What to Do If Your Files Suddenly Don't Open? A Collection of Ransomware Response Resources
Collection Security 2026.07.26

What to Do If Your Files Suddenly Don't Open? A Collection of Ransomware Response Resources

Materials for reducing infection spread and checking official reporting, backup, and recovery options

If the extensions of your documents and photos suddenly change or if an alert demanding money appears, you might suspect ransomware. In such cases, contacting the numbers in the alert in a hurry or downloading an unverified decryption program can lead to further infection and fraud.

Disconnect suspected infected devices from the network and external storage devices, and if the device belongs to an organization, report it to the security officer before turning off the power or deleting files. Take photos of the memo screen, altered extensions, occurrence time, and recently executed files. Also, check for any abnormalities in shared folders on other devices within the same network.

The possibility of recovery depends on the type of ransomware, backup status, and extent of encryption, and no one can guarantee a specific outcome. There is also no guarantee that attackers will decrypt files after receiving payment.

This list compiles resources for domestic reporting and consultation, international decryption tool verification, and official recovery materials for operating systems and the cloud. Regularly having offline or isolated backups and restoration tests is the most realistic preparation. After an incident, do not think of infection removal and file recovery as the same task; proceed with validated procedures for each.

KISA Ransomware Reporting and Consultation

KISA Ransomware Reporting and Consultation is an official function or service that can be used for reporting and consulting on domestic ransomware incidents. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

Right after discovering a ransom note or file encryption, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is required, this record can serve as explanatory material for the situation.

Before reporting, document the ransom note, extension, and occurrence time, and preserve original files. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 한국인터넷진흥원 KrCERT/CC 주요 용도 국내 랜섬웨어 침해사고 신고와 대응 상담 확인 시점 랜섬노트나 파일 암호화를 발견한 직후 분류 공식 신고 주의사항 신고 전 랜섬노트·확장자·발생 시각을 기록하고 원본 파일을 보존한다.

No More Ransom

No More Ransom is an official function or service that can be used for identifying types of ransomware and verifying public decryption tools. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When checking for the existence of official tools, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is needed, this record can serve as explanatory material for the situation.

Verify the applicability of the tools and confirm with the expert regarding copies of important originals. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 Europol 및 협력기관 주요 용도 랜섬웨어 종류 식별과 공개 복호화 도구 확인 확인 시점 공식 도구가 존재하는지 확인할 때 분류 복호화 자료 주의사항 도구의 적용 대상을 확인하고 중요한 원본의 복사본에서 전문가와 검증한다.

CISA StopRansomware

CISA StopRansomware is an official function or service that can be used to provide integrated prevention, response, and reporting materials for organizations. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When preparing or reviewing incident response procedures for businesses or organizations, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is required, this record can serve as explanatory material for the situation.

Overseas guides do not replace domestic reporting obligations and internal procedures. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 CISA 주요 용도 조직용 예방·대응·보고 자료를 통합 제공 확인 시점 기업이나 기관의 사고 대응 절차를 준비하거나 점검할 때 분류 대응 가이드 주의사항 해외 가이드는 국내 신고 의무와 조직 내부 절차를 대체하지 않는다.

Microsoft Ransomware Protection

Microsoft Ransomware Protection is an official function or service that can be used to guide protective features such as Windows Security and Controlled Folder Access. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When checking preliminary defensive settings on Windows PCs, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is needed, this record can serve as explanatory material for the situation.

Check for conflicts with business apps but do not follow unclear guidance to turn off protective features. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 Microsoft 주요 용도 Windows 보안과 제어된 폴더 액세스 등 보호 기능 안내 확인 시점 Windows PC의 사전 방어 설정을 점검할 때 분류 Windows 보호 주의사항 업무 앱과 충돌 여부를 확인하되 보호 기능을 끄라는 불명확한 안내는 따르지 않는다.

Windows File History

Windows File History is an official function or service that can be used to guide the version backup and restoration processes of personal files. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When preparing backups or confirming recovery possibilities before infection, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is needed, this record can serve as explanatory material for the situation.

Do not reconnect backup drives before the infection has been removed. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 Microsoft 주요 용도 개인 파일의 버전 백업과 복원 절차를 안내 확인 시점 감염 전 백업을 준비하거나 복원 가능성을 확인할 때 분류 로컬 백업 주의사항 감염이 제거되기 전에는 백업 드라이브를 다시 연결하지 않는다.

OneDrive File Restore

OneDrive File Restore is an official function or service that can be used to guide the restoration of the entire OneDrive to a previous point in time. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When a mass change or encryption has been synchronized to the cloud, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is needed, this record can serve as explanatory material for the situation.

Check the restoration period and pricing conditions, and first stop synchronization with the infected device. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 Microsoft 주요 용도 OneDrive 전체를 이전 시점으로 되돌리는 공식 기능 안내 확인 시점 대량 변경이나 암호화가 클라우드에 동기화됐을 때 분류 클라우드 복원 주의사항 복원 가능 기간과 요금제 조건을 확인하고 감염 기기 동기화를 먼저 중지한다.

Google Drive File Recovery Help

Google Drive File Recovery Help is an official function or service that can be used to verify recovery paths for deleted or modified Drive files. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When you notice damage or mass changes to Google Drive data, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is needed, this record can serve as explanatory material for the situation.

