Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · The Passage of Time Cuts Both Ways

An Old Attack Is Worth Identifying Precisely, Because Some Have Since Been Broken

His enquiry concerns something that happened years ago and has been left entirely alone since. A laptop attacked in 2018, where he "hasn't attempted to unlock it and the attackers disappeared", still encrypted, with music files and notation work he would like back. Leaving it alone was the right decision, and the years since have changed the position in one specific way that is worth checking before anything else.

MediaLaptop hard drive encrypted by hostile software in 2018 — no remediation attempted; machine unused since; audio and music notation files sought
Reported situationLaptop affected by hostile encryption in 2018 · no attempt made to remediate or pay · originating party no longer contactable · content remaining encrypted · machine unused in the intervening period · audio recordings and music notation files sought
Fault classHostile encryption of unidentified family — feasibility governed by whether a published weakness or key set exists; unencrypted remnants possibly retained
Equipment usedEncryption family identified from file markers and note structure before any remediation was considered · published recovery tooling checked against the identified family · imaged write-blocked at the block level before any interpretation · unencrypted remnants located in temporary, cache and unallocated regions · content carved by signature independently of the encrypted copies

The decode: what identification is for, and what may have escaped encryption

Why the family matters more than the age: the families differ enormously. Some were implemented with flaws that were later analysed and published, and free tooling exists for those.

Why that possibility grows rather than shrinks with time: analysis continues. Keys have been seized and released, and weaknesses have been found years after a family stopped operating.

How the family is identified: from what it left. The extension applied, the structure of the note and markers within the encrypted files identify it fairly reliably.

What the honest position is if no tooling exists: nothing can be done to the encrypted copies. Sound encryption without the key is a mathematical transformation rather than a barrier, and no amount of effort changes that.

Why that is not the end of the case: encryption is rarely complete. Hostile software works under time pressure and commonly skips large files, skips certain locations, or encrypts only the first portion of each file.

Why partial encryption matters especially for his material: audio files are large. Where only the opening of a file is transformed, the remainder is intact and the audio can frequently be recovered by rebuilding a header.

What else commonly escapes: the remnants. Temporary copies, caches, previous versions and unallocated regions hold unencrypted material the attack never enumerated.

Why leaving the machine untouched preserved all of that: nothing overwrote it. A machine returned to service would have consumed exactly those regions, and his has not.

Why the attackers disappearing changes little practically: paying was never a reliable route. The absence of a counterparty removes an option that should not have been taken anyway.

What must not happen now: no cleaning tools and no reinstallation. Removal software deletes encrypted files as hostile artefacts, and those files are the material.

On the bench

The encryption family was identified from file markers and note structure before any remediation was considered — families differing widely, with some implemented flawed and subsequently analysed, and published tooling or released key sets appearing years after a family ceased operating. Where no such route exists the encrypted copies are final. Unencrypted remnants were located in temporary, cache and unallocated regions, which an unused machine retains and a machine returned to service consumes.

The outcome

The family identified before any remediation, published tooling checked against it, and unencrypted remnants located across temporary and unallocated regions. Free assessment, one fixed written figure including VAT; where recovery is not possible, nothing is charged. The decode: identify the family first, because some have been broken since 2018 and tooling appears years after the fact. And leaving the machine alone preserved exactly the remnants that an attack rarely reaches.

A machine encrypted years ago and set aside

Don't run removal or cleaning tools, and don't reinstall — removal software deletes encrypted files as hostile artefacts, and those files are the material you want. Get the family identified first, from the extension applied, the note's structure and markers inside the files: some families were implemented with flaws that were analysed later, and free tooling or released keys appear years after the fact. Leaving the machine unused preserved the caches, temporary copies and unallocated regions an attack rarely reaches.

Machine encrypted years ago, left untouched?
Don't run cleaning tools — call Cambridge Data Recovery on 01223 655015; family identified before any remediation, published tooling checked, unencrypted remnants located across temporary and unallocated regions.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.