Skip to main content
株式会社オブライト
Business DX2026-07-225 min read

Suspected Ransomware? Your First 30 Minutes, Step by Step

Files won't open and a ransom note appears — here are the first three things to do, what never to do, and who to call, explained step by step.


Files won't open, extensions look wrong, or a ransom note has appeared on screen — if you suspect ransomware, do three things immediately: disconnect from the network (do not power off), don't touch anything else, and call a specialist. Below are concrete steps for each, plus a list of things you should never do right after an infection.

Three things to do in the first 30 minutes

- 1. Disconnect from the network: unplug the Ethernet cable or turn off Wi-Fi. Do not power off the machine
- 2. Don't touch anything: don't open files, don't reboot, and don't follow instructions on any ransom screen
- 3. Call a specialist: notify your internal IT contact or maintenance vendor first, then escalate to a public advisory service or police cybercrime unit if needed

Signs your systems may be infected

- File extensions have changed to something unfamiliar
- The desktop wallpaper or screen has been replaced with a ransom demand
- Files won't open, or large numbers of files are being modified or encrypted at once
- Unfamiliar pop-ups or threatening messages appear
- The machine suddenly slows down, or network traffic spikes abnormally
- Files on shared folders or file servers also stop opening at the same time

Things you must never do

- Force a shutdown: this can erase information in memory that would otherwise help investigate the scope of infection or recovery options
- Contact the attackers or pay the ransom: payment is no guarantee of decryption, and paying has in some reported cases led to being targeted again
- Run a free decryption tool on your own judgment: misidentifying the ransomware variant can permanently destroy files beyond any possibility of recovery
- Delete or overwrite logs and files: this destroys evidence that may be needed to determine the scope of damage or for any later investigation

How to actually disconnect from the network

- Wired connections: physically unplug the Ethernet cable from the machine
- Wi-Fi connections: turn off Wi-Fi in the OS settings (enable airplane mode too if you're unsure)
- Shared folders or NAS: stop other devices from accessing the affected folder, and disconnect the NAS itself from the network if possible
- Cloud sync (OneDrive, Google Drive, etc.): pause syncing to prevent encrypted files from propagating to other devices or the cloud
- Other devices on the same network: temporarily disconnect them too, to prevent the damage from spreading beyond the infected machine

Who to call, and for what

ContactWhen to use itHow to find itNotes
Your maintenance vendor or internal IT contactTo share the situation and get a first-response judgmentThe contact listed in your service contract or invoicesActs as the command center for initial response
A national information security advisory hotline (e.g. Japan's IPA)For technical advice and to assess the scope of damageListed on the agency's official websiteProvides free expert advice
Police cybercrime consultation deskTo discuss filing a report, or when an investigation may be neededYour regional police cybercrime consultation deskCan also advise on preserving evidence
Your cyber insurance providerIf you carry cyber insuranceThe emergency contact on your policy documentsThe insurer may dispatch a designated responder covered by the policy

Before deciding to restore from backup

Having a backup doesn't mean you should restore it right away. If the infection source and scope haven't been identified yet, restoring can simply let the same vulnerability get exploited again. It's best to work with your maintenance vendor or a specialist first to (1) identify and remove the infection source, (2) confirm the backup itself isn't compromised, and (3) put monitoring in place after restoration. If you keep multiple backup generations, check whether you can select one from before the infection occurred.

What to do afterward

Once the immediate response has settled down, you'll need to assess the full scope of the incident and work on preventing a recurrence. If personal or client data may have been exposed, our related guide on what to do when a data breach is discovered covers those steps, and our ransomware basics guide for small businesses covers background and everyday preparedness.

Frequently asked questions

If I pay the ransom, will I get my files back?

Payment is no guarantee of decryption, and there are reported cases where paying led to being targeted again. Consult a specialist advisory service or your local police cybercrime unit before making any decision.

What if I don't have a backup?

Contact your maintenance vendor or a security specialist first and prioritize identifying and removing the infection. Whether files can be recovered requires expert diagnosis, and you should avoid running decryption tools on your own judgment.

What if I don't know who to contact internally?

If you have no dedicated IT staff, contact your maintenance vendor or IT provider first. If you have no such contract, a public information security advisory hotline can provide initial technical guidance.

How quickly do I need to respond?

Because an infection may keep spreading over time, disconnecting from the network the moment you notice something wrong is the top priority. The more detailed response that follows typically takes hours to days, guided by specialist advice.

Feel free to contact us

Contact Us