Home / Devices / Ransomware

Ransomware Data Recovery Aberdeen

Every file wearing an extension you have never seen. The same demand note dropped into folder after folder. And a claim that the attackers' own decryptor is the only way home. The disks frequently tell a different story. PCs, servers and NAS units get examined here for every lawful route back. Paying the people who did it has never been one of them.

Every ransomware job is diagnosed free. The fixed figure reaches you in writing first, before any tools come out.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// twenty-five faults this bench knows cold

The twenty-five ways they quit

First job on any ransomware is matching the symptom to the fault. Twenty-odd years in, these twenty-five cover nearly every one that reaches this bench.

One machine, everything locked

Every user folder encrypted in one run while nobody was watching the screen. That is the classic single-machine attack, and it is the shape most cases arrive here in. What matters next is that the machine stays off.

The shares on the NAS encrypted

A box reachable from the internet is the preferred target. Snapshot trees underneath those shares escape the purge considerably more often than the attackers intend.

A datastore gone in an evening

Strains aimed at hypervisors work through a datastore one virtual disk at a time, bringing the whole virtual estate down together. Partial-encryption habits often leave those guests rebuildable.

Large files only partly encrypted

A family tuned for speed encrypts the first stretch of each large file, then moves straight on. That leaves databases and archives with usable remainders, which counts for far more than it sounds.

Restore points swept first

Deleting the shadow copies before encryption begins is routine practice. Even so, deleted shadow copies can frequently be carved back out of free space afterwards.

The backup drive was plugged in

Plugged in made it reachable. Reachable made it a target. Older versions on that drive, and the remnants around them, still count for a great deal once it is imaged.

Stolen first, locked second

Theft paired with encryption, plus a threat to publish, is double extortion. Whatever left the network gets scoped for your insurers and, where it is relevant, for the ICO.

A ransom demand in place of the login

A boot-locked machine still gives up its drive. That gets imaged and examined below the lock, where your files have sat the whole time, untouched by anything on the screen.

Databases torn mid-transaction

Caught mid-write, SQL and Exchange files finish half encrypted and half untouched. Salvage proceeds page by page against the captured image, never against the live file.

Still infected and still busy

A NAS re-encrypting each restore attempt still belongs to somebody else. Isolate it first. Recovery then runs strictly from images and never off the box itself.

An extension nobody recognises

An unknown strain gets fingerprinted against the databases, hunting for a family name and for whatever published weakness the law permits us to use against it. Knowing the family also tells us what that family habitually fails to delete.

All note and no encryption

Files nobody touched, scattered with ransom notes by scareware, and genuine runs that crashed early, both arrive here. A bench check inside the free diagnostic separates fright from real loss.

A strain off a cracked download

The home-PC staple, arriving in company with pirated software. A free public decryptor exists for older offline-key variants, and we apply it lawfully whenever it fits the sample.

Original deleted, copy encrypted

Certain families encrypt a copy, then delete the original, abandoning that original in free space where carving retrieves it. A design oversight of which we are extremely fond.

In through remote desktop

Remote desktop left exposed remains an open door, with encryption following a few hours behind the entry. Logs date that entry to the minute, which matters a great deal to insurers.

Sync pushing the damage upstream

As fast as encrypted files appeared, cloud sync dutifully swapped them for the good ones. Version history gets checked, along with remnants, at either end of that pipe.

A foothold left for later

Scheduled tasks and services can set the malware off again weeks later, usually mid-restore. We sweep the images for footholds before a rebuild goes anywhere near production.

Middlemen who simply pay

Certain firms advertising recovery quietly pay the ransom, then present the outcome as expertise. Evidence is what we recover from. We tell you what is achievable, and we carry messages to criminals for nobody.

Backup servers hunted first

Removing the safety net comes before the trigger gets pulled, and modern crews are practised at it. Repository files often retain recoverable structure whatever the console reports.

A wiper wearing ransomware's clothes

Certain strains simply destroy, with no decryption route in existence anywhere, whatever their note promises. We identify that quickly and say it plainly. Recovery then works off remnants and copies.

