A LockBit infection on a single workstation holding a small business’s entire operation, with a backup drive that had been disconnected for months. The encryption was never broken — and roughly four fifths of the data was recovered regardless.
← All case files · £300 + VAT, flat
A two-person design studio had every project file, invoice and client record on one workstation. A LockBit variant encrypted the lot overnight, renamed everything, and left the usual note. The external backup drive had been unplugged since a house move.
They had been quoted for the ransom by another firm and wanted a second opinion before paying. That conversation is the reason this went as well as it did — the machine had been left powered and untouched.
a current LockBit variant with correctly implemented per-file keys sealed by the attacker’s public key. No decryptor exists and none was going to.
the ransomware had attempted to remove them, as they all do — and had failed to clear every one, which is more common than people expect.
the variant encrypted to new files and deleted the originals rather than overwriting in place, leaving a great deal recoverable by carving.
the single most useful decision the owners made.
We were explicit at the diagnostic: we would not be decrypting anything. What we would do is establish how much existed outside the encryption — and that number is knowable before anyone pays for anything.
The drive was imaged read-only first, preserving the encrypted files and the evidential state in case a decryptor were ever published or the incident needed reporting. Everything afterwards ran against the copy.
Surviving shadow copies were mounted and extracted first, returning a coherent snapshot from eleven days before the attack. Unallocated space was then carved by signature to recover deleted originals, which produced a large volume of files without names or folders. Finally the two sets were reconciled — shadow-copy versions supplied names and structure, carved versions supplied anything created since.
About 81% of the working data, including every current client project and the full invoice history. The shortfall was mostly material created in the eleven days between the last shadow copy and the attack, where no unencrypted original had survived in free space.
The studio did not pay. Worth noting the arithmetic they were considering: the ransom quote exceeded the recovery cost several times over, and would have bought a decryptor rather than any assurance about data already taken.
Modern ransomware cannot be decrypted by anyone except the attacker, and any firm suggesting otherwise is either describing an old flawed strain or selling you a ransom payment with a fee attached. What genuinely works is recovering around it — shadow copies the attack failed to clear, unencrypted originals still in free space, and anything the run never reached.
The response that preserved this one: they isolated the machine, left it powered, and did not reformat or reinstall. Ransomware work starts from £500 +VAT for servers and arrays and £300 +VAT for a single workstation, after a free assessment that tells you what is recoverable before you decide anything about paying.
Drop the drive at our Oxford Science Park reception, or post it to us — it costs nothing to find out what happened. You get a written figure from the fixed bands before any work begins.