Someone logs in on a Monday morning and finds a text file on the desktop, a changed wallpaper or an email that begins "Your network has been compromised." Panic is natural. What you do in the next hour matters, because early reactions can destroy evidence, tip off the attacker or lock you into decisions better made with counsel and experts at the table.
This post covers what to do when a ransom note or direct message from a threat actor appears. It is meant for administrators and managers who may be the first to see it.
Ransom notes vary. They may appear as:
A text or HTML file placed in many folders on affected computers
A message on the screen when a computer starts
An email sent to executives or a general inbox
A message through a website contact form, a phone call or even a printout from a printer
A note claiming data was stolen, along with a deadline and a payment demand
Some include a chat address or email contact, and many threaten to publish data. Treat all of them as serious until proven otherwise, but remember that some messages are bluffs or scams unrelated to an actual intrusion.
Preserve what you can see, and write it down.
Take photos or screenshots of the note, including the full text, file names and where it was found. A phone photo is fine.
Record the time you saw it and who found it.
Note affected systems. Which computers, servers or services show signs of trouble?
Save the original files without opening links or running anything inside them.
Keep a running log of every action taken, by whom and when.
Preserve email headers if the message arrived by email, by forwarding it as an attachment to the response team.
Good records help investigators, insurers and counsel, and they protect you if actions are questioned later.
Do not reply, click links in the note or open any chat portal. Communication with criminals should be handled, if at all, by professional negotiators working with counsel and your insurer. An uninformed reply can reveal how desperate you are, confirm which person reads the mailbox or expose your systems to further tracking.
Removing the note, wiping a computer or reinstalling software destroys evidence of how the attack happened and what was affected. Leave things as they are until the response team says otherwise.
Isolating affected devices is wise. Pulling the network cable or disconnecting from Wi-Fi stops spread while preserving the state of the machine. Powering off may erase information in memory that investigators can use, though in some situations responders will tell you to do so. When in doubt, disconnect and ask.
Keep details among the people who need to know. Rumors spread fast, and attackers sometimes monitor email, so use phone calls or a separate channel if your email may be compromised.
Decisions about payment involve legal, regulatory and practical risks, including sanctions concerns and no guarantee that data will be returned. Leave them to leadership advised by counsel and specialists.
Your IT provider or security team, immediately, by phone.
Your incident response lead or administrator, who activates your plan.
Outside counsel and your cyber insurance carrier, often through a hotline listed on the policy. Policies commonly require prompt notice and may specify approved responders.
Law enforcement. The FBI and CISA encourage reporting ransomware incidents, and your counsel can advise on timing.
Your compliance or privacy officer, because a threat involving patient data can trigger HIPAA breach assessment obligations.
Keep the contact numbers for these in a printed list outside the network, because you may not have access to email or shared files.
If the note says data was stolen, treat that as a claim to verify, not a fact. Investigators will look for evidence of data leaving the network. Do not confirm or deny anything to outside parties until you know more, and have counsel review statements to residents, families, employees or the press.
Add a page to your incident response plan on ransom notes: who to call, who is authorized to speak with attackers (usually no one on staff) and where to store evidence. Tell staff in training that if they see a strange message, they should photograph it, disconnect the device and call the help desk instead of trying to fix it.
We help healthcare and senior-living organizations in Oklahoma, Texas and Arkansas write this guidance into their incident response plans and are available to coordinate with counsel, insurers and investigators when a message like this appears.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172