Knowledge Base
Engineer Login
Back to Knowledge Base

Ransomware — What It Is and What to Do If You're Hit

Security / Antivirus ransomware virus malware attack backup recovery By Kerry · Updated 03/04/26 10:34 PM
Ransomware is malicious software that encrypts your files and demands payment to restore them. It's one of the most damaging cyber threats for small businesses. Warning signs you may be infected: - Files have changed to strange extensions (.locked, .encrypted, .crypto, etc.) - You can't open documents or photos - A ransom note appears on screen demanding payment in Bitcoin - Desktop background has changed to a ransom message - Files are being encrypted right in front of you (things are saving but becoming unreadable) What to do IMMEDIATELY if ransomware hits: 1. STOP — Do not click anything, do not pay the ransom 2. Disconnect from the network — unplug the network cable or turn off Wi-Fi RIGHT NOW. This stops the ransomware from spreading to other computers and shared drives 3. Do not turn the computer off — leave it exactly as is 4. Call us immediately at (269) 261-0269 — this is a critical emergency What we will do: - Isolate and assess affected machines - Determine the ransomware variant - Check if decryption tools are available (many ransomware variants have been cracked) - Restore from backups where available - Clean and restore affected systems Why you should NEVER pay the ransom: - There's no guarantee you'll get your files back - You'll be marked as a paying target and hit again - It funds criminal organizations Prevention — what we recommend: - Regular offsite backups (most important protection against ransomware) - MFA on all Microsoft 365 accounts - Up-to-date antivirus on all computers - Email filtering to block malicious attachments - Staff training to recognize phishing If you're not sure whether your backups are current, call us and we'll review your backup strategy.