Home / Devices / Ransomware

Ransomware Data Recovery Leicester

Every document renamed with an extension nobody recognises, and a note in each folder demanding payment. The hardware is fine. What has changed is that the contents have been through a cipher whose key sits with somebody else. This is ordinary media recovery on healthy equipment and it is priced as such, at £300 + VAT a drive and from £500 + VAT an array. It is not forensic work, it is never quoted at the forensic figure, and it is not on the no fix, no fee exclusion list either.

Every ransomware that arrives here is examined at no charge. The figure quoted afterwards is put in writing and settled before anybody reaches for a screwdriver: £300 + VAT where one disk was hit, and from £500 + VAT where an array was.

Logical recoveries carry no fix, no fee. The named exceptions to it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs; physical work takes 50% up front. The five bands are set out in full on the data recovery cost page.

// thirty faults, roughly in order of how often they arrive

Thirty ways it goes wrong, and what sits behind each

Tracing a symptom back to the failure underneath it is where the real work begins, and these thirty account for all but a handful of the boxes opened at the Cambridge bench. A fault missing from the list is not an unfamiliar one — describe it on the telephone and you will get a straight view of the odds before you spend anything on postage.

Every document renamed with an extension nobody recognises

The first thing most people see. Files are still exactly where they were, the same size or nearly, with a suffix appended and a note left in every folder. The hardware is fine. What has changed is that the contents have been through a cipher whose key sits with somebody else.

A note in every folder demanding payment

Read it, photograph it, and keep it, because the note identifies the variant and the variant decides what is possible. Do not act on it. Establishing which family you are dealing with is the first useful step and it is part of the free assessment.

Shadow copies deleted along with everything else

Most families delete Windows shadow copies as their first act, precisely because that is the easiest route back. Deleting them is not the same as overwriting them, and the remains of shadow copies are frequently recoverable from unallocated space where the machine has been left alone since.

A backup drive that was plugged in at the time

An external drive attached when the attack ran gets encrypted along with everything else, which is exactly why a permanently connected drive is not a backup. It is recovered on the same terms as the machine, 300 pounds + VAT for a single drive, and it is not forensic work.

A NAS reached over the network

Shares mounted on an infected machine are encrypted like any other folder, and boxes exposed directly to the internet get attacked in their own right. Snapshots sometimes survive because the attacker lacked the rights to remove them. An array is priced from 500 pounds + VAT.

A server encrypted and the business off the air

Say so on the call, because that moves the job to the front of the list. The realistic timings do not change: the free assessment closes two working days after the disks are booked in and work runs from there. Anybody promising a server back by tomorrow is guessing at your expense.

Virtual machines encrypted at the datastore

Where the attacker reached the hypervisor rather than the guests, whole virtual disks are encrypted as single large files. That sometimes helps, because a partially encrypted large file may still contain readable regions, and the virtual disk can be repaired around them.

Files that were only partly encrypted

Many families encrypt the first portion of each file and leave the rest, for speed. On large files, databases and video especially, that leaves a great deal of usable material behind the encrypted header. Reconstructing those files is one of the more productive routes here.

A machine that was still running when it was found

Switch it off. Encryption that is still in progress is still consuming files, and every additional minute is more material gone. There is no advantage in leaving it up, and the argument about preserving volatile evidence only applies where a separate forensic engagement is planned.

An attack that ran weeks ago and was noticed today

Some families sit quietly and encrypt gradually, or wait until backups have rotated. A long gap between the attack and the discovery makes the position harder because backups have cycled through and the machine has been used. It does not make it hopeless.

The decryptor was bought and it does not work

It happens regularly. Payment buys a promise rather than a tool that works, and several families ship decryptors that corrupt what they touch. If a decryptor has been run, say so and stop, because what it has done to the files affects what can be recovered from them.

A publicly available decryptor for that variant

For a number of older families, keys have been published or the encryption was implemented badly enough to be defeated. That is checked first, every time, and where it applies the job becomes short and inexpensive. It is not the common case and it is worth ruling in.

Files deleted rather than encrypted

Some attacks copy files, encrypt the copy and delete the original, which is a very different situation from encrypting in place. Deleted originals are recoverable by ordinary means where nothing has overwritten them, and this distinction is one of the first things established.

