Blog / Security

The First 24 Hours After a Ransomware (Cryptolocker) Attack

Published: 2026 · Reading time: 7 min

If the extension of files on your computer or server has suddenly changed and a ransom note has appeared on the desktop, you have very likely been hit by a ransomware attack. This is a distressing situation, but if you avoid panicking and follow the right steps, the chance of recovering your files can be preserved — recovery has been achieved in many cases. Missteps taken in a moment of panic, however, can seriously reduce this chance. This article covers the steps to follow in the first 24 hours.

1. Disconnect From the Network Immediately

The affected device should be disconnected from the wired/wireless network immediately, to prevent the ransomware from spreading to other devices on the network. Keep in mind that shared drives, backup servers, and connected external disks may also have been affected.

2. Don't Shut Down the System — Isolate It

Fully shutting down the computer can, in some cases, erase traces the encryption process left in memory; instead, the device should simply be isolated from the network and, if possible, preserved in its current state.

3. Don't Pay the Ransom

Paying the ransom does not guarantee your files will be returned; in many cases, the decryption key is never sent after payment, or it doesn't work. Paying also financially strengthens the attackers and increases the risk of being targeted again.

4. Preserve the Ransom Note and Sample Encrypted Files

The ransom note left on the desktop or in folders, the pattern of the file extension change, and a few sample encrypted files play an important role in identifying the ransomware family and determining a possible recovery method.

5. Request a Professional Assessment

Not every ransomware family uses the same encryption strength; for some families, files can be recovered through known vulnerabilities. Requesting a professional analysis before shutting down the system, deleting files, or paying the ransom significantly increases the chances of recovery.

Common Mistakes

  • Trying to rename or "repair" encrypted files
  • Running free "decryptor" tools downloaded from the internet without verifying their reliability
  • Formatting the system (this can also destroy potential recovery data)
  • Continuing to keep the backup system on the same network without checking the backups first
Summary

The correct first steps in a ransomware attack: isolate the network, preserve the system as-is, do not pay the ransom, and request a professional analysis.

You are not alone; many users and organizations have been successfully supported through this process. For detailed information and a free preliminary analysis regarding Cryptolocker and ransomware recovery services, see the Cryptolocker / Ransomware Recovery page.

Have you been hit by a ransomware attack?

Request a free preliminary analysis before shutting down the system or paying the ransom.

Contact Us