forumNew topic

We got hit by ransomware — writing about the process and lessons learned

OOrhanMember
Job title
IT company
Joined
Oct 2023
Message
132

Doki · Vulnerability scanning · 2026

#1

Had an incident at a client's site, posting with their permission and without naming names. Not trying to scare anyone, just showing how the process works.

Noticed it on a Friday night. File extensions on the file server had changed and a text file was dropped in every folder.

First thing we did was right: didn't shut down systems, just isolated them from the network. Shutting down destroys memory evidence, isolating stops the spread.

Then we answered three questions in order: where did they get in, how far did it spread, is our backup clean.

The answer to the first question wasn't what we expected. No vulnerability. There was a remote desktop connection open to the outside and a user's password had leaked from somewhere else. So not a technical flaw, just an open door.

The backup question saved us, but barely. Daily backups were being taken, but the backup server was on the same network and accessible with the same credentials. The only reason it wasn't encrypted is that the process was stopped before it finished that night.

DDefneMember
Job title
SOC Analyst
Organization type
a company within a holding
Joined
Feb 2024
Message
146
Most Helpful#2

Thanks for this post, incident reports are rare and these are the most educational.

Your first response decision was correct. Let me explain: on a running system, memory can contain active processes, network connections, and sometimes the encryption key itself. Shutting down wipes all that. Isolating from the network stops the spread and preserves evidence.

Entry via remote desktop with a leaked password isn't an exception either, it's actually one of the most common scenarios. So it's worth repeating these three things: don't leave remote desktop open to the outside, if you have to, definitely add 2FA, don't use admin accounts for daily tasks.

The backup part is the real lesson. Most ransomware now looks for backups as its first move. Having backups on the same network and accessible with the same identity makes the backup part of the target.

Actionable rule: keep at least one backup copy separate, inaccessible and immutable using the main system's credentials. Also, regularly test restoring from backup, just seeing that it's taken isn't enough.

İİsmailMember
Job title
System administrator
Joined
Dec 2023
Message
128
#3

We had the same incident two years ago. Only difference: our backup wasn't clean.

Production stopped for three days. Now the backup copy sits separately and immutably. Was an expensive lesson.

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
#4

I'd like to add a few points on the management side of incident response, because this side shapes the process just as much as the technical response.

First, who makes the call must be defined in advance. If it's unclear who to ask "should we stop the system" during an incident, hours are lost.

Second, communication plan. What to tell employees, when to inform customers, and how to fulfill legal notification obligations if needed should be written beforehand. If personal data is affected, consult regulations and your legal team for notification deadlines and procedures; these deadlines are short.

Third, the ransom payment decision. I want to emphasize that this is not a technical decision, but a top management and legal one. Payment doesn't guarantee data recovery and can create separate legal risks.

Fourth, the post-incident report. After the heat dies down, everyone goes back to normal and lessons aren't written down. An incident report not written within a week never gets written.

OOnurExpert
Job title
Security developer
Joined
Oct 2023
Message
196
#5

I want to poke at one point: you're saying "there were no vulnerabilities." How did you verify that?

I'm not asking out of malice. In most incidents, the first entry point found is assumed to be the correct one and the investigation stops there. But attackers usually leave behind multiple persistence methods.

Specific question: after the user logged in with a leaked password, did you check if any other accounts were created on the system, if scheduled tasks were added, or if remote access tools were installed? It's not uncommon for systems thought to be clean to be breached again three weeks later.

OOrhanMember
Job title
IT company
Joined
Oct 2023
Message
132

Doki · Vulnerability scanning · 2026

#6

Fair question, let me answer.

We checked. An independent team investigated for two weeks. Two scheduled tasks and one locally created admin account created later were found. Both were missed during the initial cleanup.

That's why I want to add this: the decision to clean up shouldn't be made by the team experiencing the incident. The team, tired and in the middle of the incident, tends to be biased toward validating their own findings. If possible, have an outside perspective.

In the end, we reinstalled the affected machines from scratch. It was slower but a more certain path.

KKaan B***Member
Job title
Infrastructure engineer
Joined
Mar 2024
Message
108
#7

From an infrastructure perspective, let me suggest a concrete backup structure, because "keep it separate" is a bit abstract.

A common and effective setup is this: have at least three copies of the data, store them in at least two different environments, and keep at least one copy completely offsite. Additionally, making that offsite copy immutable after writing is crucial in a ransomware scenario.

Also, measure your recovery time. The statement "we have backups" is not as valuable as "we can be up and running in eight hours." If you don't know the latter, try it on a Saturday.

ZZeynep K***MemberCommunity member
Joined
Feb 2024
Message
41
#8

I'm a small business, let me explain from my side. Most time waste accumulates in tasks waiting for approval.

An automated scan report is not the same as a penetration test. Proven by experience.

EEmre G***ExpertCommunity member
Joined
Jul 2024
Message
409
#9

Thanks for writing this, that's the right way. If it's your first time, start small; scaling comes later.

Correct me if I'm wrong.

DDoruk Y***VeteranCommunity member
Joined
Dec 2023
Message
69
#10

You're right. If permission and scope aren't in writing, don't start that test.

Of course, it varies if your situation is different.

MMeryem Ö***Member
Job title
Export manager
Sector
Cleaning services
Organization type
40-person manufacturing company
Joined
Feb 2024
Message
13
#11

How did you solve this? An untested backup is not a backup.

I'm also curious if anyone does it differently.

YYusuf Y***Member
Job title
Social media manager
Sector
Real estate
Organization type
a company within a holding
Joined
Sep 2024
Message
79
#12

This thread is archived.

PPerihan K***Member
Job title
Product Manager
Sector
Catering
Organization type
20-person company
Joined
Feb 2024
Message
220

Doki · Corporate website · 2024

#13

Correct.

BBurcu N***Member
Job title
Board member
Sector
Cosmetics
Organization type
20-person company
Joined
Nov 2025
Message
2
#14

Id appreciate it if you shared the outcome.

ÖÖzge Y***MemberCommunity member
Joined
Feb 2023
Message
110
#15

My perspective changed after experiencing that... Payment information changes are never verified through the channel they came from.

That's all, sorry if I went on too long.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#16

A small warning: the method shared above should be tested on your own system, not someone else's. Unauthorized testing goes beyond a technical issue.

CCanMember
Job title
SEO Specialist
Joined
Mar 2024
Message
172
#17

I've been down this road, let me tell you. When we decide without measuring, we always end up in the same place.

If you have questions, write them; I'll answer as best I can.

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#18

I felt relieved reading this answer, so it's not just me. Everything goes well for the first three months; problems arise in the fourth.

Correct me if I'm wrong.

SSedaNew member
Job title
Teacher · side hustle
Organization type
cooperative
Joined
Oct 2024
Message
42
#19

im a small business let me explain from my side but everything goes well for the first three months; problems arise in the fourth.

the answer varies greatly by industry; there is no one-size-fits-all rule.

FFatma U***Member
Job title
Site Manager
Sector
Sports and fitness
Organization type
two-branch business
Joined
Jan 2025
Message
96
#20

Just a heads-up. If permission and scope aren't in writing don't start that test.

Don't rely on a single measure; go layer by layer. If you have questions, write them; I'll answer as best I can.

Reply