All My Files Are Encrypted and There’s a Ransom Note: What to Do First
October 10, 2026
The first hour matters — but not in the way the search results suggest. There may be a free decryptor for your exact strain, and the firms advertising "proprietary decryption" above it are the part to be most careful about.
It usually announces itself in one of two ways. Either you go to open a file you use every day and it refuses — Word says it cannot read it, the photo thumbnail is a blank page, the accounting file is suddenly an unrecognised type — or you notice that every document has grown a strange new ending on its name, something like .locked or a random string of letters that was never there before. And in every folder, sitting next to your own files, there is a text file you did not create. It is addressed to you. It explains that your data has been encrypted, that only the people who did it have the key, and what they would like you to do about that.
Europol’s No More Ransom project, which we will come back to several times because it is the single most useful page on this subject, describes the shape of it precisely: "The affected files are deleted once they have been encrypted, and users generally encounter a text file with instructions for payment in the same folder as the now-inaccessible files," and "You may discover the problem only when you attempt to open one of these files." That last sentence is why this so often surfaces on a Monday morning rather than at the moment it happened.
What you do in the first hour genuinely matters. But it matters in a different way than the search results for this problem imply, and we want to be blunt about one thing before anything else: the companies advertising at the top of those results are the part of this situation to be most careful about, and on October 7, 2026 the US Department of Justice explained in considerable detail why. We will get to that. First, the things worth doing right now.
First, make sure this is actually ransomware
Three different problems arrive at our counter described in the same words — "my files are encrypted" — and only one of them involves a criminal. It is worth spending two minutes on this, because the right response to each is completely different and the other two are far less serious.
The first lookalike is BitLocker. If what you are looking at is a plain blue or black screen, before Windows has really started, asking for a long recovery key — a 48-digit number — then nobody has attacked you. That is Windows’ own disk encryption asking you to prove the drive is still in the computer it belongs to, usually after a firmware update or a hardware change. Your files are intact and the key is almost certainly sitting in your Microsoft account. We have a separate guide to that one, and it is a much better day than this one.
The second lookalike is a scare page. If the demand is in your web browser — a full-screen page, often with a countdown, sometimes with an alarm sound and a phone number to call — but your documents still open normally when you go and check a few, then nothing has been encrypted at all. That is a scareware pop-up, and the entire attack is the phone number. No More Ransom draws the same distinction for lock-screen malware: it "locks the computer’s screen and demands payment" and "presents a full screen image that blocks all other windows," but — the important part — "No personal files are encrypted." Go and open three or four real documents from different folders before you believe any message about your files. Our guides to fake Microsoft pop-ups and fake Windows update screens cover that family.
The third lookalike is a dying drive. Files that will not open, names that look garbled, folders that have gone strange — a failing disk can produce all of that, and there will be no ransom note anywhere, because there is nobody to write one. If you cannot find a readme or a payment demand in the affected folders, read our guide to the warning signs of a failing hard drive instead, and stop using the drive.
What tells you it is the real thing is the combination: files renamed or unopenable in bulk, across many folders, plus a payment demand written as a file on your own disk. One without the other is usually one of the three above.
The first hour: disconnect, and do not wipe anything
Assuming it is real, there are a small number of things worth doing immediately, and one large thing worth not doing.
Disconnect the machine from everything else. Unplug the network cable, or turn off Wi-Fi from the keyboard if you can do it without logging back in. The reason is not the infected computer — that damage is done — it is everything the infected computer can reach. Ransomware works outward along whatever is attached: the external backup drive that lives permanently plugged into the back of the tower, the network drive mapped as S:, the shared folder on the office server, the NAS in the cupboard. In a small office, the difference between one ruined computer and a ruined business is very often just how long the first machine stayed on the network. If there are other computers sharing that network and you do not know which ones are affected, take the whole thing off at the router rather than trying to work it out machine by machine.
Keep the encrypted files. Do not delete them, do not reformat the drive, and do not let anybody talk you into "starting fresh" on day one. This is not sentiment. A decryption tool for your particular strain may not exist today and may exist in a year — No More Ransom says so in as many words, noting that "Sometimes we only get a subset of the keys, so please keep checking the website." Files you still have can be decrypted later. Files you deleted in frustration on the first afternoon cannot. If you need the computer back in service urgently, the right move is to take the drive out and keep it on a shelf, or image it to another disk, and rebuild on new storage — not to wipe the only copy of your own data.
Save the ransom note itself, and a couple of the encrypted files. Copy the note to a USB stick, or at minimum photograph the screen. You will need its exact text shortly, and you will need it again if you report this. Write down when you first noticed, and what the file extensions look like.