Backups that could not be altered

Immutable and object-locked copies come through attacks that take everything else, for the straightforward reason that the attacker's credentials had no power to delete them. One of those changes the entire job, so finding out whether you have one is part of the assessment, well before carving begins.

A purchased decryptor that does not work

Plenty of organisations pay before ringing anyone, then find the tool they bought is slow, falls over on large files, or corrupts whatever it touches. A faulty decryptor creates its own recovery problem, so capture everything before that tool gets a second run.

Mailboxes in a cloud tenant

Encryption on a desktop does not reach a hosted mailbox. Deletion carried out by an attacker in possession of the credentials certainly does. Inside a tenant, retention and recovery windows are finite, and already running down, so that thread gets pulled early.

Hosts encrypted while the guests kept running

Virtualisation hosts are sometimes encrypted underneath machines still running happily in memory. Power those guests down and you complete the attacker's job on their behalf. An order exists for doing this properly, and following it can save the estate.

Reimaged by IT before anyone asked

Instinct after an attack says rebuild, get trading again. That rebuild then lands squarely on everything which could still have been recovered. Where there is a chance the data matters, pull the disks and set them to one side before anything else. An afternoon's delay, and it has saved entire businesses.

What actually happened to your files

Nothing exotic. The malware went through the storage encrypting file by file, using thoroughly standard cryptography. AES across the contents. Each of those keys then sealed under a second, asymmetric one. Its private half stayed with the people who sent the malware. The strange extension identifies the strain. The note is written at the end of the run. Better-organised families do more than encrypt: they clear shadow copies, look for any backup they can reach across the network, and cover every share the compromised account had write access to. That thoroughness is why the demand reads so confidently. It is also silent about everything the run never got to, and a careful search almost always finds some of it.

The routes home that are lawful

No laboratory on earth brute-forces properly implemented encryption. A firm that hints it might is selling a story. Much of what gets marketed as decryption turns out, once you look, to be negotiation with the criminals, resold at a margin. The genuine work goes looking for what the attack missed. Snapshots and shadow copies that survived the purge. Backups that were offline or otherwise out of reach. Originals the strain deleted instead of encrypting, because it worked on copies. Temporary artefacts and fragments carved out of slack and unallocated space. NAS and RAID structures the attack broke, rebuilt until readable data shows through. And where a strain has a publicly documented implementation flaw, a free decryptor, applied properly. The free assessment establishes which of those doors is open in your case. And when the answer is none of them, it says so plainly.

Where this bench stands on paying

Nothing is paid. No message goes to an attacker on behalf of a client. Nobody here nudges anyone toward settling. The reasons are practical rather than moral posturing: payment funds the next campaign, the promise cannot be enforced, and criminal decryptors have a bad record for damaging the files they release. What is offered instead is every technical route followed to the end, and a written account of what came back and what did not. If insurers and advisers later steer a company toward negotiating, that call is theirs to make. The job here was to make sure the technical answer arrived before it.

// the kit behind the work

Engineering kit, not downloaded software and hope

Ransomware jobs run as forensic incidents from the opening minute. Isolate, image, document, and recover only after those three:

Air-gapped imaging bench

Incident media never touches a network. Work happens on an isolated rig. Nothing there can spread, phone home, or resume encrypting from where it stopped.

Hardware write-blockers

Drives from an attack get captured behind physical write-blocking before anybody examines anything. Recovery works on copies while the originals stay sealed.

Shadow copy carving

We sweep free space for shadow copies and snapshot remains the purge overlooked, then rebuild those into restore points that actually restore something.

Strain identification

A ransom note plus a handful of samples names the family. That family is then checked against whichever public sources are worth trusting, in case a lawful decryptor exists.

Remnant and free-space carving

Originals left unencrypted, temporary copies, half-finished files, all pulled out of free space. Every hurried encryption run leaves that debris behind it.

Forensic logging and reporting

Strain, spread and outcome written down as the work proceeds. That is the paperwork your insurer, the regulator and your own post-mortem all ask for eventually.

