Victim Q&A · Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
Short answer
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
Key points
- Filing a police report and reporting an incident to regulators such as the CAC are separate duties, and many organisations need to do both.
- Police channels: call 110 or file in person locally; the cybercrime portal (cyberpolice.mps.gov.cn) is for tip-offs and does not handle emergencies.
- For incidents rated relatively major or above, critical information infrastructure operators report within 1 hour; other network operators report to the provincial CAC office within 4 hours.
- Reporting and recovery can run in parallel, provided evidence is preserved first and recovery works on copies.
- When filing in person, check the evidence receipt list and keep the case acceptance receipt.
- Whether a case is opened is decided by the police; a forensic report is supporting material, not an investigative conclusion.
In this order
What to do now
Secure the scene before you file
Isolate affected hosts without powering them off, keep the ransom note, encrypted samples and the antivirus quarantine, and pause every reinstall, format, log cleanup and snapshot rollback. You do not need to finish recovery before reporting, but evidence that gets overwritten cannot be recovered. The full first-hours sequence is in what to do after a ransomware attack.
Name a point of contact and start a timeline
Appoint one person who knows the facts and one technical contact. Start the timeline now: when the anomaly was first noticed and by whom, known suspicious logons and encryption times, and every action taken since discovery - who did what to which machine, and when. The police statement, the regulatory report and the forensic work all draw on it.
Decide whether a regulatory report is due
Rate the incident against the grading guide annexed to the CAC's incident reporting measures. If it is relatively major or above, critical information infrastructure operators report to their protection department and the police within 1 hour, and other network operators report to the provincial CAC office within 4 hours; sector-specific rules apply on top. If the cause is not yet known, report the basics first and follow up.
Report to the police: 110 or the local bureau
Call 110 if the attack is still under way and you need the police quickly; for most corporate incidents, go to the local public security bureau with your materials. Bring what you have now and supply the rest as the case officer asks - do not wait for a complete file.
Check the evidence list and keep the receipt
Under the Ministry of Public Security's procedural rules for criminal cases, the police take a statement, register the evidence you provide on a signed receipt list, and hand the reporting party a case acceptance receipt. Check the list item by item and keep the receipt and the case officer's contact details.
Keep cooperating and close out the report
Save any further messages from the attacker exactly as received and pass them to the case officer rather than replying yourself. For incidents already reported to regulators, Article 8 of the measures requires a post-incident summary report through the same channel within 30 days of the response ending.
Avoid making it worse
Do not
- Do not reinstall, format or roll back snapshots to "get the business running first" and report afterwards - overwritten evidence cannot be recovered.
- Do not delete the ransom note, empty the antivirus quarantine, clear event logs or uninstall suspicious remote-access tools yourself.
- Do not hand over screenshots alone: keep the ransom note file, emails in original format with full headers, and exported chat records.
- Do not contact the attacker or make a small test payment to "gather evidence"; if contact already happened, keep the complete exchange and tell the case officer.
- Do not give original disks to an unknown "decryption broker", and do not run recovery tools on the original disk.
- Do not delay or conceal a report out of reputational concern: Article 10 of the CAC measures provides for heavier penalties where late, omitted, false or concealed reporting causes serious harm.
Call 110 or go to the police station? Which channel is which?
A police report (a criminal complaint) and an incident report (a regulatory filing) serve different purposes through different channels, and one does not replace the other.
| Channel | When to use it | Notes |
|---|---|---|
| 110 | The attack is ongoing and police need to act quickly | Follow the dispatcher's instructions on supplying materials |
| Local public security bureau (police station or cyber security unit) | Most corporate ransomware incidents | File in person; the police take a statement, register your evidence and issue a case acceptance receipt |
| Cybercrime reporting portal (cyberpolice.mps.gov.cn) | Tip-offs and supplementary reports | The Ministry of Public Security's online reporting channel; it cannot take on-site or emergency reports - call 110 for those |
| 12387 and other CAC reporting channels | Incidents rated relatively major or above | A regulatory report, not a police report |
| Sector regulators | Finance, healthcare, education, energy and other sectors with their own rules | The sector regulator's requirements apply |
In practice, start by calling or visiting the public security bureau where the organisation is based and let the case officer tell you what else is needed. If branches, cloud servers and data centres are spread across several cities, explain the layout as it is; jurisdiction is for the police to determine.
