You arrive to find every document wearing an extension you have never seen and a demand note repeated in folder after folder, insisting the attackers' own decryptor is the only road home. The disks frequently disagree. PCs, servers and NAS units belonging to Norfolk firms and households are gone through here for every lawful way home, and paying the people responsible has never once been on that list.
Every ransomware job is diagnosed free. The quote follows in writing, fixed, before a screwdriver is picked up.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
The first job on any ransomware is matching the symptom to the fault — and after twenty-odd years, these thirty account for very nearly everything that comes through the door.
Every user folder encrypted in one overnight run. It is the classic attack on a single machine, and the shape most cases arrive in.
Boxes reachable from the internet are the preferred target. The snapshot trees beneath the shares escape the purge rather more often than the attackers intend.
Hypervisor-focused strains work through the datastore one virtual disk at a time and bring down the whole virtual estate together.
Families tuned for speed encrypt the opening stretch of each large file and move straight on. Databases and archives are left with usable remainders, which matters more than it sounds.
The shadow copies are deleted before the encryption starts, as a matter of routine. Even then, deleted shadow copies can often be carved back out of the free space.
Plugged in meant reachable; reachable meant encrypted. Older versions on it, and remnants, still count for a great deal.
Double extortion pairs the theft with the encryption and threatens publication. Whatever left the network is scoped for the insurers and, where it applies, for the ICO.
Boot-locked machines still give up their drives, which are imaged and examined underneath the lock, where the files have been all along.
SQL and Exchange files caught while writing end up half encrypted and half not. Salvage runs page by page against the captured image.
A NAS that re-encrypts every restore attempt is still owned by somebody else. Isolate first, then recover strictly from images.
Unknown strains are fingerprinted against the databases in search of a family and any published weakness that can lawfully be used.
Scareware plants ransom notes over files it never touched, and some genuine runs crash early. A bench check separates fright from actual loss inside the free diagnostic.
The big names run deletion passes that are thorough and imperfect at the same time. Recovery lives in the imperfect parts, and we have a decent idea of where those tend to be.
The home-PC staple, arriving with pirated software. Older offline-key variants have a free public decryptor, which is applied lawfully whenever it fits the sample.
Some families encrypt a copy and delete the original, which abandons that original in free space where it can be carved. It is a design oversight we are very fond of.
Exposed remote desktop is still an open door, and encryption tends to follow some hours after entry. The logs date that entry to the minute.
Cloud sync loyally replaced good files with encrypted ones as fast as they appeared. Version history and remnants are checked at both ends of that pipe.
Encrypted virtual disk files bring down every guest at once. Partial-encryption habits frequently leave those guests rebuildable.
Nothing locked, everything copied, and a leak threatened. The job turns from recovery into forensic scoping and the questions change accordingly.
The one disk that happened to be connected on the night took the hit. Off-rotation sets and carved remnants bridge the gap it leaves.
Scheduled tasks and services can refire the malware weeks afterwards, generally in the middle of a restore. Images are swept for footholds before any rebuild is allowed to go live.
Some firms advertising recovery quietly pay the ransom and present the result as expertise. We recover from evidence, we say what is possible, and we carry no messages to criminals on anybody's behalf.
Modern crews take out the safety net before they pull the trigger, and they are good at it. Repository files often keep recoverable structure regardless.
Some strains destroy with no decryption route in existence, whatever the note promises. It is identified quickly and said plainly, and recovery then works from remnants and copies.
Some runs encrypt small configuration files and never touch the large flat data behind them. Rebuilding from the material they skipped restores entire machines.
Object-locked and immutable copies survive attacks that take everything else, because the attacker's own credentials could not delete them. Where one exists it changes the whole job, and part of our assessment is establishing whether one does before anybody starts carving.
Some organisations pay before ringing anybody, and the tool that arrives is slow, crashes on large files, or corrupts what it touches. Files damaged by a faulty decryptor are their own recovery problem, and it is worth capturing everything before running it a second time.