// makes & models we see

Families and patterns handled

LockBitAkiraPhobosDharmaMakopSTOP / DjvuBlackCat / ALPHVMedusaConti lineageESXiArgs

The honest sources of recovery

Two undertakings, put in writing before work starts. Where a strain has no published weakness, nobody brute-forces it, this lab included and every other lab besides. Nor does any ransom get paid from here, and no message at all travels to the criminals at the other end of it. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.

// before it goes in the box

Before it goes in the box — free the drive if you can

Parcel tape can wait. Start by pulling the network leads and leaving every affected machine standing as it is. No antivirus sweeps. No reinstalling. No formatting. Each of those passes destroys the remnants that recovery feeds on. Hang on to the ransom note, along with two or three encrypted samples, because that is how the strain gets named. Ring us then on 0800 689 0668 and we will settle what has to travel. Media goes tracked and insured, by a courier you book, or in person to reception at our Edinburgh location, open Monday to Friday, 9am to 5:30pm. Capture runs on the air-gapped bench, and copies are the only thing recovery ever touches.

// getting your device to us

Getting it to the bench — plainly done

Nearly everything on this bench came by tracked, insured post. It is the safest way to shift a failing drive, and a parcel handed in at a North-East post office is usually here the next working day.

Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.

  • Bubble wrap, then a rigid box or padded envelope packed tight enough that nothing rattles. Keep the cables, caddies and power bricks at home.
  • Print the shipping & booking-in form (PDF). Name, mobile number, two lines on what went wrong. In the box with the drive.
  • Royal Mail Special Delivery is tracked and insured door to door. Your own courier account does the same job if you would rather use it.
  • Handing it over yourself instead? Reception takes drop-offs at the address below, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Edinburgh Data Recovery

4 Redheughs Rigg
Westpoint, South Gyle
Edinburgh, EH12 9DQ

↓ Print the shipping & booking-in form (PDF)

Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.

Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.

// ransomware recovery questions

Common questions

Only when the strain allows it. That means either a free decryptor already published, or a documented flaw in how the encryption was built. That list is short, and it is mostly older STOP/Djvu variants plus a few careless imitators. Encryption done properly opens for nobody. So the effort goes where results are possible: snapshots, backups, originals deleted instead of encrypted, fragments carved from unallocated space, and volumes rebuilt out of broken structures. The free assessment identifies which of those apply to you.
No, in any form. Nothing gets paid. Nothing gets brokered. Settling is never the recommendation from here. Payment funds the next attack, the promise is unenforceable, and the tools handed back regularly damage what they are supposed to unlock. If that decision does get taken, it belongs to you, your insurer and your advisers. Our involvement finishes when every technical route has been followed to its end.
The disks get assessed free of charge. A verdict comes back inside 2 working days of them arriving, along with one fixed quote in writing. This work sits in the forensic class, so that quote is settled before recovery starts rather than on a no fix, no fee basis, and it sets out a realistic scope before you part with anything at all.
Get everything affected off the network, then leave it strictly alone. No reinstalling, no formatting, no clean-up utilities, because each of those destroys the remnants a recovery is built on. Hold on to the note and two or three encrypted files, because that is what identifies the strain. Then ring 0800 689 0668, and post the disks with their bay numbers marked on them. Everything happens on forensic images and your originals stay sealed.
Fewer than the advertising suggests, once you subtract the outfits selling negotiation with a fresh coat of paint on it. Aberdeen Data Recovery does the work in-house. Locked PCs. NAS boxes. Servers and entire virtual estates. All of it arrives by tracked, insured post at our Edinburgh location — Edinburgh Data Recovery, 4 Redheughs Rigg, Westpoint, South Gyle, Edinburgh EH12 9DQ, Monday to Friday, 9am to 5:30pm — from every corner of the country. There is no collection service. Assessment is free and names both the strain and the realistic options; as forensic-class work the quote is settled up front, and nothing is ever paid to an attacker or brokered for a client.
// related services

Other work this lab takes on

The bench is ready when you are.

Free diagnosis, one number written down, no fix no fee on the bulk of jobs. Start online or phone it in.