Ransomware: What to Do When Your Files Are Encrypted
Security

Ransomware: What to Do When Your Files Are Encrypted

Reading 7 min · Security · by Yuna7

Your documents suddenly carry a strange extension, they refuse to open, and a message demands a cryptocurrency payment to "unlock" your files. That is ransomware. The next few minutes matter: here are the right moves to limit the damage and give yourself the best chance of getting everything back.

1. Isolate the machine at once

Ransomware tries to spread to other devices and shared drives. Cut the connection: unplug the Ethernet cable and switch off Wi-Fi. Also unplug any external hard drive, USB stick or NAS still attached. The goal is simple — stop the encryption from continuing and from reaching your backups.

2. Do not pay (at least, not yet)

Paying guarantees nothing: many victims never receive a key, or get a broken tool. Paying also funds the next attacks and marks you as an easy target. Before deciding anything, work through the options below. Reporting the incident to the authorities is strongly advised.

3. Identify the strain

Note the ransom note's filename, the new extension added to your files, and the wording of the message. The No More Ransom service (a project by Europol and security vendors) offers a tool that identifies the strain from an encrypted file and, for some families, a free decryptor. That is the first thing to check.

Screen showing security code
Every ransomware family has a signature: identifying it shapes everything that follows.

4. Look for shadow copies and version history

Windows sometimes keeps earlier versions of your files. Right-click a folder > Restore previous versions. If you use OneDrive, open the online recycle bin and the Version history feature: the cloud often keeps a clean copy from before the attack. Recent ransomware tries to wipe these copies, but it is always worth a try.

The only protection that truly works against ransomware is set up before the attack: an offline backup the virus cannot reach.

5. Restore from a clean backup

If you have an offline backup (an unplugged external drive, or cloud storage with versions), that is your strongest card. But do not restore onto a system that is still infected — clean the machine first.

6. Change your passwords

From a separate, clean device, change your important passwords (email, banking, cloud accounts). Some attacks steal credentials before they encrypt. Turn on two-factor authentication everywhere you can.

7. Take the lesson: the 3-2-1 rule

Afterwards, put a real strategy in place: three copies of your data, on two different types of media, with one kept offline or off-site. That is what turns a catastrophic attack into a mere inconvenience.

The shortcut: let Yuna7 do it

During an attack every minute counts, and a wrong move makes things worse. That is why we built Yuna7: you describe "my files are encrypted", the AI isolates connections, identifies the strain, hunts for recoverable versions and backups, and plans the cleanup — showing you every step. You approve anything sensitive, it acts.

Secure my PC with Yuna7

Read next