Open · closes 7 PM 🚨 Emergency EN ES
Cybersecurity · May 20, 2026

Ransomware hit my Miami business — what is the first call?

Your screen shows a ransom note demanding bitcoin. Files won't open. Employees are calling you. What you do in the next 60 minutes determines whether this costs you a weekend or your business. Here's the playbook we use when Miami clients call us at 2am.

Step 1: Unplug network cables (right now)

The single most important action: physically disconnect the affected machines from the network. Yank the ethernet cable, turn off the Wi-Fi. This stops the malware from spreading to other machines, file shares, and backups. Do NOT turn off the computer — some forensic evidence is in volatile memory.

Step 2: Take photos of the ransom note

Use your phone. Photograph:

  • The ransom screen with the wallet address
  • Any file extensions on encrypted files (e.g., .locky, .conti, .lockbit) — these tell us which strain
  • The Bitcoin amount demanded
  • The countdown timer if any

Step 3: Call us, not the FBI yet

Counter-intuitive but: call your incident response team first. We can be on a call within 15 minutes, on-site within 90, and we know which strains have free decryptors (some do). Once we have a handle on the situation, we'll help you decide whether/when to involve law enforcement, your insurance, and your customers.

Our 24/7 emergency line: (786) 422-0705

Step 4: Do NOT

  • Do not pay the ransom immediately. Many strains have free decryption tools available. Paying funds the criminal economy and only 65% of payers get their data back.
  • Do not restart the affected machines. Volatile memory may contain the encryption key.
  • Do not delete the ransom note. It identifies the strain.
  • Do not tell employees on Slack/Teams. Assume the attacker is listening; use phone calls and text only.
  • Do not negotiate directly with the attacker. Use a professional negotiator if it comes to that.

Step 5: Inventory what you can

Make a list of:

  • Machines affected vs unaffected
  • What server shares were mounted
  • When you last verified backups worked
  • Customer/regulatory data potentially exposed (HIPAA, PCI-DSS, etc.)

What we do when we arrive

  1. Identify the ransomware strain and check for a free decryptor
  2. Determine the entry point (was it phishing, RDP, an exposed VPN?)
  3. Isolate and image affected machines for forensics
  4. Validate the backups are clean and restorable
  5. Restore from the last clean backup, not from infected machines
  6. Harden the network so reinfection doesn't happen Monday morning
  7. Help you with breach notification if regulated data was exposed

Average recovery time

  • With current, tested backups: 24-48 hours
  • With backups but never tested: 3-5 days
  • No backups: a week or more, with significant data loss

That's why we test backups monthly for managed clients.

Right now: if you're reading this because you're under attack, call (786) 422-0705. We'll be on a video call within 15 minutes. If you're reading this proactively, take our free Ransomware Risk Score to see how vulnerable you'd be.

Got this issue with your device?

Free diagnosis. We call before end of day.

Sister Company · 123 Web Mobile

We also build websites & run marketing.

Professional web design, Miami local SEO, Google Ads, social media, and marketing automation — built by the same bilingual team you already trust for your IT.

11+ years serving Miami
12,000+ devices repaired
5.0★ Google rating
24/7 emergency support
100% satisfaction guaranteed
Call Us WhatsApp Book Now