Home / Blog / Business

Ransomware recovery: where files genuinely survive an attack, and why the ransom is not one of those places

The first hour: stand still, deliberately

The instinct is to do something. Almost every something available in that first hour makes matters worse. Isolate the affected machines from the network but leave them powered as they are, because encryption keys and useful artefacts sometimes sit in memory and a reboot throws them away. Do not run the ransomware's own decryptor. Do not let anyone reinstall Windows over the top. Above all, stop every automatic backup, snapshot and cloud sync immediately, because the next scheduled run will cheerfully write encrypted rubbish over the last clean set you own.

Then write things down while they are fresh: when it was noticed, which machines are affected, what the ransom note is called, and the file extension appended to the encrypted files. That extension identifies the family, and the family determines whether there is a published decryptor. Photograph the note rather than deleting it. If your firm carries cyber insurance, tell the insurer before anything is changed, because policies usually require the scene to be left intact.

The three places files outlive an encryption run

Backups the malware could not reach. Anything offline, anything genuinely immutable, and anything on a system the attackers did not have credentials for. Modern ransomware hunts backups first and deletes what it finds, so the copies that survive are the ones that were disconnected or write-locked. Verify by restoring a sample somewhere isolated before you trust the set — a backup nobody has ever restored from is a hypothesis, not a backup.

Volume shadow copies and snapshots. Usually deleted, but not always completely, and the deletion often leaves recoverable remnants on the disk. This is bench work rather than something to attempt on the live machine, and it is one of the reasons the drives should not be reformatted or reinstalled over.

The originals the encryption left behind. This is the one most people do not know about. Plenty of ransomware writes an encrypted copy and then deletes the original, instead of overwriting the original where it lay. On a spinning hard drive the deleted original frequently remains fully intact until something else writes over that space, which means an image taken from the disk can yield genuine, unencrypted files. It works far less often on an SSD, where TRIM clears deleted blocks quickly, and it works not at all if the machine has been left running and busy for a week. Which is exactly why the first hour matters.

On paying: the answer, once

No. Not because of a moral position anyone needs to hear about, but because it is a poor transaction. You are buying a promise from a criminal, at a price, in a currency you cannot claw back. A meaningful share of decryptors either do not work, work partially, or corrupt large files while appearing to succeed. Payment marks your firm as one that pays, and repeat attacks on the same organisation are common. And in many attacks the data was exfiltrated before encryption, so paying buys you a decryption key and no control at all over the copy they kept.

Before anything else, check whether the family has already been beaten. The No More Ransom project, run with Europol and a group of security firms, publishes free decryptors for a long list of families, and identifying yours by the file extension takes minutes. It costs nothing to look and it occasionally ends the whole incident on the spot. We will not arrange a ransom payment, we will not negotiate on your behalf, and we will tell you plainly if the honest answer is that your only route back is a clean rebuild from a backup.

Getting the storage looked at

Ransomware work is forensic-classed here, which means it is quoted and paid up front in full and does not run under no fix, no fee. That is stated plainly rather than buried, because forensic work is slow, manual and produces no guarantees, and pretending otherwise would be dishonest. The free diagnostic still applies: nothing is charged to establish what survived, and that assessment is finished within 2 working days of the media arriving.

Send the drives themselves, not the servers or the machines. Pull the disks, label them with the bay each came from, and post them tracked and insured, or use a courier you book and pay for yourself, or bring them to the counter at Edinburgh Data Recovery, 4 Redheughs Rigg, Westpoint, South Gyle, Edinburgh EH12 9DQ, open Monday to Friday, 9am to 5:30pm. Nothing is picked up from your premises; there is no such service here. Every disk is imaged read-only, so the evidential state of your media is preserved for insurers and for anyone who needs to look at it later. Ring 0800 689 0668 and the job is flagged before the parcel arrives.

The costly loss in most attacks is not the encryption. It is the scheduled backup that ran four hours later and copied the mess over the last clean set. Halt every automatic backup, snapshot and sync the second an infection is suspected — before anything else, and before anyone reboots anything. That one action has saved more north-east firms than any product they were sold afterwards.

// questions on this topic

Common questions

Sometimes, and it is always worth checking. Current families use encryption that cannot realistically be broken, but older or badly implemented ones have been cracked and free decryptors are published through No More Ransom. Identify the family from the extension on the encrypted files before assuming anything. If no decryptor exists, recovery comes from backups, snapshot remnants and deleted originals instead.
Not automatically. Deleting a snapshot removes the reference; the blocks behind it are often still on the disks until something else claims them. Power the unit down now and stop it rebuilding or resilvering. Send the member disks labelled in bay order and they will be imaged read-only and examined for what survived the deletion.
Not until the drives have been imaged. A reinstall writes across the free space where deleted originals and snapshot remnants are sitting, and that is frequently the recoverable material. Take the disks out, get images made, and rebuild onto new storage. Rebuilding onto the same disks destroys the evidence and the recovery in one move.
Yes. Confidentiality agreements are routine and the work stays in-house rather than being subcontracted. Media is imaged read-only so its evidential state is preserved, recovered data is returned on encrypted media where you want that, and working images are destroyed on your confirmation. Nothing is examined beyond what the recovery itself requires.

Read enough — want it looked at?

Diagnosis costs nothing and takes 2 working days from arrival, the figure is fixed in writing, and logical work runs no fix no fee. Begin online, or lift the phone.