption at a fixed price
- No ransom payment as a service: Some providers secretly pay the ransom and pass off the decryption as their own work – this is dishonest
- IT forensics competence: The provider should have demonstrable experience in IT forensics and incident response
- Cooperation with authorities: Legitimate providers cooperate with law enforcement and recommend filing a police report
- Realistic assessment: A good provider will honestly tell you when recovery is not possible
Warning signs of illegitimate providers:
- Guarantee of complete data recovery
- Extremely low prices
- Pressure for quick decisions
- No verifiable expertise or references
- Discouragement from filing a police report
For general criteria on selecting a data recovery provider, see How to identify a trustworthy data recovery service.
How do you protect against future ransomware attacks?
After a ransomware attack, the probability of a repeat attack is elevated. Comprehensive prevention is therefore essential:
Immediate measures after the incident:
- Change all passwords across the entire organization (especially admin accounts, Active Directory)
- Enable multi-factor authentication (MFA) for all remote access and admin accounts
- Bring all systems to the latest patch level
- Secure or disable RDP access
Long-term protection measures:
- Implementation of a 3-2-1-1-0 backup strategy with offline copies
- Deployment of Endpoint Detection and Response (EDR) on all systems
- Network segmentation to limit lateral movement
- Regular phishing training for all employees
- Establishment of a Security Operations Center (SOC) or engagement of a managed security service
- Regular penetration testing to identify vulnerabilities
- Establishment of a tested incident response plan
For a detailed guide on ransomware prevention, see our article How to protect against ransomware.
Overview of ransomware attack costs:
| Cost Factor | Typical Range |
|---|---|
| Ransom (if paid) | $10,000–$5,000,000 |
| Business interruption | $50,000–$500,000 |
| Incident response and forensics | $20,000–$200,000 |
| IT restoration | $30,000–$300,000 |
| Reputational damage | Incalculable |
| GDPR fines | Up to 20 million euros or 4% of annual turnover |
Investing in prevention is always less expensive than dealing with a successful attack.
Tip: Has your data been encrypted by ransomware and you need professional help? Request a data recovery quote – specialized labs evaluate all available recovery options before payment is even considered.
Professional data recovery needed?
Request a data recovery quote now.