Home / Blog / Ransomware Without the Ransom
Business · blog post

Ransomware data recovery: what survives an encryption run, what destroys it afterwards, and why the ransom is not the route back

By the time a ransom note is on screen the attacker has finished. What has not finished is your own automation, and the difference between a bad week and a ruinous one is usually decided by what your systems do to themselves over the next few hours.

Two clocks, and only one of them has stopped

The attacker's clock stopped when the encryption run completed. Your own is still going, and it is attached to everything that copies data on a schedule: the nightly backup job, the hourly snapshot, the replication link to the second site, the folder sync running quietly on every desktop. None of those can tell a legitimate change from a malicious one. They see files that have been modified and they do exactly what they were configured to do, which is push the modified version over the last good one and retire the copy underneath.

So the first action is not isolation, tempting though that is. Stop every scheduled backup, snapshot, replication task and sync client you own, including the ones you had forgotten about. This is the single most expensive mistake that reaches this bench and it is almost never anybody's fault — the job ran as designed, on time, and traded the last clean copies for encrypted ones. Freeze the lot, and work out afterwards what survived.

Then contain it. Pull network cables and disable the wireless on affected machines, but leave the power on where you reasonably can, because volatile memory sometimes still holds process and key material that disappears the instant it is cut. Photograph the note. Keep one encrypted file and, if you can find one anywhere, an untouched copy of the same file from before the attack — that pair is often what identifies the strain. And write down when it was noticed, because the interval between the run starting and somebody spotting it turns out to matter to almost every question asked later.

The two-minute check that occasionally ends the whole thing

Before any plan gets built, spend two minutes on the No More Ransom project. Law enforcement agencies and security researchers have broken a considerable number of strains over the years, either by finding flaws in the implementation or by seizing key material during a takedown, and the resulting decryptors are published free. Upload the ransom note and one locked file and the identification service will tell you whether yours is among them. Now and again it closes an incident inside an afternoon for nothing.

What nobody can offer is a way through the encryption itself when it has been done competently. Modern strains use standard, well-tested algorithms with per-file keys wrapped in a public key held only by the attacker, and no laboratory on earth breaks that. Any firm implying otherwise is describing a sales process rather than mathematics. Everything useful that follows comes from somewhere else entirely.

Three places the files outlive the encryption

The first is whatever the run never finished. Encrypting an estate is slow, noisy and easily interrupted — somebody notices, a laptop sleeps, a share disconnects, a service crashes partway through. Partial encryption is extremely common: large files with a scrambled header and a body that reads perfectly, whole directories skipped over, a server that was powered down that evening and never touched. Which is why the first genuinely useful document produced on one of these jobs is an inventory that separates the files which really have been encrypted from the far larger number that merely look as though they were.

The second is the deleted originals, and this is where most of the good news comes from. A great many strains do not overwrite a file in place. They read it, write an encrypted copy alongside it under a new name, and delete the source. Deletion clears the pointer and leaves the content sitting in unallocated space until something needs the room. Read the disks properly at sector level and a substantial share of the pre-attack files often comes back intact. None of that involves cryptography — it is ordinary recovery work applied to an unusual cause, which is precisely why it is priced like ordinary recovery work.

The third is anything the attack could not reach. A disk rotated into a safe, an archive tape, the external drive somebody unplugged in March and never reconnected — whatever was disconnected during the run is normally clean, and that is the entire argument for keeping one copy that does not live permanently attached to the network. Cloud services frequently hold versioned copies as well, though only for a fixed retention window, so establish that window before building a plan on it. Windows shadow copies are worth checking for the same reason, with the caveat that many strains delete them on the way through — and even then, a deleted shadow copy leaves its blocks on the disk in the same way a deleted file does.

Paying, and what this bench will and will not do

Some laboratories will settle the ransom for you, put the decrypted files on a disk and invoice the whole thing as data recovery. That does happen in this trade and it is not on offer here. The reasons are practical well before they are ethical. Decryptors handed over after payment are frequently defective, frequently incomplete, and sometimes never turn up. Payment marks an organisation as one that pays, and repeat attacks on the same victim are a well-documented pattern. Several of the groups involved sit under sanctions regimes, which turns a commercial decision into a legal one for you rather than for them. And every payment underwrites the next set of attacks.

It is worth being equally plain about what this bench is. It is not an incident response retainer and it is not a negotiator. It reads storage. What it adds for commercial work is documentation: custody of every disk recorded from the moment it arrives, so an insurer, a regulator or a solicitor can be given a clean account of where the media has been, and a non-disclosure agreement whenever you want one. Should you also need to establish how the attacker got in or what was taken out, that is a forensic investigation with a full written report at £800 + VAT — a service you ask for on purpose. It is never bolted onto a recovery quietly, and most firms getting back on their feet after an attack have no use for it.

What it costs and what goes in the box

The price follows the hardware, exactly as it does for every other job on this site. A single encrypted drive is £300 + VAT. A server, NAS or array is from £500 + VAT, rising with the number of member disks and the state they arrive in. Ransomware is not classed as forensic work here and is not priced as though it were, whatever you may have been quoted elsewhere — the fact that the cause was criminal does not change what the bench physically has to do to the disks.

Send storage, not furniture. The disks themselves, each labelled with the bay it came out of, packed so nothing can shift in transit, tracked and insured to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford, GU2 8XH. From the estates off the A329(M) or anywhere along the M4 that is close enough to be a lunchtime run if somebody wants to drive it — about forty minutes and eighteen miles from Bracknell via the A322 and the A3 — and reception takes hand deliveries Mon–Fri 9:00am–5:30pm. There is no collection service anywhere on this network, so nothing in the job waits on a driver being free.

Ring 0800 689 0668 before the parcel leaves and describe what the attack has stopped the business doing, and the job is flagged ahead of its arrival. The assessment is free and closes 2 working days after booking in. It comes back with four things: an inventory of what has actually been encrypted, an estimate of how much is retrievable from the deleted originals, a yes or no on whether a published decryptor exists for your strain, and a single fixed price.

In the hour after an attack, nothing you own is more dangerous than your own schedule. Backups, snapshots, replication and sync clients cannot tell malicious changes from legitimate ones, and left running they will faithfully replace the last clean copies with encrypted ones. Freeze every one of them before you touch anything else.

// questions we get asked on this one

Common questions

Sometimes literally, when yours turns out to be a strain that researchers or law enforcement have already broken and a decryptor for it sits on No More Ransom. Much more often the route back bypasses the encryption entirely: original files the run deleted rather than overwrote, media that was unplugged at the time, and machines or shares the attacker never reached. What nobody can sell you is a way through encryption that was applied competently.
No, and it is a common position to be in because repositories are an obvious target. The disks under that repository still hold the deleted originals of whatever was overwritten, in the same way any other volume does. Power it down now, leave any repair, resync or re-initialise strictly alone, and send the disks with their bay numbers marked on them.
Less than it feels like at the time. Removing a snapshot, like removing a volume, only releases the space it occupied; the blocks themselves stay put until something else claims them, and a sector-level read of those disks recovers a worthwhile proportion surprisingly often. What actually destroys them is whatever gets done next — a resync, a rebuild, or a new volume created across the same members.
Not until every affected disk has been imaged in full. A rebuild claims exactly the free space holding the pre-attack files, which is normally the most productive source on the job, and it wipes out the evidence of how the intrusion happened, so the same route stays open for the next one. Image, investigate, then rebuild — that sequence, every time.
The hardware sets the figure, exactly as it does on every other job here. A single encrypted drive is £300 + VAT. A server, NAS or array starts at £500 + VAT and moves with the disk count and their condition. This is not classed as forensic work and is not charged as though it were. The assessment costs nothing, closes 2 working days after the media is booked in, and fixes the price in writing before any chargeable work starts.
Yes, and it normally needs to be. A non-disclosure agreement is available wherever you want one, custody of the media is documented at every stage, and anything written up is drafted so it can go to an insurer or a regulator without disclosing more than the point at issue. Media is returned or destroyed securely on your written instruction, and the job is not discussed outside it.

Seen enough — shall we take a look at it?

Free diagnostic closing 2 working days after your device is booked in, one fixed written quote, and no fix, no fee on logical faults. Cards and USB sticks £250 + VAT, any single drive or SSD £300 + VAT.