The safest way to recover ransomware-encrypted files is to isolate the infected device, remove the ransomware, and restore the files from a clean backup or cloud version history. If no backup exists, identify the ransomware strain and check for a legitimate decryptor through the No More Ransom project. Do not pay the ransom as a first step. Payment does not guarantee that your files will be recovered.

Ransomware File Recovery at a Glance

Recovery option When it works Recommended action
Offline or external backup A clean backup exists from before the attack Restore it after cleaning or rebuilding the affected device
Cloud version history A cloud service saved earlier file versions Restore files from before the encryption
Official decryptor The ransomware has a known flaw or a released key Identify the strain and use a trusted decryptor
File recovery software Original files were deleted and their disk space was not overwritten Treat this as a specialist recovery case, not decryption
Ransom payment The attacker provides a working key Do not treat payment as a reliable recovery method
No backup or decryptor Strong encryption is in use and no key is available Preserve the files and seek professional help

1. Disconnect the Infected Device Immediately

Disconnect the affected computer from:

  • Wi-Fi
  • Ethernet
  • VPN connections
  • External hard drives
  • USB storage
  • Network shares
  • Mapped drives
  • Cloud synchronization applications

This can stop the ransomware from encrypting more files or reaching other computers. If multiple systems are affected, isolate the network instead of handling each device separately.

CISA recommends powering down a device only when it cannot otherwise be disconnected from the network. Shutting it down can destroy useful evidence stored in memory.

Do not delete the ransom note, encrypted files, suspicious programs or logs. Preserve:

  • The ransom note
  • Several encrypted files
  • The new file extension
  • Any attacker email address or cryptocurrency address
  • The approximate date and time of the attack
  • Screenshots of the ransom message

Businesses should contact their incident-response provider, internal security team, cyber-insurance provider and law-enforcement contacts before making major changes to affected systems.

2. Do Not Overwrite the Encrypted Files

Do not format the drive, reinstall Windows, run disk-cleaning tools or keep using the infected computer until you have chosen a recovery plan.

If possible, create a separate copy of the encrypted data. Use the copy for testing rather than experimenting with the only remaining files. Do not rename the encrypted files. Their extensions and filenames may help identify the ransomware family or match a decryptor.

Removing ransomware stops further encryption. It does not decrypt files that were already encrypted.

3. Identify Which Ransomware Encrypted the Files

Look for the ransomware name in:

  • The ransom note filename
  • The ransom note text
  • The extension added to encrypted files
  • The attacker's email address
  • A victim ID in the ransom message
  • The name of the malicious program or lock screen

The Crypto Sheriff tool from the No More Ransom project can help identify the ransomware strain. Identification matters because a decryptor for one ransomware family will not work on another. Crypto Sheriff also checks whether a known decryption solution is available.

Do not upload confidential business documents to an unknown website. If you use an identification service, submit only the minimum sample required and confirm that the service is operated by a reputable security organization.

4. Restore Files From a Clean Backup

A clean backup is usually the most reliable recovery option. Possible sources include:

  • An offline external drive
  • A backup server disconnected during the attack
  • A cloud backup
  • A virtual machine snapshot
  • Windows File History
  • macOS Time Machine
  • A previous system image

Before reconnecting a backup, confirm that the ransomware has been removed or rebuild the affected system. Ransomware can encrypt or delete backups that remain connected to an infected network.

CISA recommends restoring from offline, encrypted backups and testing their integrity before relying on them.

Organizations should restore to a clean network or rebuilt system rather than placing the backup directly on a compromised computer.

5. Recover Files From OneDrive

If the files were stored in OneDrive, use its ransomware recovery and version-history features.

Microsoft's recovery process is:

  1. Sign in to OneDrive.
  2. Review the suspicious files shown by the ransomware detection process.
  3. Clean or reset every device connected to the OneDrive account.
  4. Select Restore your OneDrive.
  5. Choose a time before the encryption occurred.
  6. Review the activity feed.
  7. Restore the affected files and folders.

Microsoft 365 subscribers can restore an entire OneDrive to an earlier point within the available recovery period. Microsoft currently documents this feature as covering up to 30 days. Files created after the selected restore point may be moved to the OneDrive Recycle Bin.