For foreign-invested companies, the same channels apply to systems in mainland China. If money has also been fraudulently transferred - for example through an executive-impersonation scam run with a remote access trojan such as Silver Fox - calling the police and the bank to stop the payment comes before any technical step; see what to do about Silver Fox.
What incident reporting duties does the organisation have?
Beyond the police report, an organisation acting as a network operator, data processor or personal information processor may owe reports to regulators. The table covers the provisions most directly relevant to ransomware. Whether they apply, to whom and in what form is for the competent authorities and your legal counsel to confirm; this page is not legal advice.
| Provision | What it requires in a ransomware incident |
|---|---|
| National Cybersecurity Incident Reporting Measures (issued by the CAC in September 2025, in force since 1 November 2025) | Rate the incident against the annexed grading guide. For relatively major incidents and above: critical information infrastructure operators report to their protection department and the police within 1 hour at most; central government bodies and their affiliated units report to their department's cyberspace affairs office within 2 hours; other network operators report to the provincial CAC office within 4 hours. Suspected crimes must also be reported to the police promptly |
| Cybersecurity Law (amended 28 October 2025, in force 1 January 2026), Article 27 | When an incident endangering network security occurs, activate the response plan, take remedial measures and report to the competent authorities as required |
| Critical Information Infrastructure Security Protection Regulations, Article 18 | Operators report major incidents or major threats to the protection department and the police |
| Data Security Law, Article 29 | On a data security incident, take immediate measures, inform users and report to the competent authorities as required |
| Network Data Security Management Regulations, Article 11 | Report network data security incidents as required, and report suspected criminal leads found during the response to the police or state security authorities |
| Personal Information Protection Law (PIPL), Article 57 | Where personal information is or may have been leaked, altered or lost, take remedial measures immediately and notify the regulator and the individuals concerned |
Points that are often misread:
- What counts as relatively major? The grading guide has qualitative criteria and quantitative indicators. Those closest to ransomware include critical infrastructure fully down for 10 minutes or more or its main functions down for 30 minutes or more; personal information of 1 million or more people leaked; leaks of important data threatening national security and social stability; and direct economic loss of 5 million yuan or more. Falling below these thresholds does not remove the case for a police report, nor any sector-specific requirement.
- The report must describe the ransom. Article 7 lists the required content, and for ransomware attacks it adds the amount, method and date of the ransom demanded.
- Late reporting and mitigation. Article 10 provides for heavier penalties where late, omitted, false or concealed reporting causes serious harm; Article 11 allows lighter or no liability where reasonable protections were in place, the response followed the plan and reporting was timely.
For notifying individuals and handling external communication when personal data is involved, see a ransomware gang threatening to leak data.
What materials should we prepare?
Do not wait for a complete file before reporting. Organise what you have into an indexed pack, keep originals and copies apart, and add the rest as the case officer requests.
1. Organisation and representatives
- Business licence or equivalent proof of the entity, plus a letter of introduction or power of attorney (the local bureau's requirements apply)
- ID for the person filing, and contact details for the technical lead
- Where the affected systems sit: own data centre, colocation or cloud, and the provider and account holder
2. Incident description and timeline
- When the anomaly was first noticed, by whom and how (application errors, ransom note, security alert)
- Known milestones: suspicious logons, new accounts, antivirus disabled, encryption start, ransom note appearing
- Every action taken since discovery: who disconnected, rebooted or restored which machine and when - this decides which evidence is still reliable
- The time zone used, and whether server clocks were accurate
3. Ransom-related originals
- The ransom note files (txt, html, hta and so on) and photos or screenshots of desktops and logon screens
- Two or three encrypted samples with their original file names and paths
- Attacker contact details: email addresses, TOX ID, Session or Telegram handles, .onion negotiation address, victim ID
- The demand: amount, currency, wallet address and deadline - also required content for the regulatory report
- Any exchange with the attacker: emails in original format with full headers, exported chat records
4. Logs and technical evidence
- Windows Security log: successful and failed logons (event IDs 4624 and 4625), user account created (4720), member added to a local security group (4732), service installation (4697), scheduled task created (4698), audit log cleared (1102)
- Firewall, VPN, bastion host, remote desktop and web proxy logs, focusing on external logons and large outbound transfers in the days and weeks before encryption
- Antivirus and EDR alerts and the quarantine (do not empty it)
- Paths and copies of suspicious binaries, scripts and newly installed remote-access tools
5. Impact and loss
- Affected asset inventory: hostnames, IPs, business systems, data types, whether personal information is involved
- Duration and scope of business interruption
- Loss estimate: direct loss, estimated recovery cost, potential third-party liability, with unknowns marked "to be assessed"
How do we preserve evidence so it holds up?
Preservation has one purpose: anyone looking later must be able to verify that this data is exactly what was taken from that device at that time, and that it has not changed since.
- Image first, analyse second. Take disk and memory images of key hosts, do all analysis and recovery on copies, and write nothing further to the original media; capture memory first on hosts that are still running.
- Hash and register everything. Compute SHA-256 or similar for every image, log export and sample, and record it. China's joint provisions from the Supreme People's Court, Supreme People's Procuratorate and Ministry of Public Security on electronic evidence in criminal cases (Article 5) list computing an integrity check value alongside sealing the original media, making and sealing backups and video-recording the extraction as methods of protecting integrity.
- Delete nothing, clean nothing, overwrite nothing. No reinstall, format, log cleanup or quarantine purge, and never restore data back onto the original disk. Export logs from firewalls and VPN appliances with short retention first.
- Keep a chain of custody. For each item, record who collected it, when, from which device and how, who received it and where it is stored, with signatures at every hand-over of media.
- Prefer original formats. Screenshots support; they do not replace. Keep emails in original format, ransom notes as files, and chat records via the platform's own export.
- Limit access. Store copies in access-controlled locations and never pass them around through personal cloud drives or messaging apps.
Our forensics service follows this process for disk, memory and log evidence. The report covers the timeline, entry point, compromised asset inventory, indicators of compromise and an evidence register (source, collection time, hash), and serves as technical material for a police report, regulatory explanations and insurance claims. Two caveats: unless separately agreed and legally qualified, a technical forensic report is not a judicial expert opinion; and whether a case is opened and how it is characterised is for the police to decide.
Will reporting delay recovery, and what happens afterwards?
They do not conflict if the order is right: preserve evidence, then recover on copies. Once images are taken and logs exported, recovery can proceed in parallel without waiting for a decision on the case. If the case officer asks for original media or wants the scene left intact, cooperate and adjust the recovery plan accordingly.
What commonly follows a report:
- Requests for more material. The case officer may ask for further logs, samples or a written account, so keep the technical contact reachable.
- Further contact from the attacker. Save new emails and messages exactly as received and pass them on; do not reply to probe.
- Keys from law enforcement operations. Keys for some families have been seized in operations, LockBit being one example. Reporting helps link your case to such leads, but it is not a recovery path to count on - recoverability still depends on the conditions described in can encrypted files be recovered.
- Paying the ransom. Reporting does not take that decision away from you, but we advise against paying and do not negotiate on anyone's behalf; see should we pay the ransom.
And close the loop: if the entry point stays open, backdoors remain and credentials are unchanged, no amount of careful reporting will stop a second encryption through the same door - see why ransomware keeps coming back.
Where do overseas entities report?
Foreign-invested companies in China and Chinese organisations with overseas operations often have to satisfy several jurisdictions at once. For systems in mainland China, report to the public security authorities and regulators as described above. Where an overseas entity or overseas data is affected, local requirements apply as well. The usual equivalents:
- United States: report to the FBI through the Internet Crime Complaint Center (IC3, ic3.gov) or a field office, to the Secret Service, or to CISA (cisa.gov/forms/report). CISA notes that a victim only needs to report once for the other agencies to be notified.
- United Kingdom: since 4 December 2025, Report Fraud (reportfraud.police.uk) has replaced Action Fraud as the cyber crime and fraud reporting service for England, Wales and Northern Ireland; cyber incidents can also be reported to the NCSC at report.ncsc.gov.uk.
These arrangements change often, so confirm with the local authorities and your legal counsel.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Aftermath
A ransomware gang is threatening to publish our data - what should we do?
Do not respond or pay yet. First establish with evidence whether data actually left and what it was: check outbound traffic, archive staging, transfer tools such as Rclone, MEGA or WinSCP, and cloud sign-in and export logs, and compare any samples the attackers released against your own data - some threats are bluffs or recycled old leaks. Paying does not buy deletion: the UK's National Crime Agency found data belonging to victims who had paid still on LockBit's systems. Close the exfiltration path, rotate credentials, and assess notification duties under the PIPL and related rules.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
FAQ
Follow-up questions
Do we have to finish forensics before reporting?
