Cybercrime First Aid · Free tool by Paragamix GmbH

Ransomware first aid

Files locked? Ransom demanded? Work out your next steps without uploading anything.

1 · Describe the warning signs

What happened?

Broad choices only. No files, passwords, recovery keys or real incident details.

Your observations
More context optional

Only in this tab. No uploads, saved cases or AI requests. Clear discards working state; it cannot delete files you already saved.

Don’t wait to get help

Suspect ransomware? Start here.

  1. Limit spreading damage. Arrange safe, authorized network isolation of suspected systems. Isolation is not the same as powering off.
  2. Reach trusted help. Use a separate trusted device and a verified contact for IT or a qualified responder.
  3. Protect remaining copies. Do not connect backups, wipe devices or try random decryptors. Preserve evidence without delaying urgent containment.

Select what you see for a short, tailored brief. It is not a malware scan or a decryption service.

What this ransomware help tool can — and cannot — do

This is a first-aid decision aid, not a ransomware detector, removal tool or universal decryptor. It sorts broad observations into practical next steps. It cannot inspect your device, identify the attacker, confirm stolen data or authorize recovery.

Can I recover encrypted files?

Sometimes protected backups, file versions or a matching decryptor help. Availability depends on the incident and variant. Preserve originals and have a qualified responder assess the options. Paying does not guarantee recovery.

Should I turn the computer off?

Network isolation and shutdown have different consequences. Shutdown can destroy volatile evidence. If safe isolation is impossible and damage is continuing, an authorized responder may need to power down after weighing the risks. Never apply that rule blindly to safety-critical systems.

Does a threat prove I was hacked?

No. A message may contain leaked passwords without proving current access, but real data theft can occur without encrypting files. Independent evidence matters. The tool never labels a threat “definitely harmless”.

Where does my information go?

Choices and optional generic reminders stay in this tab’s memory. No application storage, uploads or third-party scripts. Download and print are explicit actions creating copies under your control. Ordinary page requests still reach our host; see the privacy notice.

Coordinating a team? Continue with the Incident Response Checklist for roles, the first hour, recovery and closure. Your first-aid answers are not transferred.

Sources and limits

US-oriented references; local reporting duties differ. Guidance version: . Developed with AI assistance; no independent human incident-response expert review or endorsement by the cited organizations is claimed. Methodology.

Cyber Decision Lab · Paragamix GmbH · cyberdecisionlab.com/ransomware-first-aid/ · September 9, 2026