Files encrypted by an attacker, a threatening demand for payment via cryptocurrency, a countdown timer... Ransomware is designed to create panic. And panic is precisely the emotion that attackers rely upon. Panic causes hasty decision-making. Therefore, methodical decision making should be employed when dealing with ransomware: Isolate whatever portion of the system was infected. Do not pay anyone anything. Let a structured process assess which elements may be recovered without providing resources to fund the next potential attack. We operate our own UK-based lab utilising that methodology for both personal residences and business operations throughout Yorkshire.
Disconnect infected computers from your local area network (LAN) and the internet, because once ransomware infects one computer or device that is connected to other shares, drives or networked devices on your LAN, it will spread to anything else that it has access to. Network attached storage (NAS) devices make ideal ransomware targets since they provide easy access to large amounts of data. When recovering data from an infected machine, do not remove, “clean” or reinstall programs, because in addition to the actual encrypted files themselves being important for recovery purposes, so too are the ransomware’s note and the actual malicious software used by the attackers. Removing them would essentially eliminate most or all of the necessary forensic information needed to recover your files. Do not pay ransom demands: paying a ransom demand does nothing but fund the cybercrime economy, mark you as a willing victim (and therefore increase your chances of future attacks), and also make it much less likely that the ransomware operators will even deliver a functioning decryptor. Report it to Police Yorkshire on 101 and the National Cyber Security Centre (NCSC); the NCSC takes these reports very seriously. Then get the affected media to us, powered off, for assessment.
Ransomware data recovery begins the same as all other recovery scenarios: no actions are taken on the source media. All drives that were hit are then read-only imaged in sector-by-sector format; each attempt (including all decryption attempts, carving, rebuilding, etc.) occurs on an image. The need for this process is much greater here than most other processes due to some of these ransomware types “booby-trapping” their own messes: a single incorrect action on a live disk can turn what could have been recovered files into lost files.
Then we determine what strain it is. The ransom note, file extensions, and a handful of sample encrypted files will usually tell us exactly which family we’re dealing with, and that decides the whole plan, because what works against one family is useless against another. Once we know which family (strain), and hold safe images of everything, we can start working to restore your system.
The majority of attacked files do not come back from one source; in many cases, a restored system will be comprised of recovered data from multiple sources. First, we attempt using free decryption tools provided by organisations that have broken your specific strain (such as law enforcement or researchers, through efforts like the No More Ransom project), which occurs with greater frequency than the hackers care for you to know. Next is what the encryption missed: files that were being worked on when the encryption was initiated, files that were excluded due to some interruption in process or skipped, and (most notably with larger files) many ransomware variants only encrypt the beginning section of the file for speed purposes while allowing the remainder of the file to remain accessible and able to be partially rebuilt.
Then, the shadow copies or snapshots that were made. The Windows Volume Shadow Copies can withstand sloppier strains, and the NAS snapshot versions from Synology and QNAP devices often remain intact, even if the shared folder(s) being backed up were completely encrypted. Next, the originals after deletion: most variants encrypt a copy of your file and delete the unencrypted original, and as such create a race to recover the deleted files against the passage of time; many deletions may be recoverable from a hard drive. Finally, backup archaeology: a long-lost external drive, the old archive box, the past cloud version histories we all thought would never again see the light of day. Unattractive, methodical; this is how we bring the data back to its owner without giving anything to the attacker.
Business jobs for our ransomware recovery services are where we earn our keep, as the ransom demand letter typically finds its way to that part of a business’s infrastructure it cannot afford to lose: the server, RAID array and NAS which all departments have mapped a drive to. The sequence in restoring these types of data loss is very rigid. In this process, all hardware is isolated, each individual member disk is imaged separately, the RAID is reconstructed virtually with those images, and finally, the encrypted volume is evaluated. This protects you in two ways: First, since everything the hacker left behind has been isolated, there will be no additional harm done by what was left behind. Second, since we’re not working on the original evidence, we won’t create an evidentiary nightmare while attempting to restore data.
When the company has idle machines and is losing revenue every hour, the emergency track allows us to move the project to the first position at the workbench. The terms will be the same whether we take that path or the above path: a complimentary evaluation of your item(s), a fixed written quote prior to doing anything with your money, and honesty about how much can be recovered (not a sales pitch), based upon our experience and knowledge.
Two lines are never crossed. No payments are made to an attacker (directly or indirectly) by us, on your behalf or otherwise, and we never negotiate with one. Payments fund the next campaign, mark you as a payer, and deliver a working decryption much less reliably than the note claims. And we do not promise decryption will work for every ransomware strain. Any outfit claiming they can break “any” modern properly implemented encryption is either making a guess or secretly paying the crooks to provide a decryptor and then billing you for their efforts. Instead, what we promise is the truth: identify the strain, find the real decryptors available if there are any, and recover all that was not destroyed by the attack, which is often a great deal.
We’re very strong in our opinion that you shouldn’t pay. Paying the ransom has a history of failure to work as expected. Broken decryptors, partial keys and repeated attacks for money have been reported. It will fund the next cyberattack and may result in legal issues with regard to the individual or group responsible for the strain. There is typically more recovered by letting an assessment determine what recovery occurs without paying than your panic suggests.
The assessment is free, and all figures are fixed and documented in a written agreement prior to any paid work. For single encrypted drive devices, we charge the same as our basic £300 + VAT band. We quote each individual job on multi-disk servers, RAID arrays and NAS units at £500 + VAT or more, because every member disk requires imaging individually. There is no hourly metered time and there is also no fee based on a percentage of your data.
No, and no one with integrity will ever claim to. Where researchers have been able to break a strain of encryption, there is an existing working decryption tool which we use. Where they have been unable to break an individual strain, properly applied encryption methods cannot be brute forced. Therefore, all that remains are those items that the attack failed to identify (shadow copies, snapshots, original deleted files, partially encrypted files and backups). This multi-layered process typically recovers much more than many would think possible.
Yes. Once you have a quote, drop your drives to us at our Leeds office on Albion Street; no appointment necessary. Alternatively, if you are elsewhere in the UK, please send your powered-down drives via an insured postal service, ideally with a photo of the ransom demand. All our work is carried out in-house by our own staff and all of your data remains within the United Kingdom.
Often, yes, and we have so much more to work with from a NAS: what the strain was unable to remove (snapshots), and the original files that were removed and stored in the free space of the volume. Turn it off, hold back your desire to do a factory reset, and send the labelled drives to us if you can take them out, or otherwise the entire NAS unit. Now we see NAS-specific strains regularly as part of our work.
Yes. The first thing we do for all jobs is identify everything possible about your case by reviewing the information contained in the note(s), extensions and samples. We then check this against the currently available decryptors. If a decryptor is found, we will utilise it as a means of recovering files in addition to the other methods we would have applied. If no decryptor exists, the other strata of file recovery are still applicable. In either case, you will be aware if decryption is possible or not prior to spending anything.