← Resources

What Happens During a Ransomware Incident

A clear, honest walkthrough of what actually happens if ransomware hits your business, detection through recovery.

Created September 7, 2026

What Happens During a Ransomware Incident

This is the worst-case scenario, and it deserves a straight answer, not a marketing one. Here's what actually happens, step by step, if ransomware gets into your environment. If you're looking for what to do personally in the moment, see I Think I Clicked Something Bad, Now What? instead, this guide is the bigger picture behind it.

Detection & Containment

In a lot of cases, Huntress catches ransomware behavior before a person does, and can isolate the affected device from the network automatically the moment it's confident something real is happening. If a person notices first (a ransom note, files that suddenly won't open, everything running strangely), the moment we're notified, the same containment happens: get the affected device(s) off the network and stop the spread before anything else.

Assessing the Scope

Before touching anything else, we figure out what's actually been hit: which devices, what data, how it got in, and whether it's still spreading. This isn't a step we skip to move faster, restoring the wrong thing, or restoring before containment is confirmed, can make everything worse.

Recovery: Restoring From Clean Backups

This is the part the rest of your setup has been quietly built around. Your backups are stored with write-locks enabled (see Where Backups Are Stored & How They're Protected), which means even an attacker with valid admin credentials can't delete or encrypt your way out of a clean recovery point. We restore from the most recent backup taken before the infection (see How Backups Work for the schedule), not from whatever the attacker left behind.

Recovery time depends on scope, how much needs restoring and from how far back. The standard backup schedule is built for reliable recovery, not a guaranteed number of hours. If a faster, tighter recovery window matters enough to your business to plan around in advance, faster RTO/RPO options exist and are configured per-tenant, ask your account manager before an incident, not during one.

Should You Pay the Ransom?

Our recommendation is no. There's no guarantee a ransom payment actually gets you a working decryption key, and paying funds the same group to do this again, to you or someone else. Our entire approach is built around not needing that option in the first place, a clean, immutable recovery path means the ransom demand doesn't have leverage over you.

Insurance & Legal Considerations

  • If you carry cyber insurance, loop your carrier in early. Many policies have a notification window, and involving them after the fact instead of during can affect coverage.
  • Depending on what data was involved, you may have breach notification obligations under state or industry regulations. That's a legal question, not a technical one, we're not your attorney, but we can provide the technical documentation and timeline your legal counsel will need to make that call.

After Recovery

  • Any credentials that may have been exposed get rotated, including anything stored outside Keeper that shouldn't have been.
  • We'll walk through what allowed the incident to happen and what's changing as a result, a ransomware incident is also the clearest possible signal about where a gap actually was.

If You Suspect an Active Incident Right Now

Don't wait for a good time, don't finish reading this guide first, call the emergency line immediately:

  • Phone: (404) 387-0435

Need Help?

If you run into any issues, reach out to the Triumphant support team: