forumNew topic

Ransomware encrypted all our company servers last night, what exactly should I do in the first few hours?

AAli P***MemberCommunity member
Joined
Oct 2023
Message
69
#1

We run an 18-person wholesale food and logistics company in Valencia. Last night, ransomware infected our main file server and shared network storage. We realized what happened this morning when our accountant walked in and couldn't open any Excel sheets or invoice archives. The text file left on the screens states that our data is encrypted and demands 45,000 euros in crypto to unlock it.

Our daily deliveries are on hold, we can't issue invoices, and we can't log incoming customer orders into the system. Since our local NAS backup was continuously connected to the main server, the file extensions on the last two weeks of backups were modified as well, and they won't open either. We are in total shock and panic.

What exactly should we be doing right now in these critical first hours, both technically and administratively? Is paying the ransom a viable option, or is there another way to recover the system? What are our legal reporting requirements in Spain?

TTaner V***MemberCommunity member
Joined
Jan 2023
Message
307
#2

Right this second pull the ethernet cables from every PC in the office and disable Wi-Fi. Do not pull power cords or shut down infected machines; just isolate them from the network. Powering off completely can wipe transient encryption keys from RAM and destroy digital forensic evidence.

NNurayMember
Job title
Publisher
Organization type
two-branch business
Joined
Oct 2023
Message
92
Most Helpful#3

Short answer: Disconnect every system—affected or not—from the local network and the internet immediately, but leave the machines powered on. Do not pay the ransom; paying never guarantees full decryption and will paint a massive target on your back for future attacks.

Concrete technical steps for the first hours: 1) Physical network isolation: unplug everything, including servers switches, routers, and backup appliances. 2) Do not reboot or power off machines, so digital forensic examiners can analyze volatile memory and trace the attack vectors. 3) Using a clean, isolated external machine, check the encrypted file extensions and ransom note against open-source decryptor databases maintained by independent public cybersecurity platforms.

On the legal side, you must comply with Spanish regulations. If your systems hold personal data belonging to clients, staff, or suppliers, you are legally required to report a data breach to the Spanish Data Protection Agency (AEPD) within 72 hours of becoming aware of it. At the same time, file an official police report with the cybercrime division of the Policia Nacional or Guardia Civil to get formal documentation on file.

To manage operations without paying, check for older backups on offline drives or previous version snapshots with your cloud provider. Instead of handing 45,000 euros over to criminals, hiring a professional incident response firm to rebuild your systems from clean images is far safer and provides a permanent fix.

KKaan B***Member
Job title
Infrastructure engineer
Joined
Mar 2024
Message
108
#4

Copy a couple of encrypted file samples and the ransom note onto a clean USB drive and check them on an isolated machine. You need to identify the exact malware strain. With some older variants, the symmetric key might still be sitting in memory, or security researchers may have already released a public decryptor for that build.

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
#5

People who think paying the ransom will get their files back usually end up sorely disappointed. A logistics company in Madrid in a similar spot paid 30,000 euros; the decryptor they sent corrupted half the files, and two weeks later they broke in through the exact same vulnerability and demanded more money. Do not pay them under any circumstances.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#6

Our storage got locked down by a similar attack last year. We paid an independent third-party incident response specialist 5,500 euros. We had an offline tape backup from two weeks prior, so we restored from that and manually re-entered the invoices issued in between. We lost 4 days of work in total, but we didn't pay the extortionists a single cent.

ÜÜmit K***Member
Job title
Operations manager
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2022
Message
406
#7

Any idea how the attackers got in? Was there an exposed remote desktop (RDP) port, or did an employee open an attachment from an email? Don't you have any other backups that are completely isolated from the network or keep historical versions in the cloud?

TTaner Ç***MemberCommunity member
Joined
Apr 2022
Message
352
#8

Please ensure you do not miss the deadline for notifying the Spanish Data Protection Agency (AEPD). Even if the technical investigation is not completed within the 72-hour window, the initial notification must be submitted, with supplementary reports added to the file as the extent of the damage and the number of affected records become clear.

BBeren G***Member
Job title
Project manager
Sector
E-commerce
Organization type
cooperative
Joined
May 2024
Message
97
#9

so sorry to hear this I know all too well that helpless feeling of walking into the office in the morning and seeing that screen. tell your team not to panic, keep your clients calm by telling them you're doing technical maintenance and look into getting professional help immediately.

MMusaNew member
Job title
Intercity freight
Joined
Oct 2024
Message
34
#10

If you've pulled the network cables, don't format anything and bring in a professional cyber incident response consultant right away.

NNeşe A***Member
Job title
Content agency
Organization type
early-stage startup
Joined
Mar 2024
Message
106
#11

My question might sound amateurish, sorry about that. The real issue isn't the number, but what it's based on.

TTülay Y***Member
Job title
Graphic Designer
Sector
Construction
Organization type
medium-sized business
Joined
Nov 2025
Message
2
#12

I've been down this road, let me tell you. Trying to do this alone is the most expensive way.

If I were you, I'd go this route.

EElif P***New member
Job title
Quality control inspector
Sector
Energy
Organization type
a company within a holding
Joined
Jul 2026
Message
130
#13

Just a heads-up. Forgotten test environments are more often the entry point than live systems.

Good luck with that.

İİlker K***Member
Job title
Technical service technician
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2025
Message
273
#14

You're right.

TTunçExpert
Job title
SaaS Founder
Joined
Jul 2023
Message
186
#15

There's a common mistake people make when doing this. An automated scan report is not the same as a penetration test.

I'm also curious if anyone does it differently.

ÖÖzge E***Member
Job title
Sales Manager
Sector
Paper
Organization type
workshop
Joined
Jun 2023
Message
50

Doki · Brand identity · 2023

#16

My perspective changed after experiencing that. The answer varies greatly by industry; there is no one-size-fits-all rule.

Payment information changes are never verified through the channel they came from. Just leaving this note, it might be useful.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#17

We got stuck at the same point for a while. Hasty decisions become decisions you have to fix six months later.

Hope this helps.

MMert D***MemberCommunity member
Joined
Feb 2023
Message
40
#18

I'd appreciate it if you shared the outcome. Don't hesitate to ask; those who don't ask always pay more.

I'm also curious if anyone does it differently.

CCeren E***MemberCommunity member
Joined
Apr 2025
Message
95
#19

I'm curious too.

SSultan M***MemberCommunity member
Joined
Jul 2023
Message
12
#20

Let me summarize the topic, since several different answers were given. When we decide without measuring, we always end up in the same place.

Proven by experience.

Reply