7 Core Rules for Responding to Ransomware and Infrastructure Breaches
In recent months, questions and requests for advice after various incidents have become increasingly common: some organizations find their systems encrypted, others discover that their infrastructure has been damaged or that corporate email accounts and credentials have been stolen.
In mature companies with established information security practices, such situations are already covered by documented incident response procedures, and teams know exactly who does what in the first minutes and hours. However, when an organization encounters an incident for the first time, the situation becomes far more difficult: everything is down, business stakeholders are anxious, information is scarce, and immediate action is required.
At such moments it is easy to act too aggressively—rebooting servers, deleting suspicious files, clearing logs, or starting restoration from backups—and thereby accidentally complicate any subsequent investigation.
1. Isolate affected systems
The first action is to disconnect compromised machines from the network, including LAN, Wi-Fi, and VPN connections. If the boundary of the incident is clear, isolate specific hosts or network segments. When the scope is unknown and the attack may still be spreading, temporarily shutting down the entire network can be preferable to allowing further lateral movement.
Isolation does not mean powering off the server. Systems should be left running whenever possible. The preferred method is to isolate the host externally—through switch ACLs, firewall rules, port shutdowns, or by physically unplugging the network cable. If software controls must be used, both inbound and outbound traffic should be blocked so that a compromised system cannot continue communicating with attacker infrastructure.
2. Do not reboot or power off systems indiscriminately
A common reaction is to reboot an encrypted server or power it off entirely. Rebooting or shutting down erases volatile information that may be critical for forensic analysis: contents of RAM, active connections, running processes, and other traces of activity at the time of discovery. Once the spread has been contained through isolation, leave systems in their current state unless active encryption or destruction is still occurring.
3. Do not delete or clean anything
Another instinctive response is to locate suspicious items and remove them immediately. Avoid running antivirus scans that delete files, clearing the %TEMP% folder, wiping event logs, or terminating processes simply because they appear unusual. Artifacts that seem irrelevant now—malware launch files, logs with timestamps, command-line arguments, or evidence of lateral movement—may later prove essential to reconstructing the attack.
4. Do not begin restoring from backups
When data is encrypted or systems are broken, the immediate impulse is often to restore from backups and resume operations. This step should be postponed until it is confirmed that the backups themselves are intact and that the attacker is no longer present in the environment. Restoring systems into a still-compromised network risks a second round of encryption. Offline backups should also be protected and not connected directly to potentially compromised infrastructure.
5. Close obviously compromised access channels
If the initial entry point is known—whether a specific account, VPN, exposed RDP, SSH, or email credential—that channel must be closed. When dealing with accounts, terminate active sessions and revoke tokens where possible. Perform these actions from the perimeter or a trusted system rather than from a potentially compromised host. Avoid mass password resets or broad infrastructure changes in the first minutes, as such actions create noise and alter the environment that investigators need to examine.
6. Document what happened
During an incident, details are easily forgotten. Spend a few minutes recording the facts: when the problem was first noticed, who observed it and what exactly they saw, which systems are confirmed affected, what was happening immediately before discovery, the exact time and time zone, and what actions administrators have already taken. Screenshots of ransom notes, error messages, and system states should also be captured. These records will be requested by any investigator and help reconstruct the timeline later.
7. Stop and wait for a plan
Once affected systems are isolated, obvious access channels are closed, the current state is documented, and further spread has been halted, further experimentation should cease. Installing multiple antivirus products, deleting files, rebuilding domain controllers, or returning servers to production without a coordinated plan can destroy evidence and complicate recovery. From this point, structured activities—artifact collection, entry-point identification, timeline reconstruction, and scope assessment—should begin according to a deliberate plan.
In summary, the seven rules are: isolate infected systems, avoid unnecessary reboots or shutdowns, do not delete or clean files, do not start backup restoration prematurely, close known compromised access paths, record observed facts and actions, and stop once containment is achieved so that subsequent work follows a structured plan. These steps are not a complete incident response framework, but they provide a solid starting point when an organization faces its first ransomware or infrastructure incident.
