Overview
This article provides a low-risk, evidence-driven troubleshooting path for ransomware suspected: what to do immediately. Work from identity and service checks toward more disruptive actions, and stop before a change could cause data loss, broaden access, weaken security, or interrupt other users.
Why this happens
Security warnings and suspected account compromise require evidence preservation, safe containment, credential protection, and coordinated administrator-side review rather than ordinary trial-and-error troubleshooting.
Before You Begin
- Preserve screenshots, alert text, times, sender addresses, and other useful evidence.
- Use a known-clean device for sensitive account changes when practical.
- Do not approve unexpected MFA prompts or communicate secrets to an unverified requester.
- If ransomware or active compromise is suspected, prioritize containment and escalation over ordinary troubleshooting.
Navigation reference: Official work account portal > Security.
Click-by-Click Troubleshooting
Step 1: Disconnect the affected device
Action: Disconnect the device from Wi-Fi and unplug Ethernet if ransomware activity is active or files are rapidly changing.
Why this matters: Network isolation can limit spread to shares and other systems.
What to look for: Look for ransom notes, mass file renames, inaccessible files, or rapid encryption activity.
Expected result: The affected endpoint should no longer communicate with the business network.
Step 2: Do not power off unless directed
Action: Leave the device powered on unless there is an immediate safety concern or IT specifically directs shutdown.
Why this matters: A running system may contain volatile evidence useful for investigation.
What to look for: Do not continue using applications or browse through affected folders.
Expected result: The device should remain isolated and preserved for response.
Step 3: Protect shared storage
Action: From a known-clean device, notify IT immediately so network shares, sync clients, or compromised accounts can be contained centrally.
Why this matters: Ransomware can propagate through synchronized or mapped business storage.
What to look for: Report which shares, OneDrive/SharePoint locations, or mapped drives were connected.
Expected result: IT should be able to evaluate and contain shared-storage exposure.
Step 4: Preserve the ransom note and timeline
Action: Photograph or capture the ransom message, filenames, time first observed, and actions immediately before the event.
Why this matters: This evidence helps determine ransomware family, scope, and entry point.
What to look for: Do not contact the attacker or run random decryptors.
Expected result: The incident timeline and visible indicators should be preserved.
Step 5: Use the incident channel
Action: Contact the approved security/IT escalation channel and identify this as suspected ransomware.
Why this matters: Ransomware is a business incident, not a routine workstation problem.
What to look for: Provide device name, user, location, and affected resources.
Expected result: The incident should be actively owned by the response team.
Step 6: Do not restore until containment is confirmed
Action: Wait for IT to confirm the threat is contained before restoring files, reconnecting the device, or re-enabling sync.
Why this matters: Premature recovery can re-encrypt restored data or spread the incident.
What to look for: Confirm clean recovery source, containment, and credential remediation.
Expected result: Recovery should begin only after the environment is considered safe.
What to Look For
- Whether the issue affects one user/device or multiple users.
- Whether a clean browser or alternate approved client changes the result.
- Whether the error points to identity, permission, licensing, service, device, or network state.
- Whether the same controlled test succeeds after the targeted correction.
When to Stop
When to Contact IT
Contact J3 Systems Group if the issue remains unresolved, affects multiple users, requires administrator-level changes, involves security or data-loss risk, or the next step would be disruptive. Include article code KB-07.008, the affected account/device/resource, exact error, time observed, and the results of the controlled tests above.
Need help with this issue?
J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.
Contact J3 Systems GroupAuthoritative references
Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.