Home / Blog / Business

Ransomware data recovery: the three places files survive, and why the ransom is never one of them

The first hour: stand still on purpose

The instinct after finding the ransom note is to start putting things right, and it is almost always the wrong instinct. Disconnect affected machines from the network — pull the cable, drop the wi-fi — but leave them switched on if you reasonably can, because volatile memory occasionally still holds keys or process detail that is gone the moment the power is. Photograph the note. Keep one sample of an encrypted file and, if you can find it, an untouched original of the same file; a matched pair like that is often what identifies the strain and tells you whether a published decryptor exists.

Then suspend every automated backup job before anything else. This is the single costliest mistake we see, and it is nobody's fault in particular: the backup ran overnight, exactly as designed, and faithfully replaced the last good copies with encrypted ones. Snapshots, replication, cloud sync and the rest all behave the same way, because none of them can tell the difference between a legitimate change and a malicious one. Pause them, then start working out what you actually still have.

The three places files outlive an attack

First place: whatever the attack did not reach. Offline media is the obvious candidate — a rotated drive in a safe, an archive tape, the disk somebody unplugged in March and forgot about. Anything not connected at the time is usually untouched, which is the entire argument for keeping one copy that is not permanently attached to anything. Cloud sync services often keep versioned copies too, though only for a limited window, so check the retention period before you assume.

Second place: the deleted originals. Plenty of ransomware families encrypt a copy of each file and delete the original rather than overwriting it in place. Deleting removes the reference and leaves the content sitting on the disk until something else needs the space, so a forensic pass across the raw disk frequently recovers a substantial proportion of the pre-attack files intact. This is ordinary recovery work rather than cryptography, and it is the route that most often produces the good news.

Third place: what the attacker missed. Encrypting an entire estate takes time and makes noise, so attacks are commonly interrupted — by someone noticing, by a machine going to sleep, by the process falling over on a large share. Partial encryption is extremely common: file headers scrambled while the bulk of a large file remains readable, whole directories skipped, one server left alone because it was off that night. An itemised assessment of what is genuinely encrypted, rather than what appears to be, is the first useful thing anyone can give you.

About paying: the answer, given once

We will not help you pay, and we will not quietly pay on your behalf and present it as a recovery — a practice that exists in this industry and should not. The reasons are practical rather than moral. A meaningful share of victims who pay receive a decryptor that is broken, partial or simply never arrives. Payment marks you as a payer, and repeat targeting is a documented pattern. There may be sanctions exposure attached to the group you would be paying. And every payment funds the next attack, quite possibly on somebody you know.

There is one honest exception to the pessimism, and it is worth ten minutes of anybody's time: some strains have been broken, and free decryptors are published for them by law enforcement and security researchers through the No More Ransom project. Take your note and a sample encrypted file, check there first, and check before you do anything else. It costs nothing and it occasionally ends the whole problem in an afternoon.

Getting the storage to an engineer

Practicalities. Ransomware recovery is forensic-classed work here, which means the fee is settled in advance rather than on the usual no fix, no fee basis, and it means the job is handled with a documented chain of custody in case an insurer, a regulator or a solicitor wants to see one later. What you send is the storage — the disks themselves, labelled by bay if they came out of a server or a NAS — rather than the whole rack, and you send it tracked and insured, or bring it to the Cambridge desk yourself. There is no collection service, so nothing waits on a van.

The assessment is free and complete inside 2 working days of arrival. It tells you what is actually encrypted, what is recoverable from deleted originals, whether a published decryptor applies, and what a full recovery would cost as one fixed figure. Norfolk's larger employers — the food processors and packers, the agricultural co-operatives, the offshore supply-chain firms out of Great Yarmouth — all run systems where a week of lost records is a great deal more expensive than the assessment, and all of them are welcome to ring 0800 689 0668 before they decide anything at all.

In most attacks the expensive loss is not the encryption itself — it is the backup that ran on schedule a few hours later. Pause every automatic backup, snapshot and sync as soon as an infection is confirmed, before your own automation trades the last clean copies for locked ones.

// questions on this topic

Common questions

Sometimes directly, if the strain is one of those that has been broken and a free decryptor is published. More often the route back is different: recovering the deleted originals the attack left behind, restoring from something that was offline at the time, or salvaging the parts of the estate the encryption never reached. Breaking modern encryption itself is not on the table for anybody.
Not necessarily. Deleted snapshots and deleted volumes both leave their content on the disks until it is overwritten, and a forensic pass across the raw disks recovers a useful proportion more often than people expect. Power the unit down now, do not rebuild or re-initialise anything, and send the disks labelled by bay.
Only after you have taken a full image of every affected disk, and only once you know how they got in. Rebuilding over the top destroys the deleted originals that are frequently the best route back, and it destroys the evidence of the entry point, which means the same door stays open. Image first, investigate second, rebuild third.
Yes, and it usually needs to. Work can run under a non-disclosure agreement, media is handled under documented custody, and the report is written so it can be handed to an insurer or a regulator without exposing anything else. Media is returned or securely destroyed exactly as you instruct, and nothing is discussed outside the job.

Read enough — want it recovered?

Free diagnostic inside 2 working days of arrival, one fixed quote, no fix no fee on logical faults. Start online or ring the freephone.