Blog · October 1, 2026

Ransomware Attack: What to Do Immediately and How to Recover Your Files

You turned on your computer and your files are locked with a demand for payment. Here’s what to do right now, and what recovery actually looks like.

← Back to all posts

If this is happening right now: Disconnect from Wi-Fi immediately. Unplug any network cables. If files are actively being encrypted (you can see filenames changing), shut the computer off. Do not pay the ransom. Call (401) 884-4432.

What Is Ransomware?

Ransomware is malicious software that encrypts the files on your computer and then demands payment - usually in cryptocurrency - in exchange for a decryption key. Once it runs, your documents, photos, and other files become unreadable. A ransom note appears on screen or is placed in every folder it touched.

Ransomware attacks happen to individuals, small businesses, hospitals, schools, and large corporations. No one is too small to be targeted. Most attacks are automated and indiscriminate - the software just looks for vulnerable systems to infect.

How Ransomware Gets on Your Computer

The most common entry points are:

  • Phishing emails with infected attachments (fake invoices, shipping notifications, HR notices)
  • Clicking a malicious link in an email that leads to a drive-by download
  • Fake software update pop-ups (fake Adobe, Java, or browser update alerts)
  • Downloading software from untrusted or pirated sources
  • Remote Desktop Protocol (RDP) left open to the internet - very common in small business attacks
  • Infected USB drives
  • Visiting compromised websites, especially ones that push malicious ads

Step-by-Step: What to Do Right Now

  1. Disconnect from the network immediately. Turn off Wi-Fi and unplug the ethernet cable. Ransomware often tries to spread to other devices on the same network. Cutting the connection limits the damage.
  2. Do not restart the computer yet. Restarting can sometimes trigger additional encryption or destroy forensic evidence that could help identify the strain.
  3. Photograph the ransom note. Use your phone to take a picture of the screen. The ransom note often contains the ransomware family name or an ID that can be used to look up decryption tools.
  4. Do not pay the ransom. Payment does not guarantee recovery. It funds criminal organizations. And it marks you as a paying target for future attacks.
  5. Check your backups. Is there a backup drive that was not connected to the computer during the attack? Cloud backups through OneDrive, Google Drive, or Backblaze? If so, recovery is likely possible without any decryption tools.
  6. Search for free decryption tools. Visit nomoreransom.org - a free resource maintained by law enforcement and cybersecurity firms with decryptors for many ransomware strains. You will need the ransomware name or a sample encrypted file.
  7. Report the attack. Report to the FBI at ic3.gov and to the FTC at reportfraud.ftc.gov. For businesses, also notify your cyber liability insurance carrier if you have one.
  8. Call a technician. A professional can assess the scope of the infection, identify the ransomware strain, determine whether decryption is possible, and help with a clean reinstall if needed.

Can You Recover Files Without Paying?

It depends on three things:

1. Whether you have a backup. This is the most important factor. If you have a recent backup on an external drive that was not connected during the attack, or in a cloud service, your files can usually be restored after the infection is removed. This is why off-site or disconnected backups are so important.

2. Which ransomware strain was used. Older or less sophisticated ransomware strains sometimes have free decryption tools available. Nomoreransom.org is the best place to check. Newer strains from sophisticated criminal groups rarely have public decryptors.

3. How quickly you disconnected. If ransomware was caught early and only encrypted a portion of your files, recovery is simpler than if every file on the machine was touched.

Ransomware Removal Services in Rhode Island

Comp-u-Doc provides ransomware assessment and removal services throughout Rhode Island, including Providence, Warwick, Cranston, East Greenwich, North Kingstown, and surrounding communities. We will come to your home or office, assess what happened, help you identify recovery options, remove the infection, and help you set up backups so this does not happen again.

If your business was hit, we can also help you document the incident for insurance purposes and assess whether any sensitive data may have been accessed before encryption.

How to Prevent Ransomware

  • Keep a backup on a separate drive that is not always connected - or use a cloud backup service with version history
  • Keep Windows and all software fully updated - most ransomware exploits known vulnerabilities that patches already fix
  • Use a quality antivirus with real-time protection (Windows Defender is decent, but dedicated endpoint protection is better for businesses)
  • Be extremely skeptical of unexpected email attachments, even from people you know
  • Never enable macros in Office documents from unknown sources
  • Disable Remote Desktop Protocol if you do not need it, or put it behind a VPN
  • Use strong, unique passwords and enable two-factor authentication on important accounts
  • Train everyone who uses your computers - most ransomware attacks start with a human clicking something they should not have

A Note on Paying the Ransom

The FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and cybersecurity professionals all advise against paying. Here is why: roughly half of businesses that pay do not get all their files back. Paying does not remove the ransomware from your system - you still need a technician for that. And once you pay, you are known as a business or individual willing to pay, which increases the chance of being targeted again.

Exhaust every other option before considering payment. A technician can help you evaluate your situation honestly.

Hit by ransomware in Rhode Island?

Comp-u-Doc can come to your home or business to assess the situation, help with recovery, and make sure the infection is fully removed. We serve Warwick, Providence, Cranston, East Greenwich, and all of Rhode Island.

Call (401) 884-4432

Related reading: Virus Removal Rhode Island · Cybersecurity Services · How to Spot a Tech Support Scam