Every document renamed with an extension nobody recognises, and a note in each folder demanding payment. The hardware is fine. What has changed is that the contents have been through a cipher whose key sits with somebody else. This is ordinary media recovery on healthy equipment and it is priced as such, at £300 + VAT a drive and from £500 + VAT an array. It is not forensic work, it is never quoted at the forensic figure, and it is not on the no fix, no fee exclusion list either.
Every ransomware that arrives here is examined at no charge. The figure quoted afterwards is put in writing and settled before anybody reaches for a screwdriver: £300 + VAT where one disk was hit, and from £500 + VAT where an array was.
Logical recoveries carry no fix, no fee. The named exceptions to it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs; physical work takes 50% up front. The five bands are set out in full on the data recovery cost page.
Tracing a symptom back to the failure underneath it is where the real work begins, and these thirty account for all but a handful of the boxes opened at the Cambridge bench. A fault missing from the list is not an unfamiliar one — describe it on the telephone and you will get a straight view of the odds before you spend anything on postage.
The first thing most people see. Files are still exactly where they were, the same size or nearly, with a suffix appended and a note left in every folder. The hardware is fine. What has changed is that the contents have been through a cipher whose key sits with somebody else.
Read it, photograph it, and keep it, because the note identifies the variant and the variant decides what is possible. Do not act on it. Establishing which family you are dealing with is the first useful step and it is part of the free assessment.
Most families delete Windows shadow copies as their first act, precisely because that is the easiest route back. Deleting them is not the same as overwriting them, and the remains of shadow copies are frequently recoverable from unallocated space where the machine has been left alone since.
An external drive attached when the attack ran gets encrypted along with everything else, which is exactly why a permanently connected drive is not a backup. It is recovered on the same terms as the machine, 300 pounds + VAT for a single drive, and it is not forensic work.
Shares mounted on an infected machine are encrypted like any other folder, and boxes exposed directly to the internet get attacked in their own right. Snapshots sometimes survive because the attacker lacked the rights to remove them. An array is priced from 500 pounds + VAT.
Say so on the call, because that moves the job to the front of the list. The realistic timings do not change: the free assessment closes two working days after the disks are booked in and work runs from there. Anybody promising a server back by tomorrow is guessing at your expense.
Where the attacker reached the hypervisor rather than the guests, whole virtual disks are encrypted as single large files. That sometimes helps, because a partially encrypted large file may still contain readable regions, and the virtual disk can be repaired around them.
Many families encrypt the first portion of each file and leave the rest, for speed. On large files, databases and video especially, that leaves a great deal of usable material behind the encrypted header. Reconstructing those files is one of the more productive routes here.
Switch it off. Encryption that is still in progress is still consuming files, and every additional minute is more material gone. There is no advantage in leaving it up, and the argument about preserving volatile evidence only applies where a separate forensic engagement is planned.
Some families sit quietly and encrypt gradually, or wait until backups have rotated. A long gap between the attack and the discovery makes the position harder because backups have cycled through and the machine has been used. It does not make it hopeless.
It happens regularly. Payment buys a promise rather than a tool that works, and several families ship decryptors that corrupt what they touch. If a decryptor has been run, say so and stop, because what it has done to the files affects what can be recovered from them.
For a number of older families, keys have been published or the encryption was implemented badly enough to be defeated. That is checked first, every time, and where it applies the job becomes short and inexpensive. It is not the common case and it is worth ruling in.
Some attacks copy files, encrypt the copy and delete the original, which is a very different situation from encrypting in place. Deleted originals are recoverable by ordinary means where nothing has overwritten them, and this distinction is one of the first things established.
Backup software that keeps its archives on a mounted volume loses them along with everything else. Where backups live on media that was disconnected, they survive. That is the whole argument for offline copies and it is usually learned on this page rather than before it.
Database files are held open and written to constantly, and an attack partway through leaves a file that is neither complete nor entirely encrypted. Transaction logs and older consistent copies in unallocated space are both worth pursuing, and both frequently succeed.
Wiping and rebuilding a machine to get the business moving is understandable and it removes the evidence and much of the recoverable material at the same time. Where the original disk still exists, do not reuse it. Where it has been reused, the position depends on how long for.