Clean every synchronized device before restoring OneDrive. Otherwise, the ransomware may encrypt the restored files again.

6. Use an Official Ransomware Decryptor

If no usable backup exists, check the No More Ransom Decryption Tools directory. It lists tools for selected ransomware families from organizations such as Avast, Emsisoft, Kaspersky and Trend Micro.

Use this process:

  1. Identify the ransomware family.
  2. Confirm that the decryptor supports the exact variant.
  3. Read the decryptor's instructions.
  4. Remove or isolate the malware.
  5. Make a backup copy of the encrypted files.
  6. Test the decryptor on a small sample.
  7. Check the recovered files before processing the full dataset.

A decryptor can fail even when the ransomware name appears to be correct. No More Ransom notes that some tools work only with a subset of available keys. A tool may become more effective later if researchers recover additional keys.

Download decryptors only from the security vendor or project linked by a trusted source. Search results and forum posts can contain fake decryptors that install more malware.

7. Check Cloud Version History and Previous Versions

Cloud storage services may retain earlier versions of files even when the current synchronized copies are encrypted. Check for:

  • File version history
  • Recycle Bin or deleted-file recovery
  • Folder restore
  • Snapshot recovery
  • Previous document versions
  • Backup recovery points

For OneDrive, Microsoft supports restoring an earlier file version or restoring the entire OneDrive to an earlier time. Permanently deleted files that are no longer in the Recycle Bin cannot be recovered through OneDrive.

A synchronized cloud folder is not automatically a ransomware-proof backup. If the encryption synchronized successfully, the cloud copy may also be encrypted unless version history or ransomware recovery is available.

8. What If There Is No Backup and No Decryptor?

If you have no backup and no decryptor, there may be no immediate way to decrypt the files when the ransomware uses strong encryption and no key or implementation flaw is available.

No More Ransom identifies three situations that can make decryption possible:

  • The ransomware author made a cryptographic or implementation mistake.
  • A master key was released publicly.
  • Law enforcement or researchers recovered keys from seized infrastructure.

If none of those options applies:

  1. Preserve the encrypted files.
  2. Keep the ransom note and other identifying information.
  3. Record the ransomware extension and variant.
  4. Do not pay a third party promising guaranteed recovery.
  5. Ask a reputable digital-forensics or incident-response provider to assess the system.
  6. Check trusted decryptor directories periodically.

Generic file-repair software will not normally decrypt ransomware. It may repair a damaged document, but it does not break the encryption applied by the ransomware.

9. Should You Pay the Ransom?

Do not pay the ransom unless qualified legal, security and business-risk advisers determine that there is no safer alternative. The FBI does not support paying ransomware demands because payment does not guarantee a working decryption key and can encourage further attacks.

Payment also may not resolve data theft. Attackers can copy data before encrypting systems, then publish or misuse that data even after receiving payment. CISA refers to this as data extortion or double extortion.

Before considering payment, obtain advice about:

  • Legal and regulatory obligations
  • Sanctions risks
  • Data-breach notification
  • Whether the attacker actually stole data
  • Whether the requested wallet or contact method is linked to a known criminal group
  • Whether a legitimate decryptor or backup is available

10. Report the Ransomware Attack

In the United States, individuals and organizations can report ransomware to the FBI's Internet Crime Complaint Center, known as IC3, or contact a local FBI field office. Include:

  • The ransom note
  • The ransomware name
  • The encrypted-file extension
  • The payment demand
  • The cryptocurrency address
  • The date of infection
  • Estimated losses

Businesses should also notify:

  • Their cyber-insurance provider
  • Their managed security provider
  • Legal counsel
  • Relevant regulators
  • Customers or partners if sensitive data may have been exposed

The Correct Recovery Order

Use this order to reduce further damage:

  1. Disconnect affected systems from networks.
  2. Preserve the ransom note and encrypted files.
  3. Identify the ransomware family.
  4. Check offline backups and cloud version history.
  5. Check No More Ransom for a matching decryptor.
  6. Clean or rebuild affected devices.
  7. Restore data to clean systems.
  8. Reset compromised passwords and credentials.
  9. Report the incident.
  10. Monitor for reinfection or unauthorized access.

The best recovery option is a known-clean backup. Without one, identify the ransomware and check for a trusted decryptor before considering any payment or third-party recovery service.