Every document renamed, a ransom note in each folder, and the backup NAS encrypted alongside everything else because it was mapped as a drive letter. Then the machine was left running for two days while the business decided what to do.
← All case files · £300 + VAT, flat
This is a scenario, not a case study. It describes a failure pattern we handle regularly and how it is approached, written from the technical work rather than from one client's job. Our documented case files are here.
An encryption run has completed across a network. Files carry a new extension, a ransom note is present, and the backups have been found to be encrypted too — or to have been failing quietly for months. The question is what can be recovered without paying.
Modern ransomware uses standard public-key cryptography: files encrypted with a symmetric key, that key encrypted with the operators' public key, the private key never leaving their possession. There is no flaw to exploit and no computation that shortens it.
Several firms advertise ransomware decryption as a service. In practice a number of them negotiate and pay on the client's behalf, marked up, without saying that is what happened. You are then paying a premium for something you could have arranged directly, and funding the operation either way.
The honest exception is older or badly implemented strains where researchers have published working decryptors. The No More Ransom project catalogues those and it is worth checking. If yours is not listed, no laboratory is going to decrypt it.
Disconnect affected machines from the network and from each other. Do not reimage — those disks hold the unencrypted originals in free space.
Payment carries no guarantee and the decryptors supplied frequently work partially. Find out what you can get back without it before deciding.
UK GDPR requires notification within 72 hours of becoming aware where personal data is affected. That clock is independent of the recovery.
Offline copies, immutable cloud snapshots and version history survive far more often than network shares do.