Every file wearing an extension you have never seen. The same demand note dropped into folder after folder. And a claim that the attackers' own decryptor is the only way home. The disks frequently tell a different story. PCs, servers and NAS units get examined here for every lawful route back. Paying the people who did it has never been one of them.
Every ransomware job is diagnosed free. The fixed figure reaches you in writing first, before any tools come out.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
First job on any ransomware is matching the symptom to the fault. Twenty-odd years in, these twenty-five cover nearly every one that reaches this bench.
Every user folder encrypted in one run while nobody was watching the screen. That is the classic single-machine attack, and it is the shape most cases arrive here in. What matters next is that the machine stays off.
A box reachable from the internet is the preferred target. Snapshot trees underneath those shares escape the purge considerably more often than the attackers intend.
Strains aimed at hypervisors work through a datastore one virtual disk at a time, bringing the whole virtual estate down together. Partial-encryption habits often leave those guests rebuildable.
A family tuned for speed encrypts the first stretch of each large file, then moves straight on. That leaves databases and archives with usable remainders, which counts for far more than it sounds.
Deleting the shadow copies before encryption begins is routine practice. Even so, deleted shadow copies can frequently be carved back out of free space afterwards.
Plugged in made it reachable. Reachable made it a target. Older versions on that drive, and the remnants around them, still count for a great deal once it is imaged.
Theft paired with encryption, plus a threat to publish, is double extortion. Whatever left the network gets scoped for your insurers and, where it is relevant, for the ICO.
A boot-locked machine still gives up its drive. That gets imaged and examined below the lock, where your files have sat the whole time, untouched by anything on the screen.
Caught mid-write, SQL and Exchange files finish half encrypted and half untouched. Salvage proceeds page by page against the captured image, never against the live file.
A NAS re-encrypting each restore attempt still belongs to somebody else. Isolate it first. Recovery then runs strictly from images and never off the box itself.
An unknown strain gets fingerprinted against the databases, hunting for a family name and for whatever published weakness the law permits us to use against it. Knowing the family also tells us what that family habitually fails to delete.
Files nobody touched, scattered with ransom notes by scareware, and genuine runs that crashed early, both arrive here. A bench check inside the free diagnostic separates fright from real loss.
The home-PC staple, arriving in company with pirated software. A free public decryptor exists for older offline-key variants, and we apply it lawfully whenever it fits the sample.
Certain families encrypt a copy, then delete the original, abandoning that original in free space where carving retrieves it. A design oversight of which we are extremely fond.
Remote desktop left exposed remains an open door, with encryption following a few hours behind the entry. Logs date that entry to the minute, which matters a great deal to insurers.
As fast as encrypted files appeared, cloud sync dutifully swapped them for the good ones. Version history gets checked, along with remnants, at either end of that pipe.
Scheduled tasks and services can set the malware off again weeks later, usually mid-restore. We sweep the images for footholds before a rebuild goes anywhere near production.
Certain firms advertising recovery quietly pay the ransom, then present the outcome as expertise. Evidence is what we recover from. We tell you what is achievable, and we carry messages to criminals for nobody.
Removing the safety net comes before the trigger gets pulled, and modern crews are practised at it. Repository files often retain recoverable structure whatever the console reports.
Certain strains simply destroy, with no decryption route in existence anywhere, whatever their note promises. We identify that quickly and say it plainly. Recovery then works off remnants and copies.
Immutable and object-locked copies come through attacks that take everything else, for the straightforward reason that the attacker's credentials had no power to delete them. One of those changes the entire job, so finding out whether you have one is part of the assessment, well before carving begins.
Plenty of organisations pay before ringing anyone, then find the tool they bought is slow, falls over on large files, or corrupts whatever it touches. A faulty decryptor creates its own recovery problem, so capture everything before that tool gets a second run.
Encryption on a desktop does not reach a hosted mailbox. Deletion carried out by an attacker in possession of the credentials certainly does. Inside a tenant, retention and recovery windows are finite, and already running down, so that thread gets pulled early.