Backups that were encrypted too

Backup software that keeps its archives on a mounted volume loses them along with everything else. Where backups live on media that was disconnected, they survive. That is the whole argument for offline copies and it is usually learned on this page rather than before it.

A database that will not open after the attack

Database files are held open and written to constantly, and an attack partway through leaves a file that is neither complete nor entirely encrypted. Transaction logs and older consistent copies in unallocated space are both worth pursuing, and both frequently succeed.

A machine that was reinstalled to get it working again

Wiping and rebuilding a machine to get the business moving is understandable and it removes the evidence and much of the recoverable material at the same time. Where the original disk still exists, do not reuse it. Where it has been reused, the position depends on how long for.

Antivirus that removed the payload and left the files

Cleaning the infection does not decrypt anything, and in some cases it removes a component that held key material in memory. Where the machine has been cleaned, say so, because it changes what can be looked for.

An attack that arrived through remote desktop

Exposed remote access is the commonest route in for the families that target small businesses. Knowing how it happened matters for putting things back safely, and establishing it properly is a separate forensic engagement at 800 pounds + VAT rather than part of the recovery.

Every machine in the office affected at once

Domain-wide attacks encrypt everything reachable from one compromised account, which usually means every server and every workstation. All of it is quoted from the hardware: 300 pounds + VAT for a single drive and from 500 pounds + VAT for an array, however many machines are involved.

A cloud sync folder that propagated the encryption

Files encrypted locally sync to the service and overwrite the good copies there. Most services keep version history, and restoring from it is frequently quicker and cheaper than anything done here. That gets checked before anybody pays for a recovery.

An attack on a machine that was already failing

Two problems at once. The disk is imaged first, exactly as any failing disk would be, and the encrypted material is dealt with on the copy. The physical part of that is charged as physical work and takes 50% up front, because mechanical failure is an exclusion and ransomware is not.

Files that were exfiltrated as well as encrypted

Modern attacks copy data out before locking it, and the threat to publish is separate from the threat to withhold. Establishing what left the building is forensic work, priced at 800 pounds + VAT with a report, and it is a different engagement from getting the files back.

An insurer asking what happened before they pay

Claims frequently require an independent account of the incident. That is forensic work and it is quoted separately. Getting the files back is recovery and it is priced as ordinary media. The two are not the same service and should not appear on the same invoice as one.

A home machine with family photographs on it

The same problem at a smaller scale, and it gets the same answer. A single drive is 300 pounds + VAT, the assessment is free, and what is possible depends on the variant and on what has happened since. There is no cheaper category and there is no more expensive one either.

A drive that was formatted after the attack

Formatting removes the file system and leaves most of the content in place, encrypted or otherwise. Where files were deleted rather than encrypted in place, a format on top makes the job harder rather than impossible. Stop using the disk from that point.

Someone offering to decrypt anything for a fee

There is a trade in firms who take payment, pay the ransom quietly and present the result as their own technical work. That should be known about rather than discovered. Where a variant cannot be defeated, that is said here plainly, and the assessment costs nothing either way.

A partially completed attack that was interrupted

Where the machine was switched off or lost power midway, a proportion of the files were never touched. Identifying which is quick and it frequently returns a substantial part of the data without any further work at all.

Temporary files and application caches that escaped

Working copies, autosaves, print spools, thumbnails and application caches often sit in locations the attack did not reach. They rarely amount to everything, and on a document-heavy machine they amount to a great deal more than people expect.

An old backup that is better than nothing

Where a disconnected backup exists but is out of date, the sensible job is often to recover what changed since rather than everything. That is a smaller piece of work and it gets said honestly rather than expanded into a full recovery nobody needs.

Nothing recoverable, and the answer given straight

Where a modern family has done its work properly, the key sits with the attacker and no laboratory in the world opens it. Where that is the position you are told during the free assessment, at no charge, rather than after money has changed hands.

The first hour, and what to do in it

Switch the machine off, at the wall if that is quicker. An attack still running is still consuming files, and there is no advantage in leaving it up. Then photograph the ransom note and keep it, because the note, the extension and the structure of an encrypted file together identify the family, and the family decides what is possible. Keep one encrypted file and, if you have one, a copy of the same file from before, since a matched pair tells a great deal in a few minutes. After that, the list of things not to do is short and it matters. Do not reinstall or format, because that removes both the evidence and much of the recoverable material. Do not run a decryptor bought from anyone, since several families ship tools that corrupt what they touch and payment buys a promise rather than a working program. Do not let a cleanup utility loose on the disk. If a drive was plugged in when it ran, that drive is affected too and it goes in the same consignment. If a NAS or a server is involved, power those down as well and send the members labelled.