Cleaning the infection does not decrypt anything, and in some cases it removes a component that held key material in memory. Where the machine has been cleaned, say so, because it changes what can be looked for.
Exposed remote access is the commonest route in for the families that target small businesses. Knowing how it happened matters for putting things back safely, and establishing it properly is a separate forensic engagement at 800 pounds + VAT rather than part of the recovery.
Domain-wide attacks encrypt everything reachable from one compromised account, which usually means every server and every workstation. All of it is quoted from the hardware: 300 pounds + VAT for a single drive and from 500 pounds + VAT for an array, however many machines are involved.
Files encrypted locally sync to the service and overwrite the good copies there. Most services keep version history, and restoring from it is frequently quicker and cheaper than anything done here. That gets checked before anybody pays for a recovery.
Two problems at once. The disk is imaged first, exactly as any failing disk would be, and the encrypted material is dealt with on the copy. The physical part of that is charged as physical work and takes 50% up front, because mechanical failure is an exclusion and ransomware is not.
Modern attacks copy data out before locking it, and the threat to publish is separate from the threat to withhold. Establishing what left the building is forensic work, priced at 800 pounds + VAT with a report, and it is a different engagement from getting the files back.
Claims frequently require an independent account of the incident. That is forensic work and it is quoted separately. Getting the files back is recovery and it is priced as ordinary media. The two are not the same service and should not appear on the same invoice as one.
The same problem at a smaller scale, and it gets the same answer. A single drive is 300 pounds + VAT, the assessment is free, and what is possible depends on the variant and on what has happened since. There is no cheaper category and there is no more expensive one either.
Formatting removes the file system and leaves most of the content in place, encrypted or otherwise. Where files were deleted rather than encrypted in place, a format on top makes the job harder rather than impossible. Stop using the disk from that point.
There is a trade in firms who take payment, pay the ransom quietly and present the result as their own technical work. That should be known about rather than discovered. Where a variant cannot be defeated, that is said here plainly, and the assessment costs nothing either way.
Where the machine was switched off or lost power midway, a proportion of the files were never touched. Identifying which is quick and it frequently returns a substantial part of the data without any further work at all.
Working copies, autosaves, print spools, thumbnails and application caches often sit in locations the attack did not reach. They rarely amount to everything, and on a document-heavy machine they amount to a great deal more than people expect.
Where a disconnected backup exists but is out of date, the sensible job is often to recover what changed since rather than everything. That is a smaller piece of work and it gets said honestly rather than expanded into a full recovery nobody needs.
Where a modern family has done its work properly, the key sits with the attacker and no laboratory in the world opens it. Where that is the position you are told during the free assessment, at no charge, rather than after money has changed hands.
Switch the machine off, at the wall if that is quicker. An attack still running is still consuming files, and there is no advantage in leaving it up. Then photograph the ransom note and keep it, because the note, the extension and the structure of an encrypted file together identify the family, and the family decides what is possible. Keep one encrypted file and, if you have one, a copy of the same file from before, since a matched pair tells a great deal in a few minutes. After that, the list of things not to do is short and it matters. Do not reinstall or format, because that removes both the evidence and much of the recoverable material. Do not run a decryptor bought from anyone, since several families ship tools that corrupt what they touch and payment buys a promise rather than a working program. Do not let a cleanup utility loose on the disk. If a drive was plugged in when it ran, that drive is affected too and it goes in the same consignment. If a NAS or a server is involved, power those down as well and send the members labelled.
Nothing here attacks the cipher, because a correctly implemented one does not yield to effort. What works instead is finding the material the attack missed and rebuilding what it only partly touched. Published keys exist for a number of older families where the encryption was implemented badly or the keys were seized, and that is checked first every time because it makes the job short and inexpensive. Shadow copies and snapshots are next: most families delete them as their first act, and deleting is not the same as overwriting, so the remains are frequently recoverable from free space where the machine has been left alone. Where the attack copied a file, encrypted the copy and deleted the original, the originals come back by ordinary means. Many families encrypt only the first portion of each file for speed, which leaves large documents, databases, archives and video substantially readable behind an encrypted header. And caches, autosaves, temporary files and print spools regularly sit in locations the attack never reached. Where a modern family has done its work properly, the key is with the attacker and no laboratory in the world opens it, and you are told that during the free assessment at no charge.
