Ransomware — What It Is and What to Do If You're Hit
Security / Antivirus
ransomware
virus
malware
attack
backup
recovery
By Kerry · Updated 03/04/26 10:34 PM
Ransomware is malicious software that encrypts your files and demands payment to restore them. It's one of the most damaging cyber threats for small businesses.
Warning signs you may be infected:
- Files have changed to strange extensions (.locked, .encrypted, .crypto, etc.)
- You can't open documents or photos
- A ransom note appears on screen demanding payment in Bitcoin
- Desktop background has changed to a ransom message
- Files are being encrypted right in front of you (things are saving but becoming unreadable)
What to do IMMEDIATELY if ransomware hits:
1. STOP — Do not click anything, do not pay the ransom
2. Disconnect from the network — unplug the network cable or turn off Wi-Fi RIGHT NOW. This stops the ransomware from spreading to other computers and shared drives
3. Do not turn the computer off — leave it exactly as is
4. Call us immediately at (269) 261-0269 — this is a critical emergency
What we will do:
- Isolate and assess affected machines
- Determine the ransomware variant
- Check if decryption tools are available (many ransomware variants have been cracked)
- Restore from backups where available
- Clean and restore affected systems
Why you should NEVER pay the ransom:
- There's no guarantee you'll get your files back
- You'll be marked as a paying target and hit again
- It funds criminal organizations
Prevention — what we recommend:
- Regular offsite backups (most important protection against ransomware)
- MFA on all Microsoft 365 accounts
- Up-to-date antivirus on all computers
- Email filtering to block malicious attachments
- Staff training to recognize phishing
If you're not sure whether your backups are current, call us and we'll review your backup strategy.