What actually comes back, and by which routes

Nothing here attacks the cipher, because a correctly implemented one does not yield to effort. What works instead is finding the material the attack missed and rebuilding what it only partly touched. Published keys exist for a number of older families where the encryption was implemented badly or the keys were seized, and that is checked first every time because it makes the job short and inexpensive. Shadow copies and snapshots are next: most families delete them as their first act, and deleting is not the same as overwriting, so the remains are frequently recoverable from free space where the machine has been left alone. Where the attack copied a file, encrypted the copy and deleted the original, the originals come back by ordinary means. Many families encrypt only the first portion of each file for speed, which leaves large documents, databases, archives and video substantially readable behind an encrypted header. And caches, autosaves, temporary files and print spools regularly sit in locations the attack never reached. Where a modern family has done its work properly, the key is with the attacker and no laboratory in the world opens it, and you are told that during the free assessment at no charge.

The price, and why it is not the forensic one

This is priced from the hardware in front of us like any other media job. A single drive out of a workstation is £300 + VAT. An array, a NAS or a server is from £500 + VAT, rising with the member count, and that figure covers reassembling the volume before anything else can be attempted. The free assessment closes two working days after the device is booked in and establishes the variant, whether snapshots or deleted originals survived, and whether a genuine route back exists. Ransomware is also not on the no fix, no fee exclusion list: the published exclusions are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, and an encrypted-file recovery on healthy hardware is none of those. Where an organisation additionally needs to establish how the attackers got in and what left the building before the encryption ran, that is a separate forensic engagement at £800 + VAT with a written report, and it should appear as a second line rather than be folded into the first. If the business has stopped trading, say so on the call and the job moves to the front of the list.

// what stands on the bench

The equipment involved, and why any of it matters

Nothing on this bench attacks a cipher, because a correctly implemented one does not yield to effort. What it does instead is find the material the attack missed, rebuild the files it only partly touched, and identify the variants where a genuine route back exists.

Variant identification from the note and the samples

The note, the extension and the structure of an encrypted file together identify the family, and the family decides what is possible. Where keys have been published or an implementation was weak, that is established in the first hours rather than the first week.

Shadow copy and snapshot recovery

Deleted shadow copies, NAS snapshots and file system snapshots recovered from unallocated space where the machine has been left alone. Deleting a snapshot is not the same as overwriting it, and this route closes a good number of these jobs completely.

Partial-encryption reconstruction

Many families encrypt only the first portion of each file. Large documents, databases, archives and video are rebuilt around the encrypted header, which on a media-heavy machine recovers a substantial proportion of what was lost.

Deleted original recovery

Where the attack encrypted a copy and deleted the original, ordinary recovery applies to the originals. That is why a machine should be switched off rather than left running, and it is one of the more productive routes on this page.

Array and volume reassembly first

Encrypted NAS and RAID volumes are put back together from images of the members before anything else is attempted, because there is no point examining a set that has not been reassembled. Arrays are priced from 500 pounds + VAT.

Imaging before anything else, on write-blocked ports

Every device is imaged first and all the work happens on copies. That protects whatever is left and it keeps the original intact in case a decryptor becomes available later, which for some families it eventually has.

// badges that arrive in the post

What arrives after an attack

Windows workstations and laptopsWindows and Linux serversNAS boxes reached over the networkRAID arrays and SAN LUNsVirtual machines and datastoresExternal drives left plugged inBackup appliances and their archivesMac machines, less oftenCloud sync folders that propagated itHome machines with family photographs

Routes back, in the order they are tried

This is priced from the hardware in front of us like any other media job: 300 pounds + VAT for a single drive and from 500 pounds + VAT for an array, rising with the member count. It is not forensic work, it is never quoted at the forensic figure, and any firm presenting it as forensic should be asked why. Ransomware is also not on the no fix, no fee exclusion list. The published exclusions are electronic and mechanical failures, chip-level work, recorder jobs and forensic jobs, and an encrypted-file recovery on healthy hardware is none of those. The free assessment closes two working days after the device is booked in and it establishes the variant, whether snapshots or deleted originals survived, and whether a genuine route back exists. Where one does not, you are told at no charge. Where an organisation additionally needs to establish how the attackers got in and what left the building, that is a separate forensic engagement at 800 pounds + VAT with a written report.