No. Report with what you can gather immediately - an account of the incident, the original ransom note, the attacker's contact details and a list of affected systems - and add the rest as the case officer asks. The same goes for the regulatory report: Article 7 of the CAC's incident reporting measures allows you to report the basics first when the cause cannot be determined in time, and supplement later. What cannot wait is evidence preservation: imaging, log export and hash registration must happen before any recovery or cleanup.
We are a small company - do we still report to the CAC?
The CAC measures draw the line by incident severity, not company size: only incidents rated relatively major or above under the grading guide follow the measures' procedure and deadlines. A single-site ransomware incident at a small business often will not reach that level, but other duties may still apply - sector rules require reporting to the sector regulator, and a personal information leak triggers an assessment under PIPL Article 57. A police report does not depend on severity, and we recommend filing one either way. Whether a regulatory report is due is for the authorities and your legal counsel to confirm.
We already contacted the attacker, or even paid - can we still report?
Yes - and it is all the more important to keep the complete exchange and disclose it fully to the case officer: original emails, exported chats, wallet addresses, and the time and record of any payment are valuable leads for tracing funds and actors. Discuss any compliance exposure from a payment already made with your legal counsel. Do not relax after paying either: decryptors can be incomplete and stolen data is not reliably deleted, so recovery and exfiltration assessment still need to run their course. We do not pay ransoms or negotiate on anyone's behalf; see should we pay the ransom.
Our servers are in the cloud - do we go to the provider or the police?
Both, for different reasons. The cloud provider can help preserve cloud-side evidence - console audit logs, security group and access policy changes, sign-in records, snapshots and flow logs - much of which has limited retention, so export it or request preservation quickly. The police report still goes to the public security authorities, with the provider's logs and the provider and account holder details included in your materials. When recovering, work from snapshot copies rather than rolling back the original instance, so the post-encryption state is not overwritten.
Will reporting make the incident public?
A police report is a report to the authorities, not a public announcement. Whether the organisation must disclose externally, to whom and in what words depends on other duties: notifying individuals after a personal information leak, listed-company disclosure rules and contractual commitments to customers and partners - questions for your legal and compliance teams. A bigger exposure risk than reporting is the attacker posting your data on a leak site; see a ransomware gang threatening to leak data.
Sources
- 国家网络安全事件报告管理办法(2025-09 公布,2025-11-01 施行;第四条报告时限、第七条报告内容含赎金信息、第八条总结报告、第十条与第十一条责任条款、附件分级指南)— 国家互联网信息办公室
- 中华人民共和国网络安全法(2025 修正,2025-10-28 通过,2026-01-01 施行;第二十七条)— 商务部全球法规网
- 关键信息基础设施安全保护条例(国务院令第 745 号;第十八条)— 生态环境部转载
- 中华人民共和国数据安全法(第二十九条)— 国家统计局
- 网络数据安全管理条例(2025-01-01 施行;第十一条)— 国家互联网信息办公室
- 中华人民共和国个人信息保护法(第五十七条)— 国家互联网信息办公室
- 公安机关办理刑事案件程序规定(2020 修正;第一百六十九条至第一百七十一条:笔录、接受证据材料清单、受案回执)— 中国政府网
- 最高人民法院 最高人民检察院 公安部关于办理刑事案件收集提取和审查判断电子数据若干问题的规定(第五条:完整性校验值等保护方法)— 重庆市公安局转载
- 怎样举报网络违法犯罪?(网络违法犯罪信息举报网站 cyberpolice.mps.gov.cn,不具备现场、紧急报警受理功能,紧急情况拨打 110)— 福建省人民政府门户网站
- Appendix L: Events to Monitor(Windows 安全事件 ID 4624 / 4625 / 4697 / 4698 / 4720 / 4732 / 1102)— Microsoft Learn
- Report Ransomware(IC3、FBI 外勤办公室、美国特勤局、CISA;只需报告一次)— CISA
- Report Fraud service goes live with full public launch in January 2026(2025-12-04 起取代 Action Fraud)— City of London Police
- Report a Cyber Incident — UK National Cyber Security Centre (NCSC)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated