Home / Blog / Business

Ransomware data recovery: the three places files survive, and why the ransom is not one of them

The first hour: stand still on purpose

Everybody's first instinct on reading a ransom note is to start fixing things, and it is nearly always the wrong one. Get the affected machines off the network by pulling the cable and switching the wi-fi off, but leave the power on where you sensibly can, because memory sometimes still holds process detail that vanishes with it. Take a photograph of the note. Set aside one encrypted file, and an untouched original of the same file if there is one anywhere. That pairing is often what pins down the strain and decides whether a published decryptor covers it.

Then stop every scheduled backup, ahead of anything else on the list. This is the dearest mistake that comes through here and it is rarely anybody's fault: the overnight job ran precisely as it was built to, and dutifully swapped the last clean copies for encrypted ones. Snapshots, replication and cloud sync all do the same thing, because none of them can tell a legitimate change from a malicious one. Halt the lot of them first, and only then work out what has survived.

The three places files outlive the encryption

First place: whatever the attack could not reach. Offline media is the obvious candidate — a rotated disk in a safe, an archive tape, the drive somebody pulled out in March and never got round to plugging back in. Whatever was disconnected when the run started is normally clean, and that is the entire case for keeping one copy that never lives permanently attached to anything. Cloud services often hold versioned copies as well, though only for a set window, so check the retention period before you rely on it. Windows shadow copies are worth a look for the same reason, though a good many strains delete them on the way through.

Second place: the deleted originals. A good many strains write an encrypted copy alongside each file and then delete the original, rather than overwriting the file where it sits. A deletion only clears the reference and leaves the content in place until the space is wanted for something else, so reading the raw disks properly often hands back a large share of the pre-attack files untouched. None of that is cryptography. It is ordinary recovery work, and it is where most of the good news on these jobs comes from.

Third place: what the attacker missed. Encrypting a whole estate takes time and makes noise, so runs are commonly interrupted. Somebody notices, a machine goes to sleep, the process falls over on a large share. Partial encryption is very common: headers scrambled while the bulk of a large file stays readable, whole directories skipped, one server left alone because it happened to be off that night. The first genuinely useful thing anybody can hand you is an itemised list separating what is truly encrypted from what only looks it.

About paying: the answer, given once

This lab will not help you pay, and it will not pay quietly on your behalf and hand the result back dressed up as a recovery. That practice exists in the trade and it should not. The objections are practical before they are moral. A good share of the firms that pay get a decryptor that is broken, that works on only part of the estate, or that never turns up at all. Paying also puts you on a list of firms that pay, and being hit a second time is a documented pattern. The group holding your files may carry sanctions exposure. And the money funds whoever gets hit next, which could easily be a firm you trade with.

One exception to all that gloom is worth ten minutes of anybody's day. A number of strains have been broken over the years, and law enforcement and security researchers publish the resulting free decryptors through the No More Ransom project. Upload your note and one locked file there before you commit to any other plan. The check is free, and now and again it closes the whole incident inside an afternoon. Nobody can promise you decryption, here or anywhere else, and a firm that does is describing a sales process rather than mathematics.

Getting the storage to an engineer

Practicalities, and the money first because people ask last. Ransomware is priced from the hardware exactly like any other recovery, not as a forensic investigation: £300 + VAT for a single encrypted drive, and from £500 + VAT for a server, NAS or array, rising with the number of disks. What is different is the terms. The figure is settled before the work rather than under no fix, no fee, and the job carries a documented chain of custody in case an insurer, a regulator or a solicitor asks to see one later. A full forensic investigation ending in a written report is a separate service at £800 + VAT, and most firms recovering from an attack do not need one. What you send is the storage itself — the disks, labelled with the bay each one came out of — rather than the rack, and it goes tracked and insured to Peter House, Oxford Street, Manchester, about 35 miles along the M62. No collection service exists anywhere on this network, so no part of the job waits on a driver.

The assessment is free and complete within 2 working days of arrival. It sets out what is genuinely encrypted rather than what merely looks it, what can be pulled back from deleted originals, whether a published decryptor covers your strain, and one fixed figure for the whole job. The firms that ring about this locally are the recognisable ones: freight forwarders, hauliers and agents working the port, the process plants around Runcorn and Widnes, component suppliers to Halewood and Speke, and the solicitors and accountants in the commercial district for whom a fortnight of missing records is a regulatory problem as much as a commercial one. The freephone is 0800 689 0668, Monday to Friday, 9:00am to 5:30pm.

The encryption is rarely the expensive part of an attack. The backup that ran on schedule a few hours afterwards usually is. Stop every scheduled backup, snapshot and sync the moment an infection is confirmed, before your own systems swap the last clean copies for locked ones.

// questions on this topic

Common questions

Occasionally in the direct sense, where the strain is one of the broken ones and a free decryptor has been released for it. Far more often the way back has nothing to do with the encryption at all: the deleted originals the attack left on the disks, media that happened to be offline that night, or the parts of the estate the run never got to. Nobody can offer you a way through current encryption itself.
Not necessarily. A deleted snapshot and a deleted volume both leave their contents sitting on the disks until the space is needed, and reading those disks raw returns a useful share far more often than people expect. Shut the unit down straight away, leave any rebuild or re-initialise well alone, and post the disks with the bay numbers written on them.
Only once every affected disk has been imaged in full, and only once somebody knows how they got in. A rebuild on top wipes out the deleted originals that are usually the best route back, and it wipes out the traces of the entry point too, so the same door stays open for next time. Image first, investigate second, rebuild third.
Yes, and it usually needs to be. Work runs under a non-disclosure agreement where you want one, custody of the media is documented at every step, and the report is written so it can be handed to an insurer or a regulator without spilling anything beyond the point at issue. Your media comes back to you or is destroyed securely, whichever you put in writing, and the job is never discussed outside it.

Read enough — want it recovered?

Free diagnostic within 2 working days of arrival, one fixed written quote, no fix no fee on logical faults. Cards £250 + VAT, any one drive or SSD £300 + VAT.