forumNew topic

Office workers' computers suddenly show only a black screen with 'decrypting' text — is it ransomware?

IIrmak Ö***ExpertCommunity member
Joined
Aug 2023
Message
153
#1

I was having my morning coffee when someone called saying 'bro my computer froze'. Then another person. Then 5-6 computers at once in the same state. There's red text on the screen: something like 'Your Files Are Encrypted, Pay 0.5 Bitcoin', not in Turkish. There's a phone number and email address, explaining the payment system. The whole file folder is locked, nothing works.

We have 50 computers on our network, now 15 of them have the same issue. I don't have a network admin, when I checked all files show 'locked' status. The data is important, I don't want to lose it. I checked if I have cyber insurance yes I do, but I don't know the claim process.

I'm gonna cut the internet connection but users want to keep working. Should I negotiate with the hackers? Or should I just wipe it immediately? I don't know what to do.

TTuğçe Y***Member
Job title
Quality Assurance Manager
Sector
Food wholesale
Organization type
regional distributor
Joined
Mar 2022
Message
329
Most Helpful#2

This is a Ransomware attack. IMMEDIATE steps (first 2 hours are critical): 1) Cut internet connection for the entire network (don't just turn off the switch, disable device access), 2) Close active connections from currently unaffected computers (backup server etc.), 3) Physically disconnect infected devices from the network (unplug cables), 4) Report to your cyber insurance company IMMEDIATELY (a few hours delay is vital), 5) Open local copy for ease, check backups to see if data was stolen (data exfiltration), 6) File a complaint with the police cyber crime unit (opening an official file is required for insurance claim), 7) Do not make any payments (even if paid, there's no guarantee of recovery, hackers have been reported in the media), 8) Call a forensic expert. Do not format these devices — evidence will be deleted.

MMustafa S***Member
Job title
Human Resources Manager
Sector
Jewelry
Organization type
two-branch business
Joined
May 2024
Message
43
#3

ransomware is really bad stuff man.. and shut down the network immediately dont pay. anyway i have some IT know-how call for forensic analysis, i checked later therees a recovery tool but it only worked on 3 folders...

edit: I wrote something wrong above, sorry about that.

NNazlı Ş***New member
Job title
Product Manager
Sector
Healthcare services
Organization type
20-person company
Joined
Jun 2026
Message
351

Doki · Infrastructure migration · 2023

#4

Identifying the ransomware vector is important: 1) Email phishing, 2) RDP exploit, 3) VPN vulnerability, 4) Supply chain (contractor), 5) USB portable media. Analyze the attacker's note (ransom note file, .txt) to determine the encryption algorithm. Some ransomware types (Wannacry, Petya etc.) have known decryption keys — you can use the ID Ransomware tool (id-ransomware.malwarehunterteam.com). Capture network logs: /var/log/auth.log, Windows Event Log (Eventid 4697, 4688).

FFiliz K***Member
Job title
Intern
Sector
Chemistry
Organization type
medium-sized business
Joined
Apr 2026
Message
35
#5

this is exactly why you do backups bro. or wait a sec... is this 0.5 bitcoin more valuable than the database? never pay, because they often don't unlock it and the police will cause you a lot of trouble too. cut the network immediately, restore from backup, done.

ÖÖzgür G***Member
Job title
Software developer
Sector
Cosmetics
Organization type
8-person team
Joined
Jun 2023
Message
16
#6

Ransomware prevention and response plan: 1) Immutable backups (3-2-1 rule: 3 copies, 2 media, 1 offsite), 2) Air-gapped backup system (disconnected from the network), 3) EDR (Endpoint Detection and Response) solution, 4) Zero Trust Network Access, 5) Incident Response Plan, 6) Cyber insurance. If this attack has already happened, you're not completely screwed — plan to restore from backup, check version histories, do incremental recovery.

OOkan E***Expert
Job title
QA Tester
Sector
Law
Organization type
early-stage startup
Joined
Feb 2022
Message
11
#7

Ransomware = 'Please end me' deadlock 😂 But seriously, shut down the network call the police, call insurance. anyway even if you pay the ransom, they won't unlock it and your email address is on 10 million other devices...

EElif Y***Member
Job title
Site Manager
Sector
Media and publishing
Organization type
20-person company
Joined
Mar 2024
Message
5
#8

Let me summarize what's been said so far. Everything goes well for the first three months; problems arise in the fourth.

Hasty decisions become decisions you have to fix six months later. If you post the result here, it will help others too.

FFiliz D***Expert
Job title
Customer service representative
Sector
Logistics
Organization type
cooperative
Joined
Jun 2023
Message
170
#9

i've been dealing with this for a long time. taking measures without an inventory leaves dors you haven't seen open.

just leaving this note it might be useful.

FFatma Ç***Member
Job title
Production Manager
Sector
Printing
Organization type
cooperative
Joined
May 2023
Message
27
#10

How did you solve this? Security isn't absolute; it's about making attacks not worth the effort.

SSelin C***Member
Job title
Secretary
Sector
Law
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
6
#11

Same here.

DDoruk T***MemberCommunity member
Joined
Jul 2023
Message
23
#12

Let me clarify the technical side. When you try to change everything at once nothing settles.

HHatice Ö***Member
Job title
Production Manager
Sector
Retail
Organization type
regional distributor
Joined
May 2022
Message
240

Doki · Log management setup · 2025

#13

We need to make a distinction here. Trying to do this alone is the most expensive way.

Taking measures without an inventory leaves doors you haven't seen open. Proven by experience.

MMeltemNew member
Job title
Bookstore
Organization type
cooperative
Joined
Sep 2024
Message
32
#14

There's a trap here, let me mention it. Taking measures without an inventory leaves doors you haven't seen open.

Good luck with that.

MMustafa E***MemberCommunity member
Joined
Feb 2024
Message
83
#15

I was thinking the same thing. If permission and scope aren't in writing, don't start that test.

Proven by experience.

GGizem A***Expert
Job title
Integration specialist
Joined
Sep 2023
Message
224
#16

Let me speak from the other side; I'm on the supplier side. The real issue isn't the number but what it's based on.

Just leaving this note, it might be useful.

EElif P***New member
Job title
Quality control inspector
Sector
Energy
Organization type
a company within a holding
Joined
Jul 2026
Message
130
#17

Just a heads-up. People defend habits, not processes. Resistance comes from there.

Taking notes for two weeks yields better results than a six-month estimate. Of course, it varies if your situation is different.

GGizem D***ExpertCommunity member
Joined
Feb 2024
Message
1
#18

Generally correct, but one part is missing. An untested backup is not a backup.

Start with a small trial; don't commit to everything at once. I'm also curious if anyone does it differently.

YYavuz G***Member
Job title
Courier coordinator
Sector
Packaging
Organization type
family business
Joined
Jun 2025
Message
45

Doki · Log management setup · 2023

#19

There's one point I'm curious about. Processes without records never improve, because you don't know what to fix.

If I were you, I'd go this route.

RRıdvan B***MemberCommunity member
Joined
May 2023
Message
180
#20

I've been dealing with this for a long time. The harder it is to reverse a decision, the slower you should make it.

I'm also curious if anyone does it differently.

Reply