And do not wipe or reinstall yet for a second reason that is easy to miss and, for a business, is the expensive one. The machine is currently the only record of what actually happened — including whether anything was copied out of it before it was scrambled. That question turns out to be the one that decides whether a California business owes its customers a letter, which we come to further down. The evidence for it lives in logs on that computer and on your firewall, and a panicked reinstall on day one destroys it. Being able to say "we checked, and we can show nothing left" is worth a great deal more than a day saved.
What not to do: do not contact the attackers "just to ask", do not pay anything yet, and do not start downloading tools named after your ransomware from sites you have never heard of. There is a legitimate place to look, and it is a short one.
Before you pay anyone — including a "recovery" company — check for a free decryptor
This is the step almost nobody takes, because almost nothing in the search results mentions it.
No More Ransom is a joint project of European law enforcement — Europol and the Dutch national police, Politie, are both on the page — and the security industry. It describes what it does plainly: "it is sometimes possible to help infected users to regain access to their encrypted files or locked systems, without having to pay. We have created a repository of keys and applications that can decrypt data locked by different types of ransomware." The tools are free, and they are hosted by the firms that wrote them.
It is not a token gesture. We counted the live list on October 10, 2026: 223 separate decryption tools covering 184 named ransomware families. The biggest contributors are named on every entry — Emsisoft has written 68 of them, Kaspersky 34, Avast 28, Trend Micro 27, Bitdefender 14 — and a handful are credited to police forces and national response teams directly, including the Japanese Police, CERT-PL, Politiet and the Police nationale.
More to the point, the list includes a lot of the strains that actually hit small businesses and households. Free tools are published today for Akira, Lockbit 3.0, BlackBasta, Phobos / 8base, Rhysida, DoNex, Bianlian, REvil/Sodinokibi, Babuk, Hive (v1 to v4), Maze / Sekhmet / Egregor, Darkside, Dharma, CrySIS and djvu, among many others. If your note came from one of those, the key you are being asked to buy may already be sitting on a public web page for nothing.
If you do not know which strain you have — and most people do not — the site has a matching tool called Crypto Sheriff. It asks for two of your encrypted files, and it is specific about the limit: "Upload encrypted files here (size cannot be larger than 1 MB)". Then it wants the identifying details out of the demand itself: "Type below any email, website URL, onion or/and bitcoin address you see in the RANSOM DEMAND", with the warning "Be especially accurate with the spelling." Alternatively you can hand it the note directly — "Or upload the file (.txt or .html) with the ransom note left by criminals". This is the reason we told you to keep the note.
Two honest caveats, both from the project itself. The first: it does not always work. The home page says "At the moment, not every type of ransomware has a solution. Keep checking this website as new keys and applications are added when available." A no today is genuinely not a no forever, which is the whole argument for keeping your encrypted files.
The second caveat is the one that can cost you the recovery, and it is printed at the top of the tools page in capitals: "IMPORTANT! Before downloading and starting the solution, read the how-to guide. Make sure you remove the malware from your system first, otherwise it will repeatedly lock your system or encrypt files. Any reliable antivirus solution can do this for you." Decrypting your files on a machine that is still infected just gives the ransomware a fresh set of readable files to encrypt again. Clean first, decrypt second, and do the decryption against copies rather than your only remaining originals.
One thing to know so you do not write the project off: parts of that site are visibly old. Its question-and-answer page still says there are "more than 50 families of this malware in circulation" and that "the portal contains a four decryption tools", which was true around its launch a decade ago and is nowhere near true now. Judge it by the decryption-tools list, which is current and dated by the strains on it, not by the FAQ.
Why a free decryptor can exist at all
It is reasonable to be suspicious of this. If the encryption is any good, how can anybody but the attacker undo it? The answer is that the tools almost never break the mathematics — they exploit something that went wrong around it, and No More Ransom lists the three routes.
Sometimes the criminals simply got it wrong: "The malware authors made an implementation mistake, making it possible to break the encryption. That was the case with the Petya ransomware and with the CryptXXX ransomware." Sometimes the keys get published — "The malware authors feel sorry about their actions and publish the keys, or a ‘master key’, as in the TeslaCrypt case." And sometimes the police take them: "Law enforcement agencies seize a server with keys on it and share them. One such example is CoinVault."
That third route is the one worth understanding, because it explains the timing. Keys often become available when a ransomware operation gets taken down, which can be months or years after you were hit. It is also why the answer to "is there a tool for my strain" changes, and why the only version of that question that matters is the one you ask today — not the forum thread you found from two years ago saying there was no hope.
