forumNew topic

We just got hacked: what should we do in the first hour of a cyberattack?

FFerhat E***MemberCommunity member
Joined
Nov 2025
Message
134
#1

We are a 14-person logistics and customs consulting office in Paris. About 45 minutes ago, we noticed that all shared folders on our primary file server were locked and file extensions were completely unrecognizable. Ransom note text files appeared on desktops, leaving an anonymous email address to get in touch. Our accounting records and client customs paperwork are completely inaccessible right now.

The team is in full panic mode. Our accountant is trying to yank computer power cords out of the wall, while our office manager wants to plug yesterday's external hard drive backup straight into the main machine and restore it immediately. I honestly don't know what to do; I'm terrified that a wrong step taken in panic will wipe our data permanently or spread the attack further.

We're in the critical first hour and can't afford to mess up. Which devices should we isolate first and how? How do we stop the attack without destroying evidence, and when should we start notifying legal authorities or clients?

RReyhan G***Veteran
Job title
Finance Manager
Sector
Cleaning services
Organization type
boutique agency
Joined
Nov 2024
Message
250
Most Helpful#2

Short answer: Do not shut down or pull the plugs on your devices; instead isolate them from the network solely by unplugging Ethernet cables and turning off Wi-Fi. Abruptly killing power permanently destroys traces of the attacker in volatile memory (RAM), active connections, and potentially even decryption keys.

Your top priority right now is isolation. Disconnect both affected and unaffected machines from the network. Absolutely do not plug the external backup drive into the current system; if ransomware is still running, it will encrypt that external drive within seconds. Keep your backups offline and physically segregated until their integrity is confirmed.

Step two is preserving evidence. If you have the internal technical chops take a RAM dump of any running machines, then put them into hibernation rather than shutting down so memory is written to disk. Do not run any cleanup tools or delete suspicious files. Since you operate in France, you will need to report this to the authority (CNIL) within the statutory notification window regarding potential personal data breaches. That said establish a clear picture of the breach's scope and prepare a calm crisis communication strategy before alerting clients and authorities.

Do not reply to the address in the ransom note right away. Entering negotiations with extortionists without retaining a professional digital forensics expert or incident response team will only make things messier.

BBurcu A***MemberCommunity member
Joined
May 2024
Message
146
#3

Pulling the plug is the biggest mistake you can make. The attacker may have left in-memory malware sitting in volatile RAM. Disable network adapters, pull the ethernet cable, cut internal access at the router, but leave the machine powered on.

MMelis K***VeteranCommunity member
Joined
Dec 2025
Message
26
#4

Stop whoever wants to plug in the backup drive right now. The first-hour rule is simple: contain the spread first, assess the damage second. Unplug network cables and contact an outside cybersecurity specialist using a clean mobile connection.

YYağmur K***Member
Job title
Administrative manager
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jul 2022
Message
1
#5

Stay calm; decisions made in panic cause more damage than the attack itself. Don't blast out a general breach announcement via email or messaging right away. First, assess the situation to figure out whether data was exfiltrated or just locally encrypted.

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#6

exact same thing happened at our warehouse in lyon two years ago but i mean the accountant plugged the backup right in, within five minutes the backup drive got locked too. do not touch that drive keep it in a separate safe.

OOkan Y***ExpertCommunity member
Joined
Aug 2023
Message
335
#7

Was your system running entirely on a local server, or did you have cloud email and file integrations? Also, did you have an open remote desktop port exposed to the internet?

DDoruk D***Member
Job title
IT manager
Sector
Freight
Organization type
a company within a holding
Joined
Jun 2022
Message
11

Doki · Incident response support · 2026

#8

Under French regulations, if systems containing customer or employee data are affected, you must file an official notification via the CNIL platform. Filing a report with the local police or gendarmerie cybercrime unit is also mandatory for any subsequent insurance claims.

PPolat Y***ExpertCommunity member
Joined
Feb 2024
Message
384
#9

Follow these three steps in order: 1) Physically pull the Ethernet cables from all office computers and turn off Wi-Fi. 2) Copy gateway and router access logs to a secure external flash drive. 3) Take photos of locked screens, noting the timestamp and device tag for each.

İİlker T***Member
Job title
Food wholesaler
Joined
Dec 2023
Message
58
#10

Don't delete any files don't connect the external drive to the network, and call in professional external digital forensics support immediately.

AAyşe E***Member
Job title
Graphic Designer
Sector
Paper
Organization type
8-person team
Joined
Feb 2023
Message
302
#11

Same here.

PPolat Y***ExpertCommunity member
Joined
May 2023
Message
54
#12

Let me share my experience. Trying to do this alone is the most expensive way.

If you post the result here, it will help others too.

VVolkan U***Member
Job title
Production Manager
Sector
Cleaning services
Organization type
chain store
Joined
Dec 2025
Message
107

Doki · Interface design · 2023

#13

it's rare to find an explanation this clear. having backups accessible on the same network and with the same identity makes them part of the target.

everyone rushing into cyberattack what to do gets stuck at the same point but that's all sorry if I went on too long.

YYusuf Ö***MemberCommunity member
Joined
Sep 2025
Message
325
#14

i'd appreciate it if you shared the outcome.

OOnur T***MemberCommunity member
Joined
Sep 2023
Message
1
#15

My questions are cleared up, thanks.

EEmre K***Member
Job title
Project manager
Sector
Software
Organization type
workshop
Joined
Nov 2023
Message
1
#16

Thanks a lot, I'll try it today. Just because everyone does it doesn't mean it's right.

GGamze G***Expert
Job title
Human Resources Manager
Sector
Security services
Organization type
medium-sized business
Joined
Apr 2022
Message
218

Doki · Phishing awareness training · 2025

#17

This thread is archived.

KKemal S***Member
Job title
Field sales representative
Sector
Machinery manufacturing
Organization type
two-branch business
Joined
Jun 2023
Message
62
#18

Thanks for writing this that's the right way. When making a decision first look at what data you have on hand.

SSena S***MemberCommunity member
Joined
May 2023
Message
175
#19

Noted thanks.

SSinanMember
Job title
Software instructor
Joined
Dec 2023
Message
186

Doki · E-commerce infrastructure · 2025

#20

You're right, I've been down that road too. Taking notes for two weeks yields better results than a six-month estimate.

Correct me if I'm wrong.

Reply