Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / ransomware
Specialist recovery · ransomware

Ransomware recovery in Cambridge, without the decryption promises.

Modern ransomware cannot be decrypted by anyone but the attacker, so the useful question is what survived it. Shadow copies the run failed to clear, unencrypted originals still sitting in free space, files it never reached, and backups it could not touch. We establish exactly what is recoverable, free, before you decide anything about paying.

From £300 + VAT
Strain identified first
Discreet & confidential
~ ransomjob-001 — live RECOVERED
$ cdr triage /dev/sdb
 Device: Dell PowerEdge (RAID 5)
 Status: RANSOMWARE — files encrypted (.locked)
 Strain: identified · known variant

$ cdr engineer-working
 Read-only image: taken · source preserved
 Shadow copies: located + extracted
 Decryptor: applied · known flaw

$ cdr verify
 ✓ databases — restored
 ✓ documents — 142,800 files
 ✓ data recovered — attacker unpaid
// the first day

What you do now shapes everything after.

01 / ISOLATE, DO NOT WIPE

Pull the network, leave the disks

Disconnect affected machines from the network and from each other. Do not reimage anything yet — those disks hold both the evidence and a good deal of what is recoverable.

02 / DO NOT PAY YET

It is rarely the fastest route

Payment funds the operation, carries no guarantee, and frequently produces a decryptor that works partially or not at all. Establish what can be recovered without it first.

03 / REPORT IT

Action Fraud, and the ICO if personal data

Where personal data is affected, UK GDPR requires notification to the ICO within 72 hours of becoming aware. That clock starts now, not when the recovery finishes.

04 / CHECK THE BACKUPS

Before assuming they are gone

Modern strains target backups deliberately, but offline, immutable and cloud-versioned copies frequently survive. Check before concluding you have nothing.

// nobody decrypts current strains

And anybody saying otherwise is not being straight.

Worth stating plainly, because the alternative claim is widespread and expensive.

Modern ransomware uses standard public-key cryptography — typically AES for the files with the AES key itself encrypted by RSA. The private key never leaves the operator. There is no flaw to exploit and no computation that shortens it.

Several firms advertise ransomware decryption as a service. In practice a number of them negotiate and pay the ransom on your behalf, marking it up, without telling you that is what happened. You are then paying a premium for something you could have done directly, and funding the operation regardless.

The honest exception is older or badly implemented strains where researchers have published working decryptors, and the No More Ransom project catalogues those. It is worth checking whether yours is on that list. If it is not, no laboratory is going to decrypt it.

// what does come back

Everything the encryption run failed to reach.

Ransomware is a race against detection, and that race leaves a great deal behind. Encryption runs are frequently interrupted part-way. Shadow copies are targeted but not always successfully cleared. Many strains encrypt only the first portion of large files to save time, leaving the remainder readable.

More usefully, the original files are often still physically present. A strain that writes an encrypted copy and deletes the original has left that original in free space exactly as any deletion would, and on mechanical storage it can frequently be carved back out.

So the work is not decryption. It is finding the intact copies, the partially encrypted files, the untouched volumes and the machines the run never reached before somebody pulled the plug. On a typical incident that recovers a substantial proportion of what matters.

Do not reimage the affected machines. The instinct is to wipe and rebuild to get back to work. Those disks hold the unencrypted originals in free space, and reimaging destroys them permanently. Take images first, rebuild afterwards.

// pricing

From £500, quoted after diagnostic.

Ransomware work starts at £500 +VAT and is quoted individually after the free diagnostic, because the scale varies enormously between a single machine and an estate.

We do not negotiate with operators, do not act as an intermediary and do not handle payment. If that is the route you choose, it is one you take directly rather than through us.

// questions

Ransomware, answered.

That is your decision and we will not make it for you, but establish what is recoverable without paying first. Payment carries no guarantee, funds the operation, and the decryptors supplied frequently work partially at best.

Not on current strains, and nor can anyone. What we recover is everything the encryption run missed — shadow copies, originals in free space, partially encrypted files and untouched volumes. That is frequently substantial.

Common, because modern strains target them deliberately. Check for offline copies, immutable cloud snapshots and version history before concluding. Those survive more often than network shares do.

If personal data is affected, UK GDPR requires notification within 72 hours of becoming aware. That is a legal obligation independent of whether the data is recovered, and the clock has already started.

Yes. A written technical account of what was found, what was affected and what was recovered comes as standard on these jobs, in a form insurers and regulators accept.

Ten to twenty working days for an estate, less for a single machine. Every affected disk is imaged before analysis, and on a multi-machine incident that imaging dominates the schedule.

// hit by ransomware?

Before you pay anyone, let us tell you what’s actually recoverable.

We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.