Dealing With Ransom Notes and Threat Actor Messages

Someone logs in on a Monday morning and finds a text file on the desktop, a changed wallpaper or an email that begins "Your network has been compromised." Panic is natural. What you do in the next hour matters, because early reactions can destroy evidence, tip off the attacker or lock you into decisions better made with counsel and experts at the table.

This post covers what to do when a ransom note or direct message from a threat actor appears. It is meant for administrators and managers who may be the first to see it.

What these messages look like

Ransom notes vary. They may appear as:

A text or HTML file placed in many folders on affected computers

A message on the screen when a computer starts

An email sent to executives or a general inbox

A message through a website contact form, a phone call or even a printout from a printer

A note claiming data was stolen, along with a deadline and a payment demand

Some include a chat address or email contact, and many threaten to publish data. Treat all of them as serious until proven otherwise, but remember that some messages are bluffs or scams unrelated to an actual intrusion.

What to document

Preserve what you can see, and write it down.

Take photos or screenshots of the note, including the full text, file names and where it was found. A phone photo is fine.

Record the time you saw it and who found it.

Note affected systems. Which computers, servers or services show signs of trouble?

Save the original files without opening links or running anything inside them.

Keep a running log of every action taken, by whom and when.

Preserve email headers if the message arrived by email, by forwarding it as an attachment to the response team.

Good records help investigators, insurers and counsel, and they protect you if actions are questioned later.

What to avoid

Do not contact the attackers

Do not reply, click links in the note or open any chat portal. Communication with criminals should be handled, if at all, by professional negotiators working with counsel and your insurer. An uninformed reply can reveal how desperate you are, confirm which person reads the mailbox or expose your systems to further tracking.

Do not delete or "clean up"

Removing the note, wiping a computer or reinstalling software destroys evidence of how the attack happened and what was affected. Leave things as they are until the response team says otherwise.

Do not shut everything off in a panic

Isolating affected devices is wise. Pulling the network cable or disconnecting from Wi-Fi stops spread while preserving the state of the machine. Powering off may erase information in memory that investigators can use, though in some situations responders will tell you to do so. When in doubt, disconnect and ask.

Do not discuss it widely

Keep details among the people who need to know. Rumors spread fast, and attackers sometimes monitor email, so use phone calls or a separate channel if your email may be compromised.

Do not pay anything on your own

Decisions about payment involve legal, regulatory and practical risks, including sanctions concerns and no guarantee that data will be returned. Leave them to leadership advised by counsel and specialists.

Who to escalate to, and in what order

Your IT provider or security team, immediately, by phone.

Your incident response lead or administrator, who activates your plan.

Outside counsel and your cyber insurance carrier, often through a hotline listed on the policy. Policies commonly require prompt notice and may specify approved responders.

Law enforcement. The FBI and CISA encourage reporting ransomware incidents, and your counsel can advise on timing.

Your compliance or privacy officer, because a threat involving patient data can trigger HIPAA breach assessment obligations.

Keep the contact numbers for these in a printed list outside the network, because you may not have access to email or shared files.

Messages that claim data theft

If the note says data was stolen, treat that as a claim to verify, not a fact. Investigators will look for evidence of data leaving the network. Do not confirm or deny anything to outside parties until you know more, and have counsel review statements to residents, families, employees or the press.

Prepare in advance

Add a page to your incident response plan on ransom notes: who to call, who is authorized to speak with attackers (usually no one on staff) and where to store evidence. Tell staff in training that if they see a strange message, they should photograph it, disconnect the device and call the help desk instead of trying to fix it.

How UnityCare IT can help

We help healthcare and senior-living organizations in Oklahoma, Texas and Arkansas write this guidance into their incident response plans and are available to coordinate with counsel, insurers and investigators when a message like this appears.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172