// getting it ready for the post

Before you tape the box shut — take the drive out if it comes out

Switch the machine off first, at the wall if necessary, and leave it off. An attack that is still running is still consuming files, and every extra minute costs. Do not reinstall, do not format, do not run a decryptor bought from anybody, and do not let a cleanup tool loose on the disk, because each of those removes material that would otherwise have been recoverable. Photograph the ransom note and keep a copy of one encrypted file and its original name if you have one, since between them they identify the variant. Then send the drives: a single disk out of a workstation, or every member of an array labelled with its bay after the front of the chassis has been photographed. Post them tracked and insured to Cambridge Data Recovery, Compass House, Vision Park, Chivers Way, Cambridge CB24 9AD, or bring them in, since the lab is two minutes off the A14 at Junction 32 with parking outside the door and Leicester to that door is about seventy miles on the M1 south to Junction 19 and then the A14 east. Reception takes drop-offs Monday to Friday, 9:00am to 5:30pm. Nothing is collected. Ring 0800 689 0668 and say if the business has stopped trading, because that moves the job to the front of the list.

// how the media reaches Cambridge

Sending a device — and the three exceptions

The post office does most of the work of getting a job here. A drive that is already unwell travels better boxed and insured than rattling around a car for a day of errands, and something dropped into a Leicestershire postbox this afternoon is generally logged in at Cambridge tomorrow.

The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.

  • A stiff box or a well-padded mailer, with enough packing that nothing moves when you shake it. Power supplies, docks and cables can stay at home unless the drive is one of the WD units above.
  • Running a RAID or a server? Send the member disks on their own, not the chassis or the controller, and write the bay order on each one — 1, 2, 3 and so on. Photograph the front of the unit before you pull anything, because that photograph occasionally saves a day of work.
  • Fill in the shipping and booking-in form (PDF) — a name, a number you actually answer, and a line on how the trouble started — and put it in the box.
  • Special Delivery is tracked and insured and is what most people use; your own courier is equally fine. Handing it over in person also works: reception at the Cambridge address takes devices across the counter, Mon–Fri 9:00am–5:30pm. What does not exist is a Leicester counter or anyone who comes to collect.
// write this on the label

Cambridge Data Recovery

Compass House
Vision Park, Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.

Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.

// ransomware recovery questions

Common questions

£300 + VAT for a single drive and from £500 + VAT for an array, rising with the member count. It is priced as ordinary media because the hardware is healthy, and it is never quoted at the forensic figure. The assessment costs nothing and closes two working days after the device is booked in. Ransomware is not on the no fix, no fee exclusion list.
That is your decision and not one this bench makes for you, but two things are worth knowing before it. Payment buys a promise rather than a working tool, and several families ship decryptors that corrupt what they touch. There is also a trade in firms who take a fee, pay quietly, and present the result as their own technical work. The free assessment tells you whether a genuine route back exists first.
Both go in the same consignment. A drive that was plugged in when the attack ran is encrypted like anything else, which is exactly why a permanently connected drive is not a backup, and shares mounted on an infected machine are reached the same way. A NAS or an array is priced from £500 + VAT, and snapshots sometimes survive because the attacker lacked the rights to remove them.
No, and it should not be billed as such. Getting the files back is recovery on healthy hardware. Establishing how the attackers got in and what was taken out before the encryption ran is a separate forensic engagement at £800 + VAT with a written report. Both are often needed and they are two jobs, so they should appear as two lines on a quote rather than one.
Say it on the call and the job goes to the front of the list. The honest timings do not change: the free assessment takes two working days from arrival and the work runs from there. Anybody promising a server back tomorrow is guessing at your expense. Power everything down now, because an attack that is still running is still costing you files.
// the rest of the week's work

What else lands on this bench

// where to read further

Pages that take it further

Whenever you are ready, the bench is.

The examination is free, one written figure follows it, and the band covering this page is £300 + VAT where one disk was hit, and from £500 + VAT where an array was.