forumNew topic

Ransomware attack: What NOT to do in the first few minutes — mistakes that make everything worse

NNeslihan S***Member
Job title
Board member
Sector
Cosmetics
Organization type
medium-sized business
Joined
Sep 2025
Message
325

Doki · Server maintenance contract · 2023

#1

We're an automotive supply company near Bologna with 30 employees. This morning, we noticed that file extensions changed on a PC in the engineering office and on our local file server, and a ransom note popped up on the desktop. Luckily, the production line hasn't been hit yet, but our accounting and order history are completely locked up.

Absolute panic in the office right now. The outsourced IT support guy is on his way, but some staff members are suggesting rebooting the machines right away, running a full antivirus scan, or even writing back immediately to the contact address in the ransom note. Personally, I'm terrified that one wrong move will destroy any data that could otherwise be salvaged.

In a crisis like this, what are the critical mistakes that we must ABSOLUTELY AVOID in the first 15 to 30 minutes? What steps would make things irreversibly worse?

NNuri K***Member
Job title
Purchasing manager
Sector
Plastic
Organization type
boutique agency
Joined
Sep 2024
Message
335
Most Helpful#2

Short answer: In the very first minutes of spotting a ransomware attack, do not pull the power cords on the machines, do not reboot them, and under no circumstances should you try to contact the attackers right away to pay the ransom. These knee-jerk reactions wipe out forensic evidence and decryption keys held in volatile memory (RAM), and can trigger the malware to encrypt files even deeper.

First, instead of shutting down or rebooting devices, physically pull out the network cables and disconnect the Wi-Fi. If you power down or restart, all volatile data in the RAM is gone for good. In some cases, decryption keys linger in memory while being sent back to the attacker's server, which digital forensics specialists might be able to recover. Merely isolating the machine from the network stops the infection from spreading to other servers without killing that data.

Second, do not rush into running a virus cleanup or full AV scan. Antivirus tools can quarantine and delete encrypted registry entries, drop scripts, or ransom notes left behind by the attacker, effectively wiping out traces and metadata that recovery tools actually rely on.

Third, never plug backup drives into an infected server to check them. The malware might still be actively running in the background and could encrypt your clean external drive or backup appliance in mere seconds.

Finally, do not panic and message the extortionists right away, and don't promise to pay. Operating in Italy, you may be legally required to report the incident to the data protection authority (Garante Privacy) within 72 hours under GDPR; clarify your legal and technical situation first.

DDefneMember
Job title
SOC Analyst
Organization type
a company within a holding
Joined
Feb 2024
Message
146
#3

Absolutely do not delete or overwrite virtual server snapshots. If possible, avoid moving any files around in the OS until an expert arrives who can take a live memory dump. Altering file attributes makes it much harder to pinpoint the exact strain of the malware.

TTaner V***MemberCommunity member
Joined
Jan 2023
Message
307
#4

The only thing to do right this second: physically unplug the ethernet cables from the back of every single PC, infected or not, and pull the plug on the office router and Wi-Fi access points. Kill all network traffic entirely but leave the machines powered on.

FFatih O***Member
Job title
Project manager
Sector
Construction
Organization type
sole proprietorship
Joined
Nov 2023
Message
1
#5

Last year, one of our clients panicked during a similar incident and rebooted their server, wiping the encryption key from RAM. The data recovery lab reported there was roughly a 70% chance they could have pulled the key straight from memory if the box had just been left running.

HHakan G***Member
Job title
Purchasing manager
Sector
Seafood
Organization type
300-person organization
Joined
Oct 2024
Message
185
#6

biggest mistake is plugging a backup drive u think is clean into the server to check it if malware is still running in the background it'll encrypt your bacukp in seconds and leave u with nothing.

TTuba E***Expert
Job title
Data protection consultant
Joined
Oct 2023
Message
158

Doki · Backup setup · 2024

#7

Under the European Union General Data Protection Regulation, if there is a risk to personal data, it is a legal requirement to notify the competent data protection authority within 72 hours of becoming aware of the breach. Make sure to preserve communication logs and system event records meticulously.

TTülay Y***MemberCommunity member
Joined
Jan 2025
Message
412
#8

Don't listen to staff suggesting paying the ransom. Even if you pay up there's zero guarantee they'll give you a working key or that your systems will recover properly. Plus, you end up marked as an easy mark for future attacks.

OOsman D***Expert
Job title
Supply chain manager
Sector
Construction
Organization type
120-person company
Joined
Mar 2025
Message
43
#9

Three things you must never do in the first half hour: 1) Do not reboot or pull the power on servers, 2) Do not attach clean backup storage to the network or any machine, 3) Do not open any dialogue with the attackers via the email or links in the ransom note.

FFerhat T***Member
Job title
Human Resources Specialist
Sector
Livestock
Organization type
20-person company
Joined
Aug 2022
Message
286
#10

Really sorry to hear this it's an incredibly stressful situation but there is still hope if you keep your cool. Once your IT specialist gets there, let them inspect the machines only while completely disconnected from the network. Staying calm is rule number one for data recovery.

İİsmail T***MemberCommunity member
Joined
Jan 2024
Message
418
#11

Saved. Trying to do this alone is the most expensive way.

Security isn't absolute; it's about making attacks not worth the effort. If you have questions, write them; I'll answer as best I can.

DDilara U***Member
Job title
Store associate
Sector
Energy
Organization type
8-person team
Joined
Sep 2025
Message
15
#12

i didnt know that.

TTolga Ş***Member
Job title
Finance Manager
Sector
Textile
Organization type
early-stage startup
Joined
Jun 2024
Message
78
#13

My perspective changed after experiencing that. Most time waste accumulates in tasks waiting for approval.

Of course, it varies if your situation is different.

CCeren K***MemberCommunity member
Joined
Jan 2023
Message
377
#14

Three different views emerged, they all complement each other. Having backups accessible on the same network and with the same identity makes them part of the target.

I'm also curious if anyone does it differently.

HHakan K***New member
Job title
Content Editor
Sector
Healthcare services
Organization type
120-person company
Joined
Jun 2026
Message
375
#15

Looking at it as a process, the picture changes. Don't rely on a single measure; go layer by layer.

Just leaving this note, it might be useful.

DDoruk Y***Member
Job title
Accounting Manager
Sector
Seafood
Organization type
two-branch business
Joined
Oct 2025
Message
86
#16

Timely topic. If it's your first time, start small; scaling comes later.

Just leaving this note, it might be useful.

AAli Ç***Expert
Job title
Logistics planning
Sector
Tourism
Organization type
workshop
Joined
Nov 2022
Message
188
#17

there different views emerged they all complement each other. when we decide without measuring we always end up in the same place.

BBurcu B***Expert
Job title
Software developer
Sector
Accounting & advisory
Organization type
300-person organization
Joined
Aug 2025
Message
210

Doki · Log management setup · 2025

#18

This thread is archived.

HHakan T***MemberCommunity member
Joined
Nov 2025
Message
106
#19

let me share what happened to me; it might be useful. btw forgotten test environments are more often the entry point than live systems.

just leaving this note, it might be useful.

AAleyna E***Member
Job title
Intern
Sector
IT services
Organization type
workshop
Joined
Jan 2025
Message
140
#20

quick summary for newcomers: Trying to do this alone is the most expensive way.

if it's your first time start small; scaling comes later. good luck with that.

Reply