Related articles
International Law Enforcement Operation Dismantles KillSec Ransomware Group and Seizes 110 TB of Stolen Data
An international operation coordinated by Eurojust with support from Europol has dismantled the infrastructure of the KillSec ransomware group. Authorities seized five servers containing at least 110 terabytes of data stolen from victims and took control of the group's leak site domains. Three individuals were arrested, including a 16-year-old identified as the group's primary administrator and operator. The coordinated action involved law enforcement from nine countries and included eight searches across Spain, Greece, the United Kingdom, and Romania. KillSec has been active since 2024 and is linked to nearly one thousand ransomware incidents worldwide, primarily using a double-extortion model that combines data encryption with threats to publish stolen information. The seized data volume highlights the scale of the group's operations, which frequently targeted healthcare environments where system downtime directly impacts patient care.
ShinyHunters Claims Breach of FBI Recruitment Portal and Demands Eight-Figure Ransom
The hacker group ShinyHunters has publicly claimed responsibility for compromising the FBI's official recruitment website, FBIjobs.gov, asserting access to sensitive data belonging to nearly all FBI agents as well as job applicants. According to the group, the intrusion extended to multiple internal systems including criminal justice databases, human resources platforms, and Medlink. The attackers stated they exploited a zero-day vulnerability in Oracle PeopleSoft to achieve remote code execution and subsequently defaced the careers site with a fabricated seizure notice. The FBI has acknowledged awareness of unauthorized activity on the portal but has not confirmed any data theft or the scope of the intrusion. ShinyHunters is now demanding an eight-figure ransom payment, framing the amount as a minor fraction of its own resources and warning that time is limited. The operation appears to be retaliation for an FBI public statement issued in May regarding the group's prior activities. Independent verification of the claims remains unavailable, and experts note that extortion groups routinely exaggerate the value of stolen data to increase pressure on victims.
PAYLOAD Ransomware Seizes Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
Researchers at Kaspersky have documented an attack by the PAYLOAD ransomware that paralyzes an entire Windows domain without encrypting a single file. Instead of encryption, the operators leverage native Windows policy mechanisms to enforce disruption across the environment. The core of the attack is a malicious Group Policy Object named PAYLOAD linked directly to the root of the Active Directory domain. This placement allows the policy to reach virtually every connected device, turning it into a corporate-wide disruption tool. Through the GPO, the group distributes ransom notes from SYSVOL, replaces wallpapers and lock screens with extortion images displaying the message Welcome to Payload, and disables local administrator accounts on affected machines. A second policy object named win Firewall Off disables the Windows firewall across the entire fleet, increasing exposure during the operation. Initial access occurred in April 2026 via a compromised legitimate domain account on a FortiGate SSL VPN, with possible entry vectors including phishing, password spraying, and credential stuffing. The victim is a manufacturing company in the Middle East. The extortion model combines data theft with operational shutdown, delivering effects similar to traditional ransomware but without any decryption key to negotiate.
Ransomware Operators Hijack Active Directory via GPO to Lock Companies Without Encryption
Kaspersky researchers have uncovered a new extortion campaign called Payload that targets manufacturing companies by compromising privileged accounts and seizing control of Active Directory. Instead of deploying traditional ransomware encryptors, the attackers created a Group Policy Object named Payload linked to the domain root. This GPO automatically changed desktop wallpapers and lock screens across all systems, displayed ransom demands, and disabled administrative accounts after policy refresh. The group also exfiltrated valuable corporate data before the lockdown and later published it on the dark web to increase pressure on victims. Because the attack relied entirely on legitimate Windows mechanisms such as VPN access and Group Policy, conventional antivirus solutions proved ineffective. Experts recommend monitoring GPO changes, enforcing phishing-resistant MFA on VPN and admin systems, and applying least-privilege principles to limit the impact of credential compromise.