Skip to main content
Runs in your browser · Nothing you type is sent anywhere

Hit by ransomware?
Start with what it is

The family name decides the next three questions: whether a free decryptor exists and whether it reaches your files, whether the operator took your data out before encrypting it, and whether a sanctions listing touches anyone you would be paying. Three things already on your screen name it.

We do not ask for a file. Uploading a document to identify it means handing a third party the data you are trying to protect, at the moment you least want to. The extension and the note are enough for most families, and the note is the attacker’s text rather than yours.

Step 1 of 3

What are you seeing?

Tick everything that is true. This decides which guides you get at the end. It does not affect the identification — four checkboxes cannot narrow a family, and we will not pretend they can.

The family records were assembled from No More Ransom, the CISA #StopRansomware advisories and the OFAC, UN and EU listings, and last reviewed on . A decryptor’s scope can change in days: Akira’s was published on 29 June 2023 and the flaw it relied on was fixed on 2 July 2023. Check the sanctions position again at the time of the incident rather than relying on a date already printed.

Working this right now?

Tell us what you are seeing, what is already isolated, and the time you noticed it or were brought to notice — whichever came first is what starts the six hours. Security Brigade works incidents 24/7, on +91 22 4164 2220.

Describe the incident