Before recovery, check the session and password of your Google account to prevent re-infection. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 Google 주요 용도 삭제·변경된 Drive 파일의 복구 가능한 경로를 확인 확인 시점 Google Drive 자료의 손상이나 대량 변경을 발견했을 때 분류 클라우드 복구 주의사항 복구 전에 Google 계정의 세션과 비밀번호도 점검해 재침해를 막는다.

Apple Time Machine Recovery

Apple Time Machine Restore

Apple Time Machine Restore is an official procedure that can be used to restore backups of files and systems on Mac. Instead of judging by the name alone, it's important to check the operating entity and official domain together first.

When checking if there is a Time Machine backup before the infection, calmly review recent records and guidance on the usage screen, and capture any unfamiliar items with time, device, and location. If recovery or reporting is needed, this record can serve as explanatory material for the situation.

Do not hastily connect backup disks to a Mac where the infection status is unclear. Do not use it to test other people's accounts or systems and only use it within your ownership or explicit permission.

운영 주체 Apple 주요 용도 Mac의 파일과 시스템 백업을 복원하는 공식 절차 확인 시점 감염 전 Time Machine 백업이 있는지 확인할 때 분류 Mac 백업 주의사항 감염 여부가 정리되지 않은 Mac에 백업 디스크를 성급히 연결하지 않는다.

In a ransomware incident, preserving evidence and originals is more important than 'quick decryption' as a first step. Even for personal PCs, if shared folders, NAS, or cloud sync folders were connected, you should broadly check the impact range.

While there are public decryption tools for some types, there is no万能 program that fits all variants. Do not select a tool solely based on similar file extensions or monetary demands.

Version history in the cloud or operating system backups provide a way to revert to a point before infection, but synchronized files and backups might be damaged together. Connecting restoration storage devices without confirming that the infection has been removed can endanger backups. After recovery, also check account passwords and remote access settings.

Once the incident is over, it is important to test whether backups can actually restore rather than just having backups. Keep important data in copies separate from working devices, and maintain upgrades, multi-factor authentication, and the principle of least privilege. Documenting the reporting records and response process simply can help reduce the chance of suffering from the same route again.

한눈에 보기 8개
KISA Ransomware Reporting and Consultation
한국인터넷진흥원 KrCERT/CC · 국내 랜섬웨어 침해사고 신고와 대응 상담 · 랜섬노트나 파일 암호화를 발견한 직후 · 공식 신고 · 신고 전 랜섬노트·확장자·발생 시각을 기록하고 원본 파일을 보존한다.
No More Ransom
Europol 및 협력기관 · 랜섬웨어 종류 식별과 공개 복호화 도구 확인 · 공식 도구가 존재하는지 확인할 때 · 복호화 자료 · 도구의 적용 대상을 확인하고 중요한 원본의 복사본에서 전문가와 검증한다.
CISA StopRansomware
CISA · 조직용 예방·대응·보고 자료를 통합 제공 · 기업이나 기관의 사고 대응 절차를 준비하거나 점검할 때 · 대응 가이드 · 해외 가이드는 국내 신고 의무와 조직 내부 절차를 대체하지 않는다.
Microsoft Ransomware Protection
Microsoft · Windows 보안과 제어된 폴더 액세스 등 보호 기능 안내 · Windows PC의 사전 방어 설정을 점검할 때 · Windows 보호 · 업무 앱과 충돌 여부를 확인하되 보호 기능을 끄라는 불명확한 안내는 따르지 않는다.
Windows File History
Microsoft · 개인 파일의 버전 백업과 복원 절차를 안내 · 감염 전 백업을 준비하거나 복원 가능성을 확인할 때 · 로컬 백업 · 감염이 제거되기 전에는 백업 드라이브를 다시 연결하지 않는다.
OneDrive File Restore
Microsoft · OneDrive 전체를 이전 시점으로 되돌리는 공식 기능 안내 · 대량 변경이나 암호화가 클라우드에 동기화됐을 때 · 클라우드 복원 · 복원 가능 기간과 요금제 조건을 확인하고 감염 기기 동기화를 먼저 중지한다.
Google Drive File Recovery Help
Google · 삭제·변경된 Drive 파일의 복구 가능한 경로를 확인 · Google Drive 자료의 손상이나 대량 변경을 발견했을 때 · 클라우드 복구 · 복구 전에 Google 계정의 세션과 비밀번호도 점검해 재침해를 막는다.
Apple Time Machine Recovery
Apple · Mac의 파일과 시스템 백업을 복원하는 공식 절차 · 감염 전 Time Machine 백업이 있는지 확인할 때 · Mac 백업 · 감염 여부가 정리되지 않은 Mac에 백업 디스크를 성급히 연결하지 않는다.

이 포스팅은 쿠팡 파트너스 활동의 일환으로, 이에 따른 일정액의 수수료를 제공받습니다.

댓글 0

로그인 후 댓글을 작성할 수 있습니다.

첫 댓글을 남겨보세요.

이런 리스트는 어때요?

이런 리스트도 추천해요

🎲

여기서 멈추기엔 아쉽잖아?

다음에 뭘 볼지 고민하는 시간이 제일 아까워.
주사위가 대신 골라줄게 — 무슨 리스트가 튀어나올지는 굴려봐야 알지.
안 누르면… 평생 궁금하지 않겠어? 👀

All menu
Login required
Log in
Categories
Language
Display mode

Drum roll… picking a list!

모하지
Use Mohazi as an app
Open it from your home screen and browse faster.
On iPhone, tap the Share button at the bottom of Safari, then choose “Add to Home Screen” to use it like an app.