The First 24 Hours After Ransomware Hits Your Home Network

If ransomware has appeared on a computer in your home, do four things and stop. Disconnect that machine from the network — unplug the cable, switch off its Wi-Fi — but do not power it down, because shutting down destroys evidence that is often needed to identify what happened and what else was reached. Do not delete the ransom note or the encrypted files. Do not pay, or open a negotiation, before you have taken advice. And do not use the affected machine to research the problem or to contact anyone about it; assume every keystroke on it is observed. Then get a response specialist involved. The decisions made in the first few hours — particularly the instinct to clean up quickly and quietly — determine more about the eventual outcome than anything that follows.

What follows is how the first day usually goes when it goes well, and the specific mistakes that make it go badly.

Hour one: contain, do not tidy

Containment and cleanup feel like the same impulse. They are opposites. Containment stops the spread and preserves the scene; cleanup destroys the record of what happened, and with it much of the leverage you will need later.

Disconnect the affected machine from the network but leave it running. A live system holds a great deal in memory that vanishes on shutdown, and that memory frequently answers the questions that matter most: what was running, what it reached and whether it is still active elsewhere. If the machine must be moved, move it without powering it off.

Then widen the circle. Ransomware on a home network is rarely a single-machine event by the time it becomes visible. Consider every device that shares the network — other computers, network storage, backup drives left permanently connected, the home automation controller, the machines in a second residence connected over the same VPN. Anything holding a copy of the family's data that is currently reachable should be disconnected from the network as a precaution while the scope is established.

Pay particular attention to cloud sync. Consumer backup and file-sync services faithfully replicate encryption as though it were an ordinary change, which means an intact cloud copy can be overwritten with an encrypted one while you are still reading the ransom note. Pausing sync on every device — and checking whether the service retains prior versions, as most do — is frequently the difference between a bad afternoon and a genuine loss.

Hours two to four: work out what actually happened

The ransom note is the last step of an intrusion, not the first. Something arrived, something ran, and something had access — often for a good deal longer than the note suggests. The question that matters in hour two is not how to decrypt the files. It is what else was touched while the intruder was inside.

That means establishing, carefully rather than quickly, which accounts were signed in on the affected machine and which credentials it stored. A browser holding saved passwords for the family's email, banking and brokerage accounts should be treated as compromised, and those accounts secured from a different device — email first, because it can reset the others.

It also means asking whether data left the household. Extortion increasingly involves copying files before encrypting them, so that refusing to pay for decryption becomes a decision about publication rather than about access. For a prominent family the contents of a home computer — correspondence, financial records, photographs, medical and legal documents, the affairs of children — make that a materially different problem from a technical one, and one better assessed early than discovered late.

The four mistakes that cost the most

The first is wiping and reinstalling in the first hours. It feels decisive, it is occasionally the right final answer, and done immediately it destroys the only record of what happened. A machine rebuilt before it is examined leaves you unable to answer whether data was taken, unable to support an insurance claim, and unable to know whether the intrusion is over or merely relocated.

The second is paying quickly to make it stop. Beyond the obvious — that payment funds the activity and that decryption tools frequently work poorly — payments to sanctioned entities carry legal exposure that most people are unaware of until afterwards. Whether to pay is a decision to take with counsel and, where a policy exists, with the insurer, not at two in the morning on a laptop.

The third is telling too many people too early, or too few. A breach in a prominent household touches family members, staff, business interests and occasionally the press, and an uncontrolled internal message is how private incidents become public ones. The opposite failure is just as costly: keeping the household entirely uninformed while someone continues to use an affected device, or while a family member approves a payment instruction that is not what it appears to be.

The fourth is communicating on compromised equipment. If the machine or the network is suspect, so is the email account signed in on it, and so are the messages you send discussing the response. Move to a known-clean device and a different network, and where the matter is sensitive, to a channel established for the purpose.

Hours four to twelve: backups, and honest answers about them

Recovery from ransomware is a backup question. Everything else is negotiation.

The useful backup is one that was not reachable from the infected network at the time — an external drive that is normally disconnected, a service with immutable or versioned storage, a copy held somewhere the compromised machine had no path to. A backup drive that lives permanently plugged into the affected computer is not a backup for this purpose; it is another encrypted volume.

Before restoring anything, establish that the environment is clean. Restoring good data onto a machine that is still compromised produces a second, slower loss, and it is a common way for households to lose the same files twice. Rebuild first, verify, restore after. Where a machine cannot be established as clean, rebuilding it from scratch is the honest answer rather than the defeatist one.

This is also the point at which most families discover the true state of their backups. If yours turn out to be partial, stale or encrypted along with everything else, that is worth knowing calmly at hour six rather than believing otherwise until hour twenty.

Hours twelve to twenty-four: the record, and the decisions

By the end of the first day the technical picture is usually clear enough to make decisions, and the priority shifts to making them defensibly.

Keep a straightforward timeline: when the note appeared, what was done and when, which devices were isolated, which accounts were secured, what was observed. This costs very little at the time and is the backbone of an insurance claim, a report to law enforcement, or a conversation with counsel about notification obligations — which may exist if a family office, a business interest or employment records are involved.

If a personal cyber policy is in place, it should be engaged early rather than after the fact; many policies condition cover on notification within a defined period and on the use of approved responders, and a household that resolves the incident entirely on its own initiative can find it has resolved its claim as well.

After the first day

What makes households recover well is not that they had an emergency plan. It is that someone had thought, in advance, about which machines the family's real data lived on, whether a backup existed that an intrusion could not reach, and who would be called at eleven o'clock on a Saturday night.

Nearly every engagement ends with the same short list, and it is rarely exotic: separate the household network from the guest and smart-home networks, keep one backup offline, put hardware-backed authentication on email and money, and treat the devices of family members and staff as part of the same perimeter rather than someone else's problem. Most families close that gap after an incident. It is considerably cheaper to close it before.

If an incident is active now, say so when you write — active incidents are prioritized. Private cyber incident response covers containment, forensic preservation suited to insurance and legal proceedings, recovery and a plain-language debrief; a personal cybersecurity assessment is how the same ground gets covered before anything happens.

Alex Fry, founder of Privilege Security

Alex Fry is a security engineer and the founder of Privilege Security. His career spans classified defense programs, federal security engagements and global enterprise, and he brings that discipline to private clients.
About Alex →

Explore Private Cyber Incident Response

When you’re ready, the conversation is confidential.

Request a Confidential Consultation