Modern ransomware cannot be decrypted by anyone but the attacker, so the useful question is what survived it. Shadow copies the run failed to clear, unencrypted originals still sitting in free space, files it never reached, and backups it could not touch. We establish exactly what is recoverable, free, before you decide anything about paying.
$ cdr triage /dev/sdb → Device: Dell PowerEdge (RAID 5) → Status: RANSOMWARE — files encrypted (.locked) → Strain: identified · known variant $ cdr engineer-working → Read-only image: taken · source preserved → Shadow copies: located + extracted → Decryptor: applied · known flaw $ cdr verify → ✓ databases — restored → ✓ documents — 142,800 files → ✓ data recovered — attacker unpaid
Disconnect affected machines from the network and from each other. Do not reimage anything yet — those disks hold both the evidence and a good deal of what is recoverable.
Payment funds the operation, carries no guarantee, and frequently produces a decryptor that works partially or not at all. Establish what can be recovered without it first.
Where personal data is affected, UK GDPR requires notification to the ICO within 72 hours of becoming aware. That clock starts now, not when the recovery finishes.
Modern strains target backups deliberately, but offline, immutable and cloud-versioned copies frequently survive. Check before concluding you have nothing.
Worth stating plainly, because the alternative claim is widespread and expensive.
Modern ransomware uses standard public-key cryptography — typically AES for the files with the AES key itself encrypted by RSA. The private key never leaves the operator. There is no flaw to exploit and no computation that shortens it.
Several firms advertise ransomware decryption as a service. In practice a number of them negotiate and pay the ransom on your behalf, marking it up, without telling you that is what happened. You are then paying a premium for something you could have done directly, and funding the operation regardless.
The honest exception is older or badly implemented strains where researchers have published working decryptors, and the No More Ransom project catalogues those. It is worth checking whether yours is on that list. If it is not, no laboratory is going to decrypt it.
Ransomware is a race against detection, and that race leaves a great deal behind. Encryption runs are frequently interrupted part-way. Shadow copies are targeted but not always successfully cleared. Many strains encrypt only the first portion of large files to save time, leaving the remainder readable.
More usefully, the original files are often still physically present. A strain that writes an encrypted copy and deletes the original has left that original in free space exactly as any deletion would, and on mechanical storage it can frequently be carved back out.
So the work is not decryption. It is finding the intact copies, the partially encrypted files, the untouched volumes and the machines the run never reached before somebody pulled the plug. On a typical incident that recovers a substantial proportion of what matters.
Do not reimage the affected machines. The instinct is to wipe and rebuild to get back to work. Those disks hold the unencrypted originals in free space, and reimaging destroys them permanently. Take images first, rebuild afterwards.
Ransomware work starts at £500 +VAT and is quoted individually after the free diagnostic, because the scale varies enormously between a single machine and an estate.
We do not negotiate with operators, do not act as an intermediary and do not handle payment. If that is the route you choose, it is one you take directly rather than through us.
That is your decision and we will not make it for you, but establish what is recoverable without paying first. Payment carries no guarantee, funds the operation, and the decryptors supplied frequently work partially at best.
Not on current strains, and nor can anyone. What we recover is everything the encryption run missed — shadow copies, originals in free space, partially encrypted files and untouched volumes. That is frequently substantial.
Common, because modern strains target them deliberately. Check for offline copies, immutable cloud snapshots and version history before concluding. Those survive more often than network shares do.
If personal data is affected, UK GDPR requires notification within 72 hours of becoming aware. That is a legal obligation independent of whether the data is recovered, and the clock has already started.
Yes. A written technical account of what was found, what was affected and what was recovered comes as standard on these jobs, in a form insurers and regulators accept.
Ten to twenty working days for an estate, less for a single machine. Every affected disk is imaged before analysis, and on a multi-machine incident that imaging dominates the schedule.
We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.