Open navigation

My Network Was Just Hacked With Ransomware. What Should I Do?

  1. Find the RJ45 Ethernet plug in back of the computer and disconnect the plug
    1. If a wireless connect, right click the wireless icon in system tray and choose to disconnect, then disable the wireless adapter

    2.  
    3. Where do you plug an Ethernet cable into a computer? - Quora
  2. Call someone in IT or knowledgeable person who can help
    • Who can you call for help in Ohio?  First line of help is
      1. Terin D Williams - This security advisor can walk you through the steps on mitigating the attack but is not allow to access your network (only State agencies)
        Cyber Security Advisor for the State of Ohio
        [email protected] 
        614-314-7793
      2. The Ohio Cyber Reserve has a volunteer staff that can also assist with Cyber breaches, but they may take a day or two before responding
         https://www.ong.ohio.gov/special-units/cyber/ohcr/index.html
        Craig W Baker
        [email protected]

  3. Leave your computer running
    1. Some tools can find the encryption key if the computer is still running

  4. If you have a backup appliance or back up hard drive, remove it from the network and/or machine to ensure it is safe

  5. Check other systems on the same subnet, if in doubt, unplug systems from the subnet/ switch

  6. Capture a screen shot of the ransomware notice.  Do not turn off machine.

  7. Find the name of the ransomware from your screenshot

  8. Some Keys are available for Ransomware, contact your local FBI or here: https://www.ic3.gov/Home/FileComplaint

  9. Call SEO Service Center to inform us so we can monitor our database

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article