Home›Guides›What to do if…

What to do if…

Ransomware has just struck

If ransomware is encrypting your files, disconnect the machines from the network right away, do not shut them down without good reason, and restore nothing until the clean copy has been identified. The speed that matters is the speed that stops the spread, not the speed that reinstalls Windows within the hour.

Updated October 20264 min read6 sources cited

Key points

  • Cut Internet access and disconnect the affected machines: network cable and Wi-Fi. Do not shut them down; memory contains useful traces.
  • Do not pay: the French cybersecurity agency (ANSSI) points out that paying does not guarantee you will obtain a means of decryption.
  • Change passwords from a device that was not on the affected network.
  • File a complaint before reinstalling, report the incident to CERT-MU, inform your insurer and have a notification to the Data Protection Office assessed (72 hours).
  • Restore a copy taken before the intrusion, onto clean machines, never onto the still-infected network.

In the first few minutes

  1. Disconnect the network cables and Wi-Fi of the workstations and servers that are encrypting, or that can be reached from them. CERT-MU also recommends isolating infected systems from the network and cutting Internet access for the attacked network. A NAS that is still clean should also be disconnected if it is mounted on those machines.
  2. Do not shut down the affected machines: their memory holds traces useful to the investigation. ANSSI advises hibernation if encryption continues. Do not switch on healthy machines that were already off.
  3. Do not pay and do not reply to the ransom message before contacting management and, if you have one, your insurer. As ANSSI points out, paying does not guarantee you will obtain a means of decryption.
  4. Call the person who administers your systems and your backup provider. Tell them what has been disconnected.
  5. Photograph the ransom screen (group name, address, file extension). This helps with identification and with the insurer.
  6. Do not reformat. Encrypted disks may still contain untouched files and traces. Set them aside once isolated.
  7. Change the passwords for admin accounts, the VPN, email and the backup console from a phone or a computer that was not on the network, not from a PC that is still suspect.

Start an incident log right now: time, action, person. CERT-MU’s incident handling guideline asks for every action to be documented; investigators and the insurer will ask for it.

In the following hours

  • Set up a crisis unit, even a small one: management, IT, legal, communications. ANSSI stresses the importance of prepared crisis communication, both internal and external.
  • File a complaint with the Mauritius Police Force (Cybercrime Unit) before reinstalling the machines. Keep the logs, the ransom message and samples of encrypted files.
  • Notify your cyber insurer before any major restoration if the contract requires it.
  • Have a notification to the Data Protection Office assessed if personal data is affected. The Data Protection Act 2017 (section 25) requires the breach to be notified to the Data Protection Commissioner without undue delay and, where feasible, within 72 hours, via the eDPO portal; section 26 requires the individuals concerned to be informed where there is a high risk. Even without notification, the incident is recorded in the internal breach register. Your legal adviser confirms the case.
  • Report and get guidance: declare the incident on MAUCORS+, the national platform run by CERT-MU, which forwards the case to the competent institution. CERT-MU hotline: 800 2378. It is not a repair service that will restore your systems for you.
  • Find the start date: accounts created, scheduled tasks, first file extension. The backup to restore is older than that date.
  • Check that the backup console has not itself been emptied. If the copy is immutable or offline, it should still be there. ANSSI considers an offline backup essential, precisely for this scenario.

Who to notify: summary

WhoWhenWhy
IT and backup providerImmediatelyIsolation, state of the copies
ManagementImmediatelyDecisions, communication, ransom
Cyber insurerWithin the time limit set in the contractCover, appointed experts
Mauritius Police Force (Cybercrime Unit)Before reinstallationComplaint, investigation, evidence
Data Protection Commissioner (eDPO)Without undue delay, where feasible within 72 hoursData Protection Act 2017, section 25
Customers and partnersAfter management has decidedPrevent fraud and rumours

What not to do

  • Reconnect a workstation “just to see”.
  • Restore yesterday’s backup onto the still-infected server.
  • Run a decryptor downloaded at random: some are new malware. Legitimate tools are listed by the No More Ransom project, launched by Europol and security vendors.
  • Tell customers that “everything is sorted” before a verified restoration.

Next steps, once the emergency is contained, are covered in What to do after a cyberattack? and How do you restart your IT systems after ransomware?. If the attack took down a server, the restoration method is detailed in My server is down: what should I do?.

At WeDoBack

If the WeDoBack copies have not been erased, they are stored on servers dedicated to backup, separate from production, and encrypted with the customer’s key. The IMMUTABLE offer, if it covers the period, prevents these copies from being deleted. The DRP lets you restart your servers on standby instances from the version you choose; activation in a disaster is billed per day. Call +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time), i.e. from 11:00 to 15:00 and from 16:00 to 19:30 Mauritius time during European summer time (one hour later in winter), having already isolated the machines: the backup provider cannot unplug your cables remotely. The encryption key must be known to someone who can be reached: without it, no restoration is possible.

Frequently asked questions

Should encrypted machines be shut down?

As a general rule, no. CERT-MU stresses preserving evidence before any recovery: disconnect the affected machines from the network without shutting them down. ANSSI, France’s cybersecurity agency, suggests hibernation if encryption is still running. Healthy machines that were already off, on the other hand, stay off.

Should we pay the ransom to get our data back?

Cybersecurity agencies advise against it, as ANSSI does in France. Paying guarantees neither the key, nor that it will work, nor that there will be no further attack, and it funds the attackers. The decision lies with management, but it is not made in a minute, and never without first checking the state of the backups.

Who must be notified, and how quickly?

Your IT provider and your backup provider immediately, your cyber insurer within the time limit set in the contract, and the Mauritius Police Force (Cybercrime Unit) by filing a complaint before reinstallation. If personal data is affected, the Data Protection Commissioner must be notified without undue delay and, where feasible, within 72 hours (Data Protection Act 2017, section 25). The incident should also be reported to CERT-MU on MAUCORS+ (hotline 800 2378).

Can we use a free decryption tool?

Only if it comes from a reliable source: the No More Ransom project, launched by Europol and security vendors, lists tools for certain ransomware families. A “decryptor” downloaded at random may itself be new malware.

Need help now?

Do not restore anything until you have identified a clean copy. We can guide you.

Call +33 9 72 50 78 28or write to us

Dealing with an incident right now?

Our teams help you identify the right copy and restore it, Monday to Friday, 9 am to 1 pm and 2 pm to 5:30 pm (Paris time).