Quick response guides for common digital emergencies
1 Contain
Stop the damage immediately
- Disconnect from the internet: Pull the ethernet cable or turn off Wi-Fi immediately. This stops the spread and halts data exfiltration.
- Do NOT pay a ransom: Payment doesn’t guarantee recovery and funds criminal operations.
- Document everything: Photograph any ransom notes or error messages from your phone, not the infected computer.
- Secure your accounts: Change passwords for important accounts (bank, email) from a DIFFERENT, clean device.
- Isolate external storage: Do not plug USB drives or external drives into the infected machine. They can be encrypted or infected too.
2 Recover
Get back to normal
- Scan in Safe Mode: Boot into Safe Mode and run a full antivirus scan (Windows Defender, Malwarebytes, or Bitdefender). Run multiple scans with different tools for thoroughness.
- Check for free decryptors: For ransomware, visit nomoreransom.org to search for free decryption tools matching your specific ransomware strain.
- Restore from backup: Recover files from your external drive or cloud backup, but only AFTER confirming the malware has been fully removed.
- Try data recovery: If you have no backup, attempt data recovery software before resorting to a full system wipe.
- Update everything: After cleanup, update your OS and all software to the latest versions to close the vulnerabilities that may have been exploited.
- Change all passwords: Reset passwords for any accounts you accessed on the infected machine. Credentials may have been silently captured.
3 Prevent
Stop it from happening again
- Find the entry point: Identify how the malware got in (phishing email, malicious download, unpatched software, or infected USB) so you can avoid it next time.
- Keep software updated: Many attacks exploit known, already-patched vulnerabilities. Enable automatic updates for your OS and applications.
- Use real-time antivirus: Keep antivirus protection active and its definitions current.
- Follow the 3-2-1 backup rule: Maintain 3 copies of your data, on 2 different media types, with 1 copy offline or offsite.
- Never enable macros in documents from untrusted sources.
- Download from official sources only. Avoid pirated software, random “codec” installers, and unverified links.
- Enable Windows Controlled Folder Access to block unknown programs from modifying your Documents and Pictures folders.
Related Digital Chores: Enable Auto Updates, Implement Backup Strategy, Practice Vigilant Email Hygiene
Key Contacts
- No More Ransom Project: nomoreransom.org (free decryption tools and ransomware identification)
- FBI IC3: ic3.gov (report cybercrime incidents)
- CISA: cisa.gov/stopransomware (government ransomware resources)
- Malwarebytes: malwarebytes.com (free malware scanner)
Outside the United States? View international reporting resources
(If you are a victim of fraud or cybercrime outside the U.S., or the incident involves international parties, here are some resources in other countries/regions.)
Canada
The central agency for fraud and scam reporting in Canada is the Canadian Anti-Fraud Centre (CAFC) – website: antifraudcentre.ca. You can report scams, identity theft, fraud attempts, etc., through their online system or by phone (1-888-495-8501). The CAFC is jointly operated by the RCMP, Ontario Provincial Police, and Competition Bureau, and they collect intelligence on fraud schemes.
If you are a victim of identity theft or have lost money, you should also report it to your local police in Canada (bring any evidence, like bank statements or emails). The police might give you an occurrence number, which can help with bank investigations or credit bureau communications.
Canada has a national cybercrime reporting system under development – currently, the advice is to use CAFC for cyber-fraud, and if it’s a cyber incident like hacking without fraud, to report to local police or RCMP.
Canadian credit bureaus (Equifax Canada, TransUnion Canada) also offer fraud alerts and credit freezes (credit freezes are often called “credit report consumer declarations” in Canada and function a bit differently than in the US, sometimes with fees – check their sites for the latest process).
United Kingdom
The UK’s national reporting center for fraud and cybercrime is Action Fraud – website: actionfraud.police.uk. If you’re in England, Wales, or Northern Ireland and you’ve been scammed, defrauded, or hit by cybercrime, report it to Action Fraud. You can do so via their online tool 24/7, or by phone at 0300 123 2040 (available Mon–Fri 8am-8pm).
When you report online, you can create an account to get updates or report as a guest. If you’re in Scotland, Action Fraud does not cover you – instead, report directly to Police Scotland (call the non-emergency line 101 or go to a local station). In an immediate emergency or if a crime is in progress, always dial 999 in the UK.
Action Fraud will give you a crime reference number and your report feeds into the National Fraud Intelligence Bureau. For cybersecurity incidents affecting organizations, the UK has the National Cyber Security Centre (NCSC).
European Union
There isn’t a single EU-wide consumer cybercrime hotline, as law enforcement is handled by individual countries. If you’re in an EU country and fall victim to cybercrime or fraud, report it to your national police or relevant authority.
Many EU countries have online fraud/cybercrime reporting platforms or centralized offices: for example, France has a platform called “PHAROS” for reporting online illicit content; Germany has local police portals in each state; the Netherlands has a centralized reporting site (politie.nl) for internet fraud; etc. You can usually find this info on your country’s police or interior ministry website.
Europol (the EU’s law enforcement cooperation agency) does not take direct citizen reports – they advise victims to go through national authorities. However, Europol’s European Cybercrime Centre (EC3) website provides general guidance and resources on cybercrime and how to report in each EU country.
The EU also has OLAF (European Anti-Fraud Office), but OLAF deals with fraud involving EU funds or EU institutional staff – not personal identity theft or scams.
One EU-wide resource: econsumer.gov – an initiative by the International Consumer Protection Enforcement Network (ICPEN) – allows consumers in many countries (including EU members) to report international scams.
Australia
Australia has a national cybercrime reporting portal called ReportCyber, which replaced the older ACORN system. To report cybercrime (such as hacking, ransomware, online fraud) go to the Australian Cyber Security Centre’s ReportCyber page at cyber.gov.au/report and submit a report.
If it’s an immediate threat to life or safety (including something like an active extortion threat), call 000 (Australia’s emergency number) right away.
For other scams, particularly those targeting consumers (like dating scams, investment scams, etc.), you can also report to the Australian Competition & Consumer Commission (ACCC) Scamwatch at scamwatch.gov.au.
Additionally, if you experience identity theft in Australia, you can get support from IDCARE (idcare.org), a national identity & cyber support service that helps individuals navigate the recovery process. They’re not a government agency but are endorsed by the government as a helpful resource.
International Resources Summary
No matter where you are, if you’re a victim of cybercrime or fraud, report it to your local authorities – police, consumer protection agencies, or specialized cybercrime units. Many countries have similar setups to the U.S.: a consumer fraud reporting center, credit bureaus for credit issues, and emergency services for urgent situations.
If you’re traveling or a scam crosses borders, you can also file reports in multiple jurisdictions (e.g., report to your home country authorities and the country where the scammer is based if known). Agencies like Interpol and Europol facilitate info-sharing between countries.
For example, Interpol has an initiative called the International Consumer Protection and Enforcement Network and will coordinate if you report through econsumer.gov or through your national police who then reach out internationally.
The key is to use official channels – many of the same tips (don’t pay scammers, preserve evidence, alert banks, etc.) apply globally. Laws and processes vary, but the goal is to document the incident and get help. And always remember to follow up on protecting yourself (freezes, alerts, changing passwords) in addition to making reports.