This is priced from the hardware in front of us like any other media job. A single drive out of a workstation is £300 + VAT. An array, a NAS or a server is from £500 + VAT, rising with the member count, and that figure covers reassembling the volume before anything else can be attempted. The free assessment closes two working days after the device is booked in and establishes the variant, whether snapshots or deleted originals survived, and whether a genuine route back exists. Ransomware is also not on the no fix, no fee exclusion list: the published exclusions are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, and an encrypted-file recovery on healthy hardware is none of those. Where an organisation additionally needs to establish how the attackers got in and what left the building before the encryption ran, that is a separate forensic engagement at £800 + VAT with a written report, and it should appear as a second line rather than be folded into the first. If the business has stopped trading, say so on the call and the job moves to the front of the list.
Nothing on this bench attacks a cipher, because a correctly implemented one does not yield to effort. What it does instead is find the material the attack missed, rebuild the files it only partly touched, and identify the variants where a genuine route back exists.
The note, the extension and the structure of an encrypted file together identify the family, and the family decides what is possible. Where keys have been published or an implementation was weak, that is established in the first hours rather than the first week.
Deleted shadow copies, NAS snapshots and file system snapshots recovered from unallocated space where the machine has been left alone. Deleting a snapshot is not the same as overwriting it, and this route closes a good number of these jobs completely.
Many families encrypt only the first portion of each file. Large documents, databases, archives and video are rebuilt around the encrypted header, which on a media-heavy machine recovers a substantial proportion of what was lost.
Where the attack encrypted a copy and deleted the original, ordinary recovery applies to the originals. That is why a machine should be switched off rather than left running, and it is one of the more productive routes on this page.
Encrypted NAS and RAID volumes are put back together from images of the members before anything else is attempted, because there is no point examining a set that has not been reassembled. Arrays are priced from 500 pounds + VAT.
Every device is imaged first and all the work happens on copies. That protects whatever is left and it keeps the original intact in case a decryptor becomes available later, which for some families it eventually has.
This is priced from the hardware in front of us like any other media job: 300 pounds + VAT for a single drive and from 500 pounds + VAT for an array, rising with the member count. It is not forensic work, it is never quoted at the forensic figure, and any firm presenting it as forensic should be asked why. Ransomware is also not on the no fix, no fee exclusion list. The published exclusions are electronic and mechanical failures, chip-level work, recorder jobs and forensic jobs, and an encrypted-file recovery on healthy hardware is none of those. The free assessment closes two working days after the device is booked in and it establishes the variant, whether snapshots or deleted originals survived, and whether a genuine route back exists. Where one does not, you are told at no charge. Where an organisation additionally needs to establish how the attackers got in and what left the building, that is a separate forensic engagement at 800 pounds + VAT with a written report.
Switch the machine off first, at the wall if necessary, and leave it off. An attack that is still running is still consuming files, and every extra minute costs. Do not reinstall, do not format, do not run a decryptor bought from anybody, and do not let a cleanup tool loose on the disk, because each of those removes material that would otherwise have been recoverable. Photograph the ransom note and keep a copy of one encrypted file and its original name if you have one, since between them they identify the variant. Then send the drives: a single disk out of a workstation, or every member of an array labelled with its bay after the front of the chassis has been photographed. Post them tracked and insured to Cambridge Data Recovery, Compass House, Vision Park, Chivers Way, Cambridge CB24 9AD, or bring them in, since the lab is two minutes off the A14 at Junction 32 with parking outside the door and Leicester to that door is about seventy miles on the M1 south to Junction 19 and then the A14 east. Reception takes drop-offs Monday to Friday, 9:00am to 5:30pm. Nothing is collected. Ring 0800 689 0668 and say if the business has stopped trading, because that moves the job to the front of the list.
The post office does most of the work of getting a job here. A drive that is already unwell travels better boxed and insured than rattling around a car for a day of errands, and something dropped into a Leicestershire postbox this afternoon is generally logged in at Cambridge tomorrow.
The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.
↓ Print the shipping & booking-in form (PDF)
Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.
Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.
The examination is free, one written figure follows it, and the band covering this page is £300 + VAT where one disk was hit, and from £500 + VAT where an array was.