A ransomware incident becomes an evidential problem the moment a screen displays a ransom note, files change extension, or a business discovers that data has been taken. The decisions made in the first hour can determine whether investigators can later establish how the attacker entered, what they accessed, and whether the resulting evidence will withstand scrutiny. Knowing how to investigate ransomware is therefore not simply an IT exercise. It is a controlled forensic process, often with legal, regulatory, contractual and commercial consequences.
Start by preserving the scene, not solving it
The immediate priority is to contain the incident without unnecessarily destroying evidence. Disconnect affected systems from networks where it is safe to do so, particularly if encryption is still spreading. Isolate devices from wired and wireless connections, disable compromised accounts where appropriate, and restrict remote access paths that may be under attacker control.
Do not assume that every affected machine should be switched off. A live computer may contain volatile evidence that disappears when power is removed, including running processes, network connections, encryption keys, logged-in sessions and malware resident only in memory. Equally, leaving a device online may permit further encryption, exfiltration or destructive activity. The correct decision depends on the threat’s current behaviour, the scale of compromise and the available expertise.
Record every action as it happens. Note the date, time, person responsible, system affected, action taken and reason for it. Take photographs or screenshots of ransom messages, unusual desktop backgrounds, error notices and visible file changes. Preserve the ransom note exactly as received, including any files, web addresses, cryptocurrency wallet details and communications instructions. These details can assist both technical analysis and intelligence-led enquiries.
Establish a defensible chain of custody
For organisations facing litigation, regulatory investigation, insurance scrutiny or a dispute with a supplier or employee, evidential integrity is not optional. Devices, removable media, servers and relevant cloud data must be identified, secured and handled in a way that can be explained clearly later.
Each item should be logged with a unique reference, a description, its location, the person from whom it was received and the dates and times of each transfer. Investigators should work from forensic copies rather than original media wherever possible. A forensic image is a bit-for-bit acquisition designed to preserve data, including deleted material and file-system artefacts that conventional copying may miss. Cryptographic hash values provide a means of demonstrating that the forensic copy has not altered.
This discipline matters where a party may challenge the investigation. An informal clean-up by internal IT staff can be necessary to restore operations, but it can also overwrite logs, remove malware and change timestamps. Separating recovery work from forensic preservation helps protect both objectives.
How to investigate ransomware: define the scope
Ransomware is rarely confined to the first computer that displays a ransom note. The visible encryption event may be the final stage of an intrusion that began days, weeks or months earlier. A proper investigation seeks to identify the initial access route, attacker movement, privilege escalation, data theft, encryption activity and any remaining persistence mechanisms.
Start with a working timeline. Compare the first known signs of compromise against authentication logs, endpoint telemetry, firewall records, VPN activity, email gateways, cloud audit trails and backup logs. Time settings must be understood before events are correlated. Systems may use different time zones, have inaccurate clocks or retain records in coordinated universal time.
The investigation should determine, as far as the available evidence permits, whether the attacker gained access through a phishing email, stolen credentials, an exposed remote service, an unpatched vulnerability, a third-party connection or misuse by an insider. It should also identify which accounts were used, whether administrative privileges were obtained, and whether the attacker accessed file shares, backups, virtual infrastructure or cloud services.
A useful scope assessment normally considers at least five evidence areas:
- affected endpoints and servers, including machines that show no obvious encryption;
- identity systems, such as Active Directory, VPN, email and privileged-access records;
- network and security logs showing lateral movement, command-and-control traffic or bulk data transfer;
- backup platforms, cloud storage and management consoles; and
- attacker communications, ransom notes, cryptocurrency demands and any claimed proof of stolen data.
Absence of obvious encryption is not proof that a device is unaffected. Attackers may retain remote access, create new accounts, alter scheduled tasks, deploy remote-management tools or remove logs to preserve a route back into the environment.
Capture volatile and technical evidence correctly
Where circumstances justify live examination, a trained practitioner may capture memory, running processes, active connections, logged-on users, mounted drives and other volatile information before a device is shut down. This can reveal the ransomware process, its command line, encryption configuration, keys or remnants of tools used by the intruder.
Forensic examination then moves to preserved images and collected logs. Analysts examine file metadata, event records, registry artefacts, browser history, email data, persistence locations, deleted material and traces of execution. They may identify the ransomware family through ransom-note wording, file extensions, executable characteristics, encryption behaviour and indicators found in system artefacts.
Attribution requires restraint. A ransomware group may publish a name, but that name alone does not establish who conducted the intrusion. Malware can be purchased or reused, infrastructure can be shared, and criminal groups deliberately make false claims. A defensible report distinguishes observed facts from technical assessment and from conclusions that cannot safely be drawn.
Investigate exfiltration as well as encryption
Many modern ransomware incidents involve double extortion. The attacker may steal data before encrypting systems, then threaten publication if payment is not made. The investigation must therefore address confidentiality as well as availability.
Look for unusual outbound network traffic, use of file-transfer tools, cloud-storage access, archive creation, compression utilities and connections to unfamiliar destinations. Review access to sensitive repositories, finance folders, HR records, client matter data, intellectual property and personal data. Retention periods matter here: if logs are overwritten quickly, preservation requests should be issued without delay.
It may not always be possible to prove exactly which files left an environment. Investigators should avoid presenting estimates as certainty. Where records show access to a repository but not individual downloads, that limitation should be stated plainly. Clear boundaries make an expert opinion more credible, not less useful.
Keep legal, operational and forensic decisions aligned
A ransomware response can involve senior management, IT, insurers, legal advisers, data protection specialists, law enforcement and affected clients. Their objectives overlap but are not identical. Operations may need rapid restoration; legal teams may need to preserve documents and consider disclosure obligations; investigators need stable, reliable evidence.
Early coordination prevents destructive duplication of effort. Agree who has authority to make containment decisions, who may communicate with attackers, how evidence will be stored, and how internal updates will be recorded. Where legal advice is sought, organisations should obtain clear advice on the handling and circulation of investigation material. Privilege is fact-specific and should not be assumed merely because lawyers are copied into an email.
Payment decisions are separate from forensic conclusions. Paying a ransom does not guarantee decryption, deletion of stolen data or an end to further demands. It may also create legal, sanctions, insurance and reputational issues. Whatever decision is taken, preserve the communication trail and document the reasons for it.
Produce findings that can be tested
The final deliverable should be more than a list of indicators or a technical dashboard. For a dispute, prosecution, internal disciplinary matter or board-level decision, the report must explain what was examined, how it was preserved, what was found, what was not found, and the limitations of the evidence.
A clear forensic report sets out the chain of custody, acquisition method, validation results, timeline, technical findings and reasoned conclusions. It separates fact from opinion and uses language proportionate to the evidence. This allows solicitors, insurers, management teams and, where necessary, the court to understand the basis for each conclusion.
Computer Forensics Lab approaches ransomware matters with this evidential discipline: preserving the material needed to understand the attack while helping clients obtain clear, independent findings for the decisions that follow.
The strongest response is not the one that merely returns systems to service quickest. It is the one that restores control while preserving the truth of what happened, before that truth is overwritten, disputed or lost.