The most dangerous thing in these search results is some of the companies advertising in them
Search for any version of "my files are encrypted" and look at what comes back. When we ran it while writing this, the first page was antivirus vendors, a Quora thread, one unanswered question on Microsoft’s own support forum, a single government page — and three companies selling ransomware recovery as a service. That mix is worth noticing, because a firm that earns its money from your emergency has an obvious reason not to mention that your strain might have a free tool.
On October 7, 2026, the Justice Department made that concern a good deal less theoretical. In a press release that day (number 26-1153), it announced that Zohar Pinhasi, 50, "also known as ‘Zack Silver’ and ‘Zack Green,’ a U.S. and Israeli national, was arraigned today in the Eastern District of New York on wire fraud charges relating to Pinhasi’s false representations that he could decrypt ransomware without paying cybercriminals." His company, MonsterCloud, was a ransomware remediation business, and according to the department it marketed itself on exactly the principle that makes people trust such a firm: "MonsterCloud’s website cautioned clients not to pay the ransom and claimed that his team specialized in helping businesses recover their data without succumbing to ransom demands." Pinhasi, it says, "represented that he had access to ‘proprietary tools’ and ‘advanced decryption techniques’."
What prosecutors allege he actually did is the thing to carry away from this article. He "allegedly had no special technology to decrypt data but instead contacted and paid the cybercriminals who had victimized MonsterCloud’s client in exchange for a decryption key that MonsterCloud employees then used in an attempt to decrypt the client’s files." The markup is where it becomes vivid. The release gives one example: "in or around August 2023, he made a ransom payment of approximately $8,200 to a cybercriminal and charged the client approximately $150,000." Across the whole alleged scheme, it says he "charged clients more than $19 million and paid more than $8 million in ransom payments." He is charged with two counts of wire fraud and one of wire fraud conspiracy, facing a maximum of 20 years on each.
We are quoting an indictment, so the usual and important caveat applies, in the department’s own words: "An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law." Nothing here is a finding of fact, and this is one company rather than an industry.
But there is a second line in that release that is useful regardless of how the case ends, from the FBI’s Assistant Director James C. Barnacle Jr.: the defendant is alleged to have "claimed to fix ransomware while never remediating the underlying threat." That is the failure mode to watch for even with an entirely honest provider. Getting your files back is half a job. If nothing is done about how the attacker got in and whether they still have a way back, you are buying a pause, not a fix — and it rhymes exactly with No More Ransom’s warning about decrypting on a machine you have not cleaned.
So if you do hire somebody — us, or anyone — three questions in writing, before money changes hands. Will you be paying the attacker on my behalf, directly or indirectly, and will you tell me if you do? Have you checked whether a free decryptor exists for this specific strain, and what did you find? And what are you going to do about how they got in? An honest answer to the first can be yes with your informed consent. An evasive answer to any of the three is your answer.
Should you pay the ransom?
The official position is unambiguous, and the Justice Department restated it in that same release: "In joint guidance, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have advised that they do not recommend that ransomware victims pay ransom. Paying ransoms does not ensure that data is decrypted, that systems or data will no longer be compromised, or that data will not be leaked."
Read those three clauses separately, because they are three different things you are not buying. Not a guarantee the files come back. Not a clean network afterwards. And not the deletion of any copy they took — which matters, because the modern pattern is to steal the data first and encrypt it second, so that there is something to threaten you with even if your backups turn out to be fine.
No More Ransom adds a mechanical reason that gets overlooked: "Paying the ransom is never recommended, mainly because it does not guarantee a solution to the problem. There are also a number of issues that can go wrong accidentally. For example, there could be bugs in the malware that makes the encrypted data unrecoverable even with the right key." The people who wrote the malware are not necessarily good at writing software. Sometimes the key arrives and the files still do not come back.
We are not going to pretend this is a comfortable decision for everyone who faces it. A business with no usable backup, payroll due Friday and twenty years of records on one server is in a genuinely terrible position, and the people telling it not to pay are not the ones who have to make the payroll. That decision belongs to the owner, ideally with a lawyer and an insurer in the room. What we would insist on is the order of operations: check for a free decryptor, establish what backups you really have rather than what you believe you have, and find out whether data was taken — before you decide. Those three answers change the decision, and all three are cheaper than the ransom.
If you run a business in California, there is a second question: did anything leave?
For a household, ransomware is a data-loss problem. For a business with customer or employee records on the affected machine, there is a separate question sitting alongside it, and it has nothing to do with whether you get your files back.
The California Attorney General’s office states the rule like this: "California law requires a business or state agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person," citing Civil Code section 1798.82(a) for a person or business. And there is a second duty on top of it for larger incidents: "Any person or business that is required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General."
