Home / Blog / Business

Ransomware data recovery: the three ways files come back — none of them a ransom

The first hour: stand still, deliberately

Disconnect the affected machines from the network — cable out, Wi-Fi off — and then resist the urge to be busy. The two most expensive actions in any attack's first hour are both tidying: wiping machines to reinstall, and deleting the encrypted files in disgust. Leave servers and NAS boxes exactly as they stand until there's a plan. Photograph the ransom note, write down the odd new extension on the files, and above everything, pause every scheduled backup job immediately — the next automatic run will happily copy encrypted files over the clean versions you'll be depending on later.

One piece of admin also belongs in hour one. If personal data is caught up in it, UK GDPR may make the attack a reportable breach with a clock attached — so whoever carries compliance in the business hears today, not once the dust settles.

Where data survives an attack

Copies the malware never reached. Offline and off-site backups, obviously — but also version history in the big cloud platforms, which people forget they have: SharePoint, OneDrive, Dropbox and Google Drive can all walk files back to the day before. NAS snapshots. Windows shadow copies. Modern strains hunt snapshots and shadow copies specifically, but their housekeeping is imperfect, and partial survivors show up in case after case.

A decryptor somebody has already published. When researchers crack a ransomware family, free decryption tools appear — the No More Ransom project is the respectable clearing house. Identify your family first (the note's wording and the renamed files' suffix do it), then check whether yours is on the cracked list. What you never do is send money to an anonymous 'guaranteed decryption' outfit: the honest ones are quietly paying the criminals and adding a margin, and the rest are a second robbery with better web design.

Everything the encryption never got to. Encrypting a business's storage takes hours, and plenty of attacks die partway — interrupted by a reboot, an alert member of staff, or their own shoddy code. Worked methodically, the disks give up secondary volumes the sweep never visited, older file versions sitting in unallocated space, database exports the malware treated as noise, VM images it couldn't parse, and files damaged only in their opening blocks. None of this is magic; it's imaging every disk and auditing the images line by line, which is bench work of the patient sort.

The ransom question, answered once and kept answered

We don't pay ransoms, we don't negotiate with the people behind them, and we won't do either quietly on a client's behalf. The reasons are practical before they're moral: a meaningful share of payers get broken decryptors or nothing; paying marks the firm as a payer for the next crew; UK official guidance is against it; and if a sanctioned group wrote the strain, the payment itself can break the law. Every pound and hour goes further on the three routes above — which, in most incidents that reach this bench, return more than anyone believed possible in the first bad week.

Report the crime to Action Fraud, and keep the encrypted disks — all of them. Ransomware families get cracked months and sometimes years after their moment, and a drive on a shelf costs nothing while a drive in a skip is a door closed forever.

Sending a ransomware job in

Post the affected storage in tracked and insured — label the drives of any multi-bay system by slot before they move — and every disk is imaged before analysis breathes on it, so no original is ever worked. Back comes a written statement of what's recoverable by all three routes, with one fixed quote. Ransomware sits in the forensic class on our tariff, which means the agreed figure is payable before bench work starts rather than after. If the attack is still moving through the network, ring 0800 689 0668 and say so — live incidents go to the front.

The wider service is described on the ransomware recovery page, and the hardware most business data lives on has its own: RAID, NAS and SAN and virtual machines.

The dearest loss in most attacks isn't the encryption — it's the backup job that ran on schedule afterwards. Suspend every automated backup the moment ransomware is confirmed, before the automation swaps your clean copies for locked ones.

// questions on this topic

Common questions

Directly, only in two cases: a published decryptor exists for that family, or the attack quit before finishing. The reliable recoveries come from the flanks — snapshots and shadow copies that half-survived, cloud version history, and the volumes and files the sweep never visited.
Often not. Deleting a snapshot de-lists it; the underlying blocks stay on the disks until something overwrites them, and attackers rarely finish that job. Imaging the disks and hunting snapshot remnants is a standard stage of ransomware work here.
Rebuild, yes — never onto the affected disks. Image or shelve the originals, stand the business up on new storage, and let the old drives be mined for everything still recoverable. A reinstall over the top converts recoverable data into memories.
Yes. NDAs are there for the asking, handling is GDPR-compliant throughout, and working alongside IT providers, insurers and incident responders is the normal shape of these jobs. Recovered data returns on an encrypted drive.

Read enough — want it recovered?

Free diagnostic inside 2 working days of arrival, one fixed quote, no fix no fee on logical faults. Start online or ring the freephone.