Encryption on the desktop does not reach a hosted mailbox, but deletion by an attacker who took the credentials certainly does. Retention and recovery windows in the tenant are finite and they are ticking, so that thread gets pulled early.
Virtualisation hosts are sometimes encrypted underneath machines that are still running happily in memory. Powering those guests off completes the attacker's work for them. There is an order in which to do this, and getting it right can save the estate.
The instinct after an attack is to rebuild and get trading again, and the rebuild lands on top of everything that could have been recovered. If there is any chance the data matters, take the disks out and set them aside first. It costs an afternoon and it has saved entire businesses.
The malware walked the storage encrypting one file after another with entirely conventional cryptography: AES over the contents, and those keys then sealed under an asymmetric one, the private half of which stays with the people who sent it. That unfamiliar extension is the strain's signature, and the note prints once the run is finished. Capable families also remove shadow copies, chase down whatever backups they can reach, and sweep every share the compromised account had rights over, which is why the demand reads with such confidence. It says nothing at all about what the run failed to reach, and a careful look almost always finds something.
No laboratory anywhere brute-forces properly implemented encryption, and a firm hinting that it might is selling a story rather than a service. Much of what gets advertised as decryption turns out on inspection to be negotiation with the attackers, resold at a markup. The honest version goes mining for the mistakes the attack made. Snapshots and shadow copies the purge missed. Backups that were offline, or simply out of reach. Files that were deleted rather than encrypted, because the strain worked on duplicates. Temporary artefacts and fragments carved from slack and unallocated space. NAS and RAID structures broken by the attack and rebuilt until readable data appears underneath. For the handful of families whose implementation flaws are public, a free decryptor applied properly. Which of those doors exists in your case is what the free assessment establishes, and it says so plainly when the answer is none of them.
Nothing is ever paid from this bench, no message is carried to an attacker for a client, and nobody is nudged toward settling. It finances the next campaign, guarantees nothing whatever, and criminal decryptors are notorious for wrecking the files they are meant to release. What you get instead is every technical avenue followed to its end, and a written account of what returned and what did not. Should insurers and advisers later take a company down the negotiating road, that decision is theirs to own; our part was to see that the technical answer got there first.
Ransomware cases run as forensic incidents from the first minute: isolated, imaged, documented, and only then recovered:
Incident media stays off the network entirely and is worked on an isolated rig where nothing can spread, call home, or resume encrypting where it left off.
Attacked drives are captured behind physical write-blocking before anyone examines them. Recovery then touches copies while the originals sit sealed.
Free space swept for shadow copies and snapshot remains that the purge overlooked, then rebuilt into restore points that genuinely restore.
The note plus a handful of samples identify the family, and that family gets checked against the public sources worth trusting for any lawful decryptor that exists.
Unencrypted originals, temporary copies and half-finished files pulled out of free space: the debris that every rushed encryption run leaves behind.
Strain, spread and outcome documented as the work proceeds, which is the paperwork that insurers, regulators and your own post-mortem all end up wanting.
Two undertakings, given in writing before any work begins. A strain with no published weakness will not be brute-forced — not by this lab and not by any other. No ransom is paid from here either, nor any message carried to the people who are holding them. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.
Before anybody reaches for the parcel tape: pull the network leads out and leave the affected machines precisely as they stand. No antivirus sweeps, no reinstalling and no formatting, because every one of those passes grinds away the remnants recovery feeds on. Hold on to the ransom note and two or three encrypted samples so the strain can be named, then ring 0800 689 0668 and we will agree between us what should travel. Media travels tracked and insured, by your own courier, or in person to reception at our Cambridge location. Capture happens on the air-gapped bench and recovery only ever touches copies.
Most of what reaches this bench arrived by tracked, insured post. It is the steadiest way to move a poorly drive, and a parcel posted in Norfolk is usually on the bench the next working day.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
Diagnosis free, one figure written down, most work under no fix no fee. Start online, or ring us.