Encrypted files, a note demanding cryptocurrency, a countdown clock — ransomware is engineered panic, and panic is exactly what the attacker is counting on. The answer is method, not haste: isolate what’s infected, pay nobody, and let a systematic recovery establish what can come back without funding the next attack. Our own bench runs that method for homes and businesses across Yorkshire.
$ ldr mount /dev/md0 → Device: HP RAID 10 (4 × SAS) → Status: RANSOMWARE — volume encrypted → Client: confidential · York $ ldr array-rebuild → Array: isolated from network → Members: forensically imaged → Decryption: known strain · unlocked $ ldr verify → ✓ business_data — 98% restored → ✓ ransom — £0 paid → ✓ operations — resumed
Disconnect infected machines from network and internet — ransomware spreads to every share and drive it can reach, and NAS boxes are prime targets. Don’t wipe, don’t ‘clean up’, don’t reinstall — the encrypted files, the note and the malware itself are all evidence the recovery needs. Don’t pay: payment funds the industry, marks you as a payer, and returns working decryption far less reliably than the note promises. Report it — Police Yorkshire on 101 and the NCSC take these seriously — then get the affected media to the bench, powered off, for assessment.
Proper ransomware data recovery starts the same way every serious recovery starts: nothing is attempted on the original media. Each affected drive is imaged read-only, sector by sector, and every experiment — every decryptor trial, every carve, every rebuild — runs against the copy. That matters more here than almost anywhere else, because some strains booby-trap their own mess: a wrong move on the live disk can turn recoverable files into genuinely lost ones.
Then the strain is identified. The ransom note, the renamed file extensions and a handful of encrypted samples usually tell us exactly what we’re dealing with, and that identification decides the whole plan — because what works against one family is useless against another. Only once we know the strain, and hold safe images of everything, does recovery begin.
Files rarely come back from a single source after an attack — a good result is usually assembled from several. Free decryptors come first: where researchers or law enforcement have broken a strain, working decryption tools exist through efforts like the No More Ransom project, and that happens far more often than the attackers would like you to know. What the encryption missed comes next: interrupted runs, skipped folders, files that were open at the time, and — on large files — strains that encrypt only the first portion of each file to save time, leaving the rest intact and partially rebuildable.
Then shadow copies and snapshots. Windows Volume Shadow Copies survive sloppier strains, and NAS snapshots on Synology and QNAP boxes are often untouched even when the shared folders are fully encrypted. Then deleted originals: most variants encrypt a copy of your file and delete the original, which quietly turns part of the job into deleted-file recovery against a hostile clock — on a hard drive, those originals are frequently still recoverable. And finally backup archaeology: the old external drive, the half-forgotten archive, the cloud version history everyone had written off. Unglamorous, methodical — and it is how data comes home without a penny reaching the attacker.
Business jobs are where our ransomware recovery services earn their keep, because the note usually lands on the systems a company can least afford to lose: the server, the RAID array, the NAS every department maps a drive to. The sequence there is strict. The hardware is isolated, every member disk is imaged individually, and the array is rebuilt virtually from the images — only then is the encrypted volume assessed. That order protects you twice: nothing the attacker left behind can do further damage, and nothing we do can make the original evidence worse.
Where the business is down and every hour costs money, the emergency track moves the job to the front of the bench. Either way the terms don’t change: a free assessment, a fixed written quote before any paid work, and honest odds — not a sales pitch — on what can realistically come back.
Two lines we don’t cross. We never pay or negotiate with attackers, on your behalf or otherwise — payment funds the next campaign, marks you as a payer, and delivers working decryption far less reliably than the note claims. And we never promise universal decryption. Properly implemented modern encryption cannot be broken without the key; any outfit guaranteeing decryption of “any ransomware” is either guessing or quietly paying the criminals and billing you for it. What we promise instead is the honest version: identify the strain, use a real decryptor where one exists, and recover everything the attack failed to destroy — which, in practice, is often a great deal.
Our advice is firm: don’t. Payment is unreliable — broken decryptors, partial keys and repeat extortion are all common — it funds the next attack, and it can raise legal issues depending who's behind the strain. Let assessment establish what recovers without paying — frequently more than the panic suggests.
The assessment is free and the figure is fixed in writing before any paid work. Single encrypted drives follow our standard band of £300 + VAT; multi-disk servers, RAID arrays and NAS units are quoted to the job from £500 + VAT, because every member disk is imaged individually first. No hourly meter, and no percentage-of-your-data pricing.
No — and nobody honest can. Where researchers have broken a strain, a working decryptor exists and we use it. Where they haven’t, properly implemented encryption cannot be brute-forced, so recovery comes from everything the attack missed: shadow copies, snapshots, deleted originals, partially encrypted files and backups. That layered route recovers far more than most people expect.
Yes. Drop the affected drives at our Leeds address on Albion Street, or send them by insured post from anywhere in the UK — powered off, and ideally with a photo of the ransom note. All work is done in-house by our own engineers and your data never leaves the UK.
Often, yes — and a NAS actually gives us more to work with: snapshots the strain failed to purge, and deleted originals sitting in the free space on the volumes. Power it down, resist the urge to factory-reset it, and send the labelled disks. NAS-targeted strains are a bench staple now.
Yes — identification from the note, extensions and samples is step one, checked against current decryptor availability. When a decryptor exists we use it as part of the job; when it doesn't, the other recovery strata still apply. Either way you know before spending.