STOP! Read this first (First 24 Hours)
If you suspect you've been hacked, follow these universal steps immediately.
1
Isolate but Don't Power Off
Disconnect the internet (Wi-Fi/Cable). Do not turn off the PC (you might lose evidence).
Disconnect the internet (Wi-Fi/Cable). Do not turn off the PC (you might lose evidence).
2
Secure Credentials
Use a different device to change passwords immediately. Enable 2FA.
Use a different device to change passwords immediately. Enable 2FA.
3
Call for Help
Contact HKCERT (8105 6060) for confidential advice.
Contact HKCERT (8105 6060) for confidential advice.
4
Scan & Backup
Run an antivirus scan. Backup clean files only. Do not backup infected files.
Run an antivirus scan. Backup clean files only. Do not backup infected files.
Create Your Recovery Plan
Are you an Individual or representing a Company?
Crisis Simulator
Test your decision making. What would you do?
[SCENARIO 1]
A red screen appears on your office computer:
"YOUR FILES ARE ENCRYPTED. PAY 5 BITCOIN OR LOSE EVERYTHING."
A red screen appears on your office computer:
"YOUR FILES ARE ENCRYPTED. PAY 5 BITCOIN OR LOSE EVERYTHING."