Virtualisation hosts are sometimes encrypted underneath machines still running happily in memory. Power those guests down and you complete the attacker's job on their behalf. An order exists for doing this properly, and following it can save the estate.
Instinct after an attack says rebuild, get trading again. That rebuild then lands squarely on everything which could still have been recovered. Where there is a chance the data matters, pull the disks and set them to one side before anything else. An afternoon's delay, and it has saved entire businesses.
Nothing exotic. The malware went through the storage encrypting file by file, using thoroughly standard cryptography. AES across the contents. Each of those keys then sealed under a second, asymmetric one. Its private half stayed with the people who sent the malware. The strange extension identifies the strain. The note is written at the end of the run. Better-organised families do more than encrypt: they clear shadow copies, look for any backup they can reach across the network, and cover every share the compromised account had write access to. That thoroughness is why the demand reads so confidently. It is also silent about everything the run never got to, and a careful search almost always finds some of it.
No laboratory on earth brute-forces properly implemented encryption. A firm that hints it might is selling a story. Much of what gets marketed as decryption turns out, once you look, to be negotiation with the criminals, resold at a margin. The genuine work goes looking for what the attack missed. Snapshots and shadow copies that survived the purge. Backups that were offline or otherwise out of reach. Originals the strain deleted instead of encrypting, because it worked on copies. Temporary artefacts and fragments carved out of slack and unallocated space. NAS and RAID structures the attack broke, rebuilt until readable data shows through. And where a strain has a publicly documented implementation flaw, a free decryptor, applied properly. The free assessment establishes which of those doors is open in your case. And when the answer is none of them, it says so plainly.
Nothing is paid. No message goes to an attacker on behalf of a client. Nobody here nudges anyone toward settling. The reasons are practical rather than moral posturing: payment funds the next campaign, the promise cannot be enforced, and criminal decryptors have a bad record for damaging the files they release. What is offered instead is every technical route followed to the end, and a written account of what came back and what did not. If insurers and advisers later steer a company toward negotiating, that call is theirs to make. The job here was to make sure the technical answer arrived before it.
Ransomware jobs run as forensic incidents from the opening minute. Isolate, image, document, and recover only after those three:
Incident media never touches a network. Work happens on an isolated rig. Nothing there can spread, phone home, or resume encrypting from where it stopped.
Drives from an attack get captured behind physical write-blocking before anybody examines anything. Recovery works on copies while the originals stay sealed.
We sweep free space for shadow copies and snapshot remains the purge overlooked, then rebuild those into restore points that actually restore something.
A ransom note plus a handful of samples names the family. That family is then checked against whichever public sources are worth trusting, in case a lawful decryptor exists.
Originals left unencrypted, temporary copies, half-finished files, all pulled out of free space. Every hurried encryption run leaves that debris behind it.
Strain, spread and outcome written down as the work proceeds. That is the paperwork your insurer, the regulator and your own post-mortem all ask for eventually.
Two undertakings, put in writing before work starts. Where a strain has no published weakness, nobody brute-forces it, this lab included and every other lab besides. Nor does any ransom get paid from here, and no message at all travels to the criminals at the other end of it. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.
Parcel tape can wait. Start by pulling the network leads and leaving every affected machine standing as it is. No antivirus sweeps. No reinstalling. No formatting. Each of those passes destroys the remnants that recovery feeds on. Hang on to the ransom note, along with two or three encrypted samples, because that is how the strain gets named. Ring us then on 0800 689 0668 and we will settle what has to travel. Media goes tracked and insured, by a courier you book, or in person to reception at our Edinburgh location, open Monday to Friday, 9am to 5:30pm. Capture runs on the air-gapped bench, and copies are the only thing recovery ever touches.
Nearly everything on this bench came by tracked, insured post. It is the safest way to shift a failing drive, and a parcel handed in at a North-East post office is usually here the next working day.
Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.
↓ Print the shipping & booking-in form (PDF)
Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.
Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.
Free diagnosis, one number written down, no fix no fee on the bulk of jobs. Start online or phone it in.