The word doing the work there is acquired. The trigger is acquisition — somebody getting a copy — not encryption. Ransomware that only scrambled your files where they sat, with nothing taken, is a disaster for you and is not obviously an acquisition of anybody’s personal information. Ransomware that copied the customer database out before encrypting it, which is now the common pattern and is precisely the behaviour behind the FBI and CISA’s warning that paying does not ensure "that data will not be leaked", looks very different against that sentence.
We are a computer repair shop and not a law firm, and whether any particular incident crosses that line is a question for a lawyer who can see the facts. What we can tell you is the technical half, and it is the reason this section is in an article about your first hour: the evidence that answers "did anything leave" is in logs — on the machine, on the server, on the firewall, in the admin history of your email and cloud accounts. It is finite, some of it rolls over and overwrites itself within days, and a same-day reinstall deletes the rest. Businesses that wipe first and ask later frequently end up unable to show either that data was taken or that it was not, which is the worst of the three possible positions to be in.
If you have been on the receiving end of one of these notifications yourself, our guide to what a California data breach letter actually means covers the other side of the same statute.
Report it — even though you probably will not hear back
Ransomware is a crime, and the place to report it is the FBI’s Internet Crime Complaint Center at ic3.gov, which describes itself as "the central hub for reporting cyber-enabled crime. It is run by the FBI, the lead federal agency for investigating crime." Its own guidance is to file even if you are not sure it qualifies: "file a report even if you are unsure of whether your complaint qualifies."
Set your expectations honestly, because the site does: "Due to the massive number of complaints, we receive each year, IC3 cannot respond directly to every submission, but please know we take each report seriously." You are not filing this because an agent will call you back tomorrow. You are filing it because that is how strains get tracked, how key servers eventually get seized — the third route to a free decryptor from earlier in this article — and because an insurer or a lawyer will ask you for the report number. It takes a few minutes and it is worth having. Have the ransom note and your dates to hand.
What actually decides how this ends
Everything above is damage control. The thing that determines whether this is a bad week or an extinction event was settled before it happened, and No More Ransom puts it without any comfort at all: "Unfortunately, in many cases, once the ransomware has been released into your device there is little you can do unless you have a backup or security software in place."
If you are reading this before anything has gone wrong, there are two ransomware-specific points that general backup advice tends to skip, and both are about reachability. A backup drive that lives permanently plugged into the computer is not out of reach — it is just another drive letter, and ransomware will encrypt it along with everything else. The same goes for a NAS or a server share mapped as a drive. For this particular threat, a copy that is unplugged, or in a service the computer cannot write to directly, is worth more than a larger copy that is always connected.
The second point concerns cloud sync, and it cuts both ways. OneDrive, Google Drive, Dropbox and iCloud are not backups, and they will faithfully sync the encrypted versions of your files up to the cloud within minutes — the folder you were relying on fills with ruined files too. What can save you there is not the sync folder but the version history behind it, which keeps earlier copies of each file for a window of time and can roll an account back. It is a real recovery route and we have used it, but it is a feature you need to know exists and know the time limits of, and it is not the same thing as having a backup.
We have separate guides on getting that right: why you need a backup and how to check the one you think you have is actually running, and the difference between a point-in-time restore and Windows System Restore, which is one of the more consequential misunderstandings in this area. The version of that advice that applies here is short: the only backup that helps against ransomware is one the ransomware could not write to, and one you have actually restored a file from at least once.
How we can help
If you are in the middle of this right now, the useful things we do are the unglamorous ones: work out what you are actually looking at, get the machine off the network without destroying what is on it, identify the strain and check it honestly against the free-decryptor list, find out what your backups genuinely contain, and tell you plainly whether your files are recoverable or not. We do not have proprietary decryption technology, nobody does, and we will say so rather than charge you for the idea.
We will also not pay an attacker on your behalf without telling you, and we would rather spend the first hour preserving the answer to whether anything left your network than giving you a clean-looking computer by the afternoon. And if you are reading this out of curiosity rather than need, the cheapest appointment you will ever book with us is the one where we set up a backup that this cannot reach. Call us before you need it.
Keep reading
- Why You Need a Backup — and How to Check the One You Have Is Actually Working
- You Got a Data Breach Notification Letter in California — What It Means and What to Do
- BitLocker Is Asking for a Recovery Key and You Do Not Have One
- Point-in-Time Restore vs System Restore on Windows 11: Which One Gets Your Files Back
- That "Microsoft" Pop-Up Telling You to Call a Number Is a Scam
- Free vs Paid Antivirus in 2026: What Actually Earns the Money
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020