Key facts
- Disconnect infected machines from the network and Wi-Fi, but leave them powered on so evidence in memory is kept.
- Report Fraud, run by the City of London Police, replaced Action Fraud as the national cyber crime reporting service in December 2025.
- Under UK GDPR, a personal data breach that risks people's rights must be reported to the ICO within 72 hours of becoming aware of it.
- Backups that were connected to the network may also be encrypted, so check them before relying on them.
- Paying a ransom does not guarantee you get your data back and may fund further crime.
- Most ransomware starts with a phishing email, a stolen password or an unpatched remote access service.
How to tell it is ransomware
Ransomware is malware that encrypts your files and demands payment for the key. Typical signs:
- Files will not open and have a new extension added, such as .locked or a random string.
- A text or HTML file called something like README, HOW_TO_DECRYPT or RESTORE_FILES appears in every folder.
- A ransom message replaces the desktop wallpaper.
- Shared drives, the NAS or OneDrive show thousands of files changing at once.
- Antivirus is suddenly disabled, or PCs slow to a crawl as files are encrypted.
Modern attacks often steal a copy of your data before encrypting it, then threaten to publish it. So even if you can restore, treat it as a possible data breach.
The first hour: contain it
- Disconnect, do not shut down. Pull the network cable and turn off Wi-Fi on any affected PC or server. Leave it powered on: shutting down can lose evidence and sometimes damages files mid-encryption.
- Isolate backups. Unplug USB backup drives and disconnect the NAS from the network if it is not yet affected.
- Stop sync. Pause OneDrive or Dropbox sync on unaffected machines so encrypted files do not overwrite good ones in the cloud.
- Change passwords from a clean device, starting with Microsoft 365 global admin, email, remote access, banking and the domain registrar. Make sure MFA is on.
- Write things down: what you saw, when, which machines, and photograph the ransom note. Do not delete it.
- Do not contact the attackers or pay before taking advice.
Report it
- Police: in England, Wales and Northern Ireland, report to Report Fraud, the City of London Police service that replaced Action Fraud in December 2025. In Scotland, contact Police Scotland on 101.
- The ICO: if personal data (customer, staff or patient details) may have been accessed or made unavailable and that poses a risk to people, UK GDPR requires you to report it to the Information Commissioner's Office within 72 hours of becoming aware.
- Your cyber insurer, if you have one, before you start recovery. Many policies require you to use their incident response team and to notify them quickly.
- The NCSC publishes free guidance on ransomware for small organisations and can be notified of significant incidents.
Recovering your systems
Recovery has to happen in the right order, or the attacker simply comes back.
- Find the way in. Check sign-in logs in Microsoft 365, remote desktop logs, and recent phishing emails. Common entry points are an exposed Remote Desktop (RDP) port, a VPN or firewall without recent updates, or a user who entered their password into a fake login page.
- Close it: patch, remove exposed services, reset credentials, enforce MFA.
- Wipe and rebuild infected machines rather than trying to clean them.
- Check your backups are clean and from before the infection, then restore.
- Restore Microsoft 365 and OneDrive from version history or a third-party backup if files were encrypted in the cloud.
- Monitor closely for several weeks for signs of a return.
Free decryption tools exist for some older ransomware families through the No More Ransom project, which is worth checking before assuming files are lost.
Preventing the next one
The basics stop most ransomware: MFA everywhere, prompt updates, no RDP open to the internet, staff phishing awareness, and backups that are offline or immutable and regularly tested. Work through our small business cyber security checklist and consider Cyber Essentials.
When to call dijitul support
Call us as soon as you see signs of ransomware. We help you contain it remotely, secure accounts, check which backups are safe, rebuild and restore machines and Microsoft 365, and tighten security so it does not happen again. Urgent help is £45 an hour + VAT; a full recovery is quoted once we know the scale. See ransomware recovery and data backup and recovery. Phone 01623 650333.
Frequently asked questions
Should I pay the ransom?
UK law enforcement and the NCSC do not encourage paying. Payment does not guarantee a working decryption key, does not stop the data being leaked, and marks you as willing to pay. Take advice and check your backups and insurance first.
Do I have to report a ransomware attack to the ICO?
If personal data may have been accessed, lost or made unavailable and that creates a risk to individuals, UK GDPR requires you to report it to the ICO within 72 hours of becoming aware. Record your reasoning either way.
Where do I report ransomware to the police?
In England, Wales and Northern Ireland, report it to Report Fraud, the City of London Police service that replaced Action Fraud in December 2025. In Scotland, call Police Scotland on 101.
Can ransomware encrypt OneDrive and SharePoint?
Yes, if it runs on a PC that syncs with them, encrypted files sync to the cloud. OneDrive's Restore feature and version history can roll files back, but a separate Microsoft 365 backup is the safer option.
How much does ransomware recovery cost with dijitul?
Urgent containment and advice from dijitul is £45 an hour + VAT. Full recovery, including rebuilding machines and restoring data, depends on the number of devices and the state of backups, so it is quoted once the scale is known.
Should I turn off the infected computer?
No. Disconnect it from the network and Wi-Fi but leave it powered on. Switching off can destroy evidence held in memory that investigators use, and may corrupt files that were partly encrypted when the power went.
Related
Tell us what you need
We scope it, give you a clear fixed quote and do the work. No jargon.