At a glance
If you’re locked out of your files and receive a ransom message, it’s likely a ransomware attack. Record details of the ransom and turn off the infected device. Disconnect other devices from your network and change your important account passwords. Never pay a ransom and report the incident to the correct authorities.
Emergency help: If there is an immediate threat to life or risk of harm, call 000.
Ransomware explained
Ransomware is a common and dangerous type of malware. It works by locking or encrypting your files so you can no longer access them. Cybercriminals will demand a payment, usually in cryptocurrency, to:
- restore access to your files
- stop them from leaking your data online.
Learn more about ransomware.
There’s no guarantee you’ll regain access and you may be targeted again.
Signs you may be affected
You may be affected by ransomware if you:
- get a pop-up message asking for payment to unlock your files
- need a password or code to open your files
- notice folders and files aren’t in their usual location
- notice files have unexpected names, extensions or icons
- can’t access your devices or your logins don’t work.
If this is happening now
You can reduce the harm by acting quickly. This can help stop the ransomware from spreading.
Seek professional help
Ransomware attacks can cause serious damage. It’s hard to tackle and overcome them on your own. Consider finding an IT professional to help you work through a ransomware attack.
Record important information
Make a record of what has happened, including:
- when it happened
- the ransom message
- the device it happened on
- the name of any new or unusual file extensions
- any other information you received from or shared with the cybercriminal
- anything else that has changed since the attack
- what steps you took to reduce harm.
A quick way to record the information you need is to take a photo of your screen. It’s okay if you can’t record everything, but you should try to capture as much as possible, as fast as you can.
It’s important to record these details so you can:
- ask for help from a professional
- make an insurance, bank or legal claim after the attack
- submit a report to us
- tell your family, colleagues or authorities there was an attack.
This is to meet legal, customer or insurance obligations. Check if you have any urgent reporting requirements before moving to the next step.
Turn off the infected device
After you record details about the ransomware attack, turn off the infected device. Hold down the power button or unplug the device from the wall. This can help stop the ransomware from spreading.
Ransomware can spread across your network. Turn off other connected devices to help prevent it from spreading further.
Start with the devices that are most important to you, such as:
- Network Attached Storage (NAS) devices
- servers
- computers
- phones
- tablets
- any other device that stores valuable information.
Change important passwords
Some ransomware attacks can steal your passwords. You may not know what information was accessed so you should change your passwords as soon as possible.
Start with your most important accounts, including:
- cloud storage accounts
- email accounts
- bank accounts
- business accounts.
Use strong, unique passwords for each account. For extra protection, turn on multi-factor authentication where available.
What to do next
Now that you've responded to the ransomware attack, recover your data, restore affected devices and report the incident.
Check your backups
Before using a backup, check that it’s not infected with ransomware. Restoring an infected backup can spread ransomware or other malware back to your device.
Your backups may be affected if they were stored on the infected device or connected to the same network. If you think a backup is infected, don’t access it. Seek help from an IT professional.
Never pay a ransom. There is no guarantee you will recover your files. Paying the ransom doesn’t stop cybercriminals from sharing or selling your stolen data.
Learn more about backups.
Remove the ransomware
To scan for and remove the ransomware, use a trusted antivirus software.
You can also perform a factory reset on infected devices. This will permanently delete your data, so recover important information first.
Reset all drives and devices that were connected to the same network at the time of the attack.
Follow the manufacturer’s steps for your device:
- Apple iPhone, iPad or iPod
- Apple Mac devices
- Microsoft Windows devices
- Samsung phones
- Google Pixel phones.
Restore your information
After you remove the ransomware, you can reconnect your devices to your backups. You can now restore your information.
Only restore information from backups that you know are free from ransomware.
How to get help and report
If you experience a ransomware attack, you may need to report it and seek support. The steps you need to take depend on whether you’re an individual or a business.
Reporting responsibilities for businesses
You must report any ransom payment made by you or on your behalf, if your business:
- has an annual turnover of more than $3 million
- handles critical infrastructure assets under Part 2B of the Security of Critical Infrastructure Act 2018.
Submit the report within 72 hours through the ransomware payment and cyber extortion payment reporting form.
Depending on the impact of the attack, you may have to notify your customers of the attack.
You may need to report the incident to regulators, if your business:
- holds sensitive information, such as financial or personal information
- is part of a government supply chain.
If you think you need to make a report, consult with the Office of the Australian Information Commissioner. You can also seek legal or government support.
For individuals
If you’ve lost money or personal information, you should report to us.
Contact your bank or financial institution
Tell them your information may have been compromised.
Ask them to:
- monitor your accounts
- stop suspicious transactions
- freeze affected accounts or cards if needed.
Always use the organisation's official phone number or website.
Report the source of the ransomware
If you know how the ransomware was delivered report it to the relevant organisation. This may include a website, email or software provider. Reporting the source can help them investigate and protect others.
Report identity theft to the Australian Taxation Office
If you think someone has stolen your identity, contact the Australian Taxation Office.
Report any tax-related security issues as soon as possible to help protect your records and prevent fraud.
Keep records of your reports
Save any reference numbers, emails or correspondence relating to the incident. These records may help you get ongoing support or support further investigation.
If you want to talk to someone, call our hotline on 1300 CYBER1 (1300 292 371). We’re available 24 hours a day, 7 days a week.
Stay protected
Learn more about how to stay secure through our personal cyber security handbook.