Emergency line
Active cyber incident. Choose the emergency option when prompted.
Call (866) 442-3018Suggested
Ransomware, account takeover, or a breach in progress. Minutes matter. EMPIST incident response starts with containment, then recovery. Available 24/7/365.
If systems are encrypting, admins are locked out, or wire fraud is in motion, call. Do not wait for a callback window that never comes.
Active cyber incident. Choose the emergency option when prompted.
Call (866) 442-3018Direct line to EMPIST. Tell them you are under attack.
Call (312) 360-1900If you cannot talk yet, use the form below. We route it to incident response.
Request urgent help ›Simple moves that protect recovery. Avoid panic wipes that erase the trail you need.
Use (866) 442-3018 and choose the emergency option, or (312) 360-1900. Do not wait for email replies when systems are encrypting or accounts are hijacked.
Do not wipe machines or reset everything before someone is guiding containment. Evidence and live sessions often matter for stopping the attacker.
If guided to do so: disconnect affected systems from the network, pause suspicious admin changes, and stop paying or negotiating until response is engaged.
Right of the boom, in order. Speed protects the business. Investigation deepens after the bleeding stops.
Confirm what is happening, isolate paths the attacker is using, and stop the spread across identity, endpoints, email, and cloud.
Remove footholds, restore access and systems with intent, and get the business back online against clear priorities.
After the boom: close the path that worked and leave you stronger than before the incident started.
Want the full practice, including readiness before the next boom? See Incident Response.
Non-clients, ransom, and what happens next.
Call if you can. If you cannot, send details below and we will route this to incident response immediately.