You arrive to find every document wearing a strange extension and a demand note in every folder, insisting the criminals' decryptor is the only way home. The drives usually know better. Encrypted PCs, servers and NAS units from York businesses and households are examined here for every lawful route back — and handing money to attackers has never once been on the list.
Every ransomware job is diagnosed free. The quote turns up fixed, in writing, before a screwdriver is lifted.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
First job on any ransomware is putting the symptoms against the fault — after twenty-odd years, these twenty-five account for nearly everything that comes through the door.
Every user folder ciphered in a single overnight run: the classic single-PC attack, and the shape most cases arrive in.
Internet-facing boxes are preferred prey. The snapshot trees beneath the shares dodge the purge more often than attackers intend.
Hypervisor-focused strains work through the datastore VMDK by VMDK, felling the whole virtual estate at once.
Speed-tuned families encrypt an opening stretch of each big file and move along. Databases and archives keep usable remainders.
vssadmin runs before the encryption does. Even so, deleted shadow copies can sometimes be carved back out of free space.
Plugged in meant reachable, and reachable meant encrypted. Its older versions and remnants still count for plenty.
Double extortion pairs theft with encryption and threatens publication. What left the network gets scoped for insurers and the ICO.
Boot-locked machines give up their drives, which get imaged and examined beneath the lock — where the files actually are.
SQL and Exchange files caught writing end up half-ciphered. Salvage runs page by page against the capture.
A NAS that re-encrypts each restore attempt remains owned. Isolate first; recover strictly from images thereafter.
Unknown strains get fingerprinted against the databases in search of family and any published weakness worth exploiting lawfully.
Scareware plants ransom notes over untouched files, and some genuine runs crash early. A rig check separates fright from loss.
The big-name crews run deletion passes both thorough and imperfect. Recovery lives in the imperfections, and we know where they tend to be.
The home-PC staple. Older offline-key variants carry a free public decryptor, applied lawfully whenever it fits.
Certain families encrypt a copy and delete your original — abandoning that original in free space, carvable. A design oversight we cherish.
Exposed remote desktop remains an open door, with encryption following hours after entry. The logs date the walk-in to the minute.
OneDrive loyally replaced good files with ciphered ones. We check version history and remnants at both ends of the pipe.
Ciphered VHDX files drop every guest together. Partial-encryption quirks frequently leave those guests rebuildable.
Nothing locked, everything copied, leak threatened. The job turns from recovery to forensic scoping, and the questions change.
The one disk connected on attack night took the hit. Off-rotation sets plus carved remnants bridge the gap it left.
Scheduled tasks and services can re-fire the malware weeks on, mid-restore. Images get swept for footholds before any rebuild goes live.
Some 'recovery specialists' quietly pay the ransom and re-badge it as expertise. We recover from evidence, say what's possible, and carry no messages to criminals.
Modern crews disable the safety net before pulling the trigger. Repository files often keep recoverable structure all the same.
Some strains destroy with no decryption path in existence. Identified fast and said plainly; recovery then works from remnants and copies.
ESXiArgs-style runs encrypt small config files and miss the flat data behind them. Rebuilding from the skipped material restores entire machines.
The malware walked the storage encrypting file after file with entirely conventional cryptography — AES across the contents, those keys sealed in turn under an asymmetric key whose private half never leaves the attacker. The strange extension is the strain's signature; the note prints once the run finishes. Capable families also purge shadow copies, chase down reachable backups and sweep every share the compromised account could see, which is why the demand sounds so certain of itself. It never mentions what the run failed to reach, though — and a careful look nearly always finds something it didn't.
No lab anywhere brute-forces properly built encryption, and a firm implying it can is selling a story. Search for a ransomware decryption service UK-wide and much of what comes back is resold negotiation dressed as engineering; the honest version mines the attack's mistakes instead. Snapshots and shadow copies the purge overlooked. Backups out of the malware's reach. Originals that were deleted rather than encrypted, where the strain worked on a copy. Temp files and fragments carved from slack and free space. Broken NAS and RAID structures rebuilt until clean data shows through. And, for the minority of families with published flaws, a free decryptor applied lawfully. The free assessment maps which of those exits exist in your particular case.
No ransom gets paid from this bench, no message gets carried to an attacker, and no client gets steered toward paying — it bankrolls the next campaign, guarantees nothing, and criminal decryptors are famous for mangling the very files they claim to free. What you get instead: each technical route exhausted, and a written record of what came home and what stayed lost. If insurers and advisers later walk a company toward negotiating, that decision is theirs to own — ours was making certain the technical answer arrived first.
Ransomware cases run as forensic incidents from minute one: isolated, imaged, documented, then recovered:
Incident media stays off the network entirely, worked on an isolated rig where nothing spreads, calls home, or picks up encrypting where it left off.
Attacked drives get captured behind physical write-blocking before examination; recovery touches the copies while originals sit sealed.
Free space swept for shadow copies and NAS snapshot remains the purge overlooked, rebuilt into restore points that actually restore.
Note plus samples identify the family; the family gets checked against reputable public sources — No More Ransom, vendor releases — for any lawful decryptor.
Unencrypted originals, temp files and half-copies pulled from free space: the debris every rushed encryption run scatters.
Strain, spread and outcome documented as we go — the paperwork insurers, regulators and your own post-mortem will all ask for.
Two undertakings, given in writing before work starts: strains without a published weakness cannot be brute-forced by us or anybody, and we neither pay ransoms nor carry messages to the people holding your files. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.
First, before any parcel tape: unplug network leads and let affected machines stand exactly as they are — no antivirus sweeps, no reinstalling, no formatting, since every pass grinds away the remnants recovery feeds on. Keep the ransom note and a couple of ciphered samples so the strain can be identified, then ring 0800 689 0668 and we'll agree what should make the journey. Capture happens on the air-gapped rig; recovery only ever touches copies.
Nearly every job on our bench arrived by tracked, insured post — it's the quickest, safest route in. There's no collection service, so the parcel is yours to send or hand in.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Free diagnosis, a fixed written figure, no fix no fee on most work — start online or ring the freephone.