MALWARE AND PHISHING CyberArtical Editorial Team

What ransomware recovery actually involves, step by step

Hands typing on a laptop on a wooden desk, with a stethoscope lying beside it

Ransomware recovery stories tend to be written backwards, starting from the happy ending and working back through decisions that look obvious in hindsight. This is not one of those. It is the sequence the FBI and CISA actually document, in the order you would carry it out, with the uncomfortable parts left in — chiefly that the outcome is largely determined by decisions taken months before the screen goes red.

The facts that decide the outcome

  • The FBI “does not support paying a ransom in response to a ransomware attack”: payment “doesn’t guarantee you or your organization will get any data back” and it “encourages perpetrators to target more victims”.
  • The #StopRansomware Guide’s recovery-critical control is “offline, encrypted backups of critical data”, with the availability and integrity of those backups regularly tested.
  • CISA’s ransomware assistance: Central@cisa.dhs.gov or 1-844-729-2472. Report the crime at IC3.gov.
  • CISA on backup drives: “Avoid leaving the external drive connected when not actively backing up your data.”
  • The FTC’s clean-up sequence ends, if scanning fails, at recovering or reinstalling the operating system from the manufacturer’s instructions.

What this covers, and what it cannot

This describes recovery for a household or a small organisation with its own machines and its own backups. It is drawn from published federal guidance rather than from any particular incident, because the specifics of real incidents vary enormously and a narrative of one organisation’s week tells you very little about your own.

It is worth keeping the scale in proportion while you read. In the 2025 IC3 report ransomware accounted for 3,611 complaints and $32,320,105 in reported losses, with 63 new variants identified. That is far below phishing and spoofing at 191,561 complaints. Ransomware is not the most likely thing to happen to you; it is among the most disruptive.

What has to be true before the day, or recovery does not happen

  • Backups exist, are offline, are encrypted, and have been restored from at least once as a test. The #StopRansomware Guide specifies testing availability and integrity, not merely taking copies.
  • The backup drive is not permanently plugged in. CISA’s instruction is to avoid leaving an external drive connected when you are not actively backing up, and to store it safely.
  • Phishing-resistant MFA is on email, VPNs and anything reaching critical systems — this is the control most likely to have prevented the intrusion in the first place.
  • Software and operating systems are patched to current versions.
  • Someone knows the contact numbers without needing the network to look them up.

The sequence on the day

  1. Isolate the affected machines from the network and from any connected backup media, before anything else.
  2. Do not pay, and do not treat payment as a decision to make later under pressure. The FBI’s position is stated in advance for exactly this reason.
  3. Report it. Contact CISA at Central@cisa.dhs.gov or 1-844-729-2472 for technical assistance, and file with the FBI at IC3.gov. If money moved, add ReportFraud.ftc.gov, and if personal data was exposed, IdentityTheft.gov.
  4. Establish what the backups actually contain and how old they are. This is the point at which prior testing pays for itself or fails to.
  5. Rebuild rather than clean where you can. The FTC’s malware sequence ends at recovering or reinstalling the operating system using the manufacturer’s instructions, and for encrypted systems that is generally the safer starting point.
  6. Restore data to rebuilt systems, not to the machines that were compromised.
  7. Change credentials for accounts that were reachable from the affected systems, and turn on phishing-resistant MFA where it was not already on.

Why paying is not the shortcut it appears to be

The FBI’s wording is worth quoting exactly, because it is more specific than a moral position: paying a ransom doesn’t guarantee you or your organization will get any data back, and it encourages perpetrators to target more victims.

Both halves matter. The first is a statement about reliability — you would be buying a promise from someone whose business model is breaking promises. The second is about what your payment funds next.

The practical consequence is that the decision should be made before an incident, written down, and communicated to whoever will be in the room. A policy decided calmly in advance is the only kind that survives a morning like that one.

How to check the recovery actually worked

  1. Confirm restored data opens and is complete, not merely that files copied.
  2. Confirm the rebuilt systems are fully patched before they rejoin the network.
  3. Confirm no restored backup reintroduces the original access route — an old account, a stored credential, an unpatched application.
  4. Confirm MFA is enforced by trying to log in with a password alone and watching it fail.
  5. Disconnect and store the backup media again once the restore is finished.

The part that comes after the systems are back

Recovery of data is not recovery of the situation. If personal information was taken as well as encrypted — a common pattern, and the reason extortion and personal data breach both rank high in the IC3 complaint tables — then the people whose data it was have their own recovery to do, and their route is IdentityTheft.gov, which builds a personal recovery plan, tracks progress and prints pre-filled letters for credit bureaus, businesses and debt collectors.

The free credit freeze is the right thing to point them at as well: available at Equifax, Experian and TransUnion, free to place and to lift, lasting until lifted, with no effect on a credit score, and with the effect that nobody can open a new credit account in their name.

Then go back to the list of things that had to be true before the day, and make them true.

Sources: FBI — Ransomware · CISA — #StopRansomware Guide · FTC — How to recognize, remove, and avoid malware · FBI IC3 — 2025 Internet Crime Report · FTC — What to know about credit freezes and fraud alerts

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FBI, CISA and the FTC. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories