Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Victim Q&A · Aftermath

How do we report a ransomware attack to the police, and what should we prepare?

Short answer

In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.

Key points

  • Filing a police report and reporting an incident to regulators such as the CAC are separate duties, and many organisations need to do both.
  • Police channels: call 110 or file in person locally; the cybercrime portal (cyberpolice.mps.gov.cn) is for tip-offs and does not handle emergencies.
  • For incidents rated relatively major or above, critical information infrastructure operators report within 1 hour; other network operators report to the provincial CAC office within 4 hours.
  • Reporting and recovery can run in parallel, provided evidence is preserved first and recovery works on copies.
  • When filing in person, check the evidence receipt list and keep the case acceptance receipt.
  • Whether a case is opened is decided by the police; a forensic report is supporting material, not an investigative conclusion.

In this order

What to do now

  1. Secure the scene before you file

    Isolate affected hosts without powering them off, keep the ransom note, encrypted samples and the antivirus quarantine, and pause every reinstall, format, log cleanup and snapshot rollback. You do not need to finish recovery before reporting, but evidence that gets overwritten cannot be recovered. The full first-hours sequence is in what to do after a ransomware attack.

  2. Name a point of contact and start a timeline

    Appoint one person who knows the facts and one technical contact. Start the timeline now: when the anomaly was first noticed and by whom, known suspicious logons and encryption times, and every action taken since discovery - who did what to which machine, and when. The police statement, the regulatory report and the forensic work all draw on it.

  3. Decide whether a regulatory report is due

    Rate the incident against the grading guide annexed to the CAC's incident reporting measures. If it is relatively major or above, critical information infrastructure operators report to their protection department and the police within 1 hour, and other network operators report to the provincial CAC office within 4 hours; sector-specific rules apply on top. If the cause is not yet known, report the basics first and follow up.

  4. Report to the police: 110 or the local bureau

    Call 110 if the attack is still under way and you need the police quickly; for most corporate incidents, go to the local public security bureau with your materials. Bring what you have now and supply the rest as the case officer asks - do not wait for a complete file.

  5. Check the evidence list and keep the receipt

    Under the Ministry of Public Security's procedural rules for criminal cases, the police take a statement, register the evidence you provide on a signed receipt list, and hand the reporting party a case acceptance receipt. Check the list item by item and keep the receipt and the case officer's contact details.

  6. Keep cooperating and close out the report

    Save any further messages from the attacker exactly as received and pass them to the case officer rather than replying yourself. For incidents already reported to regulators, Article 8 of the measures requires a post-incident summary report through the same channel within 30 days of the response ending.

Avoid making it worse

Do not

  • Do not reinstall, format or roll back snapshots to "get the business running first" and report afterwards - overwritten evidence cannot be recovered.
  • Do not delete the ransom note, empty the antivirus quarantine, clear event logs or uninstall suspicious remote-access tools yourself.
  • Do not hand over screenshots alone: keep the ransom note file, emails in original format with full headers, and exported chat records.
  • Do not contact the attacker or make a small test payment to "gather evidence"; if contact already happened, keep the complete exchange and tell the case officer.
  • Do not give original disks to an unknown "decryption broker", and do not run recovery tools on the original disk.
  • Do not delay or conceal a report out of reputational concern: Article 10 of the CAC measures provides for heavier penalties where late, omitted, false or concealed reporting causes serious harm.

Call 110 or go to the police station? Which channel is which?

A police report (a criminal complaint) and an incident report (a regulatory filing) serve different purposes through different channels, and one does not replace the other.

ChannelWhen to use itNotes
110The attack is ongoing and police need to act quicklyFollow the dispatcher's instructions on supplying materials
Local public security bureau (police station or cyber security unit)Most corporate ransomware incidentsFile in person; the police take a statement, register your evidence and issue a case acceptance receipt
Cybercrime reporting portal (cyberpolice.mps.gov.cn)Tip-offs and supplementary reportsThe Ministry of Public Security's online reporting channel; it cannot take on-site or emergency reports - call 110 for those
12387 and other CAC reporting channelsIncidents rated relatively major or aboveA regulatory report, not a police report
Sector regulatorsFinance, healthcare, education, energy and other sectors with their own rulesThe sector regulator's requirements apply

In practice, start by calling or visiting the public security bureau where the organisation is based and let the case officer tell you what else is needed. If branches, cloud servers and data centres are spread across several cities, explain the layout as it is; jurisdiction is for the police to determine.

For foreign-invested companies, the same channels apply to systems in mainland China. If money has also been fraudulently transferred - for example through an executive-impersonation scam run with a remote access trojan such as Silver Fox - calling the police and the bank to stop the payment comes before any technical step; see what to do about Silver Fox.

What incident reporting duties does the organisation have?

Beyond the police report, an organisation acting as a network operator, data processor or personal information processor may owe reports to regulators. The table covers the provisions most directly relevant to ransomware. Whether they apply, to whom and in what form is for the competent authorities and your legal counsel to confirm; this page is not legal advice.

ProvisionWhat it requires in a ransomware incident
National Cybersecurity Incident Reporting Measures (issued by the CAC in September 2025, in force since 1 November 2025)Rate the incident against the annexed grading guide. For relatively major incidents and above: critical information infrastructure operators report to their protection department and the police within 1 hour at most; central government bodies and their affiliated units report to their department's cyberspace affairs office within 2 hours; other network operators report to the provincial CAC office within 4 hours. Suspected crimes must also be reported to the police promptly
Cybersecurity Law (amended 28 October 2025, in force 1 January 2026), Article 27When an incident endangering network security occurs, activate the response plan, take remedial measures and report to the competent authorities as required
Critical Information Infrastructure Security Protection Regulations, Article 18Operators report major incidents or major threats to the protection department and the police
Data Security Law, Article 29On a data security incident, take immediate measures, inform users and report to the competent authorities as required
Network Data Security Management Regulations, Article 11Report network data security incidents as required, and report suspected criminal leads found during the response to the police or state security authorities
Personal Information Protection Law (PIPL), Article 57Where personal information is or may have been leaked, altered or lost, take remedial measures immediately and notify the regulator and the individuals concerned

Points that are often misread:

  • What counts as relatively major? The grading guide has qualitative criteria and quantitative indicators. Those closest to ransomware include critical infrastructure fully down for 10 minutes or more or its main functions down for 30 minutes or more; personal information of 1 million or more people leaked; leaks of important data threatening national security and social stability; and direct economic loss of 5 million yuan or more. Falling below these thresholds does not remove the case for a police report, nor any sector-specific requirement.
  • The report must describe the ransom. Article 7 lists the required content, and for ransomware attacks it adds the amount, method and date of the ransom demanded.
  • Late reporting and mitigation. Article 10 provides for heavier penalties where late, omitted, false or concealed reporting causes serious harm; Article 11 allows lighter or no liability where reasonable protections were in place, the response followed the plan and reporting was timely.

For notifying individuals and handling external communication when personal data is involved, see a ransomware gang threatening to leak data.

What materials should we prepare?

Do not wait for a complete file before reporting. Organise what you have into an indexed pack, keep originals and copies apart, and add the rest as the case officer requests.

1. Organisation and representatives

  • Business licence or equivalent proof of the entity, plus a letter of introduction or power of attorney (the local bureau's requirements apply)
  • ID for the person filing, and contact details for the technical lead
  • Where the affected systems sit: own data centre, colocation or cloud, and the provider and account holder

2. Incident description and timeline

  • When the anomaly was first noticed, by whom and how (application errors, ransom note, security alert)
  • Known milestones: suspicious logons, new accounts, antivirus disabled, encryption start, ransom note appearing
  • Every action taken since discovery: who disconnected, rebooted or restored which machine and when - this decides which evidence is still reliable
  • The time zone used, and whether server clocks were accurate

3. Ransom-related originals

  • The ransom note files (txt, html, hta and so on) and photos or screenshots of desktops and logon screens
  • Two or three encrypted samples with their original file names and paths
  • Attacker contact details: email addresses, TOX ID, Session or Telegram handles, .onion negotiation address, victim ID
  • The demand: amount, currency, wallet address and deadline - also required content for the regulatory report
  • Any exchange with the attacker: emails in original format with full headers, exported chat records

4. Logs and technical evidence

  • Windows Security log: successful and failed logons (event IDs 4624 and 4625), user account created (4720), member added to a local security group (4732), service installation (4697), scheduled task created (4698), audit log cleared (1102)
  • Firewall, VPN, bastion host, remote desktop and web proxy logs, focusing on external logons and large outbound transfers in the days and weeks before encryption
  • Antivirus and EDR alerts and the quarantine (do not empty it)
  • Paths and copies of suspicious binaries, scripts and newly installed remote-access tools

5. Impact and loss

  • Affected asset inventory: hostnames, IPs, business systems, data types, whether personal information is involved
  • Duration and scope of business interruption
  • Loss estimate: direct loss, estimated recovery cost, potential third-party liability, with unknowns marked "to be assessed"

How do we preserve evidence so it holds up?

Preservation has one purpose: anyone looking later must be able to verify that this data is exactly what was taken from that device at that time, and that it has not changed since.

  • Image first, analyse second. Take disk and memory images of key hosts, do all analysis and recovery on copies, and write nothing further to the original media; capture memory first on hosts that are still running.
  • Hash and register everything. Compute SHA-256 or similar for every image, log export and sample, and record it. China's joint provisions from the Supreme People's Court, Supreme People's Procuratorate and Ministry of Public Security on electronic evidence in criminal cases (Article 5) list computing an integrity check value alongside sealing the original media, making and sealing backups and video-recording the extraction as methods of protecting integrity.
  • Delete nothing, clean nothing, overwrite nothing. No reinstall, format, log cleanup or quarantine purge, and never restore data back onto the original disk. Export logs from firewalls and VPN appliances with short retention first.
  • Keep a chain of custody. For each item, record who collected it, when, from which device and how, who received it and where it is stored, with signatures at every hand-over of media.
  • Prefer original formats. Screenshots support; they do not replace. Keep emails in original format, ransom notes as files, and chat records via the platform's own export.
  • Limit access. Store copies in access-controlled locations and never pass them around through personal cloud drives or messaging apps.

Our forensics service follows this process for disk, memory and log evidence. The report covers the timeline, entry point, compromised asset inventory, indicators of compromise and an evidence register (source, collection time, hash), and serves as technical material for a police report, regulatory explanations and insurance claims. Two caveats: unless separately agreed and legally qualified, a technical forensic report is not a judicial expert opinion; and whether a case is opened and how it is characterised is for the police to decide.

Will reporting delay recovery, and what happens afterwards?

They do not conflict if the order is right: preserve evidence, then recover on copies. Once images are taken and logs exported, recovery can proceed in parallel without waiting for a decision on the case. If the case officer asks for original media or wants the scene left intact, cooperate and adjust the recovery plan accordingly.

What commonly follows a report:

  • Requests for more material. The case officer may ask for further logs, samples or a written account, so keep the technical contact reachable.
  • Further contact from the attacker. Save new emails and messages exactly as received and pass them on; do not reply to probe.
  • Keys from law enforcement operations. Keys for some families have been seized in operations, LockBit being one example. Reporting helps link your case to such leads, but it is not a recovery path to count on - recoverability still depends on the conditions described in can encrypted files be recovered.
  • Paying the ransom. Reporting does not take that decision away from you, but we advise against paying and do not negotiate on anyone's behalf; see should we pay the ransom.

And close the loop: if the entry point stays open, backdoors remain and credentials are unchanged, no amount of careful reporting will stop a second encryption through the same door - see why ransomware keeps coming back.

Where do overseas entities report?

Foreign-invested companies in China and Chinese organisations with overseas operations often have to satisfy several jurisdictions at once. For systems in mainland China, report to the public security authorities and regulators as described above. Where an overseas entity or overseas data is affected, local requirements apply as well. The usual equivalents:

  • United States: report to the FBI through the Internet Crime Complaint Center (IC3, ic3.gov) or a field office, to the Secret Service, or to CISA (cisa.gov/forms/report). CISA notes that a victim only needs to report once for the other agencies to be notified.
  • United Kingdom: since 4 December 2025, Report Fraud (reportfraud.police.uk) has replaced Action Fraud as the cyber crime and fraud reporting service for England, Wales and Northern Ireland; cyber incidents can also be reported to the NCSC at report.ncsc.gov.uk.

These arrangements change often, so confirm with the local authorities and your legal counsel.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related questions

FAQ

Follow-up questions

  • Do we have to finish forensics before reporting?

    No. Report with what you can gather immediately - an account of the incident, the original ransom note, the attacker's contact details and a list of affected systems - and add the rest as the case officer asks. The same goes for the regulatory report: Article 7 of the CAC's incident reporting measures allows you to report the basics first when the cause cannot be determined in time, and supplement later. What cannot wait is evidence preservation: imaging, log export and hash registration must happen before any recovery or cleanup.

  • We are a small company - do we still report to the CAC?

    The CAC measures draw the line by incident severity, not company size: only incidents rated relatively major or above under the grading guide follow the measures' procedure and deadlines. A single-site ransomware incident at a small business often will not reach that level, but other duties may still apply - sector rules require reporting to the sector regulator, and a personal information leak triggers an assessment under PIPL Article 57. A police report does not depend on severity, and we recommend filing one either way. Whether a regulatory report is due is for the authorities and your legal counsel to confirm.

  • We already contacted the attacker, or even paid - can we still report?

    Yes - and it is all the more important to keep the complete exchange and disclose it fully to the case officer: original emails, exported chats, wallet addresses, and the time and record of any payment are valuable leads for tracing funds and actors. Discuss any compliance exposure from a payment already made with your legal counsel. Do not relax after paying either: decryptors can be incomplete and stolen data is not reliably deleted, so recovery and exfiltration assessment still need to run their course. We do not pay ransoms or negotiate on anyone's behalf; see should we pay the ransom.

  • Our servers are in the cloud - do we go to the provider or the police?

    Both, for different reasons. The cloud provider can help preserve cloud-side evidence - console audit logs, security group and access policy changes, sign-in records, snapshots and flow logs - much of which has limited retention, so export it or request preservation quickly. The police report still goes to the public security authorities, with the provider's logs and the provider and account holder details included in your materials. When recovering, work from snapshot copies rather than rolling back the original instance, so the post-encryption state is not overwritten.

  • Will reporting make the incident public?

    A police report is a report to the authorities, not a public announcement. Whether the organisation must disclose externally, to whom and in what words depends on other duties: notifying individuals after a personal information leak, listed-company disclosure rules and contractual commitments to customers and partners - questions for your legal and compliance teams. A bigger exposure risk than reporting is the attacker posting your data on a leak site; see a ransomware gang threatening to leak data.

Sources

External links are provided for reference only. The content is published by third parties and does not represent our position.

Updated