Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / ransomware
Specialist recovery · ransomware

Ransomware recovery, without the decryption promises.

Modern ransomware cannot be decrypted by anyone but the attacker — so the useful question is what survived. Shadow copies, unencrypted originals still sitting in free space, files the run never reached, and backups it could not reach. We assess exactly what is recoverable, free, before you decide anything about paying.

From £300 + VAT
Strain identified first
Discreet & confidential
~ ransomjob-001 — live RECOVERED
$ bdr triage /dev/sdb
 Device: Dell PowerEdge (RAID 5)
 Status: RANSOMWARE — files encrypted (.locked)
 Strain: identified · known variant

$ bdr engineer-working
 Read-only image: taken · source preserved
 Shadow copies: located + extracted
 Decryptor: applied · known flaw

$ bdr verify
 ✓ databases — restored
 ✓ documents — 142,800 files
 ✓ data recovered — attacker unpaid
!

Don’t pay yet, and don’t rebuild the machine.

Isolate the affected systems from the network but leave them powered if they are already running — shadow copies and material held only in memory can be lost on reboot. Don’t reformat, don’t reinstall, and keep the encrypted files themselves; they are sometimes needed later, and they cost nothing to retain.

// what you are dealing with

What modern ransomware actually does.

It is no longer a matter of a few scrambled documents. Current families move laterally, hunt backups deliberately, and take copies before encrypting anything — which changes what recovery means.

// the honest position

Why we don’t sell decryption.

It matters that this is said plainly, because a good deal of the industry is vague about it.

For current, properly implemented ransomware families, the encryption is sound and the keys are held by the attacker. Nobody decrypts those — not us, not a specialist firm, not law enforcement. Any company implying otherwise is either describing old strains with known flaws, or selling you a ransom payment with a service charge attached.

Where a genuine free decryptor exists, it is usually published through the No More Ransom project, and it applies to a specific family with a specific implementation error. We check for that first because it costs nothing. When one applies, excellent. When one does not, the honest answer is that decryption is off the table and recovery means working around the encryption instead.

// what actually works

Recovering around the attack.

In practice, most of what comes back after ransomware was never successfully encrypted in the first place.

01

Volume shadow copies

Ransomware tries to delete them, and frequently fails to remove every one — particularly on servers with generous shadow storage, or where deletion ran with insufficient privilege.

02

Unencrypted originals in free space

Many families encrypt to a new file and delete the original rather than overwriting in place. Those originals often remain in unallocated space and can be carved out intact.

03

Files the run never reached

Attacks get interrupted, hit permission errors, skip file types, or are stopped partway. Whole directories are commonly untouched.

04

Backups that survived

Offline copies, immutable snapshots, cloud versioning and NAS snapshots that were not reachable from the infected network.

05

Machines encrypted but not exfiltrated

Establishing what did and did not leave matters for your notification obligations, and the artefacts that answer it are often still on the system.

// preserving your position

Evidence, insurers and the ICO.

A ransomware incident is rarely only a technical event, and the technical response can damage the other parts.

Insurers generally require the affected systems preserved rather than rebuilt, and a rebuild before assessment can compromise a claim. Where personal data may have been taken, UK GDPR obliges you to assess and potentially notify the ICO within 72 hours — and answering the question of what left the network depends on logs and artefacts that a reinstall destroys.

So we image affected systems read-only before doing anything else. That preserves the evidential position, keeps the encrypted files available in case a decryptor is published later, and means every recovery attempt runs against a copy. It costs nothing extra and it protects options you may not yet know you need.

// pricing

Fixed pricing, quoted before work.

Assessed free, priced in writing, and you decide with the numbers in front of you.

Ransomware work on servers, NAS units and RAID systems starts from £500 +VAT; a single affected workstation or drive is from £300 +VAT. The free 48-hour assessment establishes the strain, what shadow copies and unencrypted material survive, and what is realistically recoverable — before you commit to anything.

We do not handle ransom negotiation or payment, and we do not take a percentage of anything. Where the assessment finds little to recover, we tell you that instead of billing you to discover it. Full write-ups: Ransomware Recovery: LockBit, and No Backup.

// getting it to us

Two easy steps.

Send the device in for its free diagnostic and tell us briefly what happened; an engineer reviews it and confirms your exact quote in writing before anything starts.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toOxford Data Recovery
John Eccles House, Oxford Science Park
Oxford OX2
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01865 593000.

Thanks — your message is in.

We’ll be in touch shortly. If it’s urgent, call 01865 593000.

// questions

Ransomware recovery — your questions.

What people most often ask us after a ransomware attack.

Not for current families. The encryption is properly implemented and the keys sit with the attacker, so nobody decrypts them — us included. Older strains with implementation flaws sometimes have free decryptors published through No More Ransom, and we check for that first because it costs nothing.

Isolate affected machines from the network but leave them powered if they are already on, because shadow copies and memory-resident material can be lost on reboot. Don’t reformat or reinstall, and keep the encrypted files — they may be useful later.

That is your decision and we take no part in it, but two things are worth knowing: payment buys a decryptor, not deletion of anything already stolen, and recovery around the attack frequently returns most of what matters without paying. Assess what is recoverable before deciding.

Usually more than people expect — surviving shadow copies, unencrypted originals still present in free space, files the attack never reached, and any backup or snapshot outside the infected network. The assessment tells you which of those apply to your case.

If personal data may have been accessed or taken, UK GDPR requires you to assess and potentially notify the ICO within 72 hours. Establishing what left the network relies on logs and artefacts that a rebuild destroys, which is one reason to image systems before restoring.

From £500 plus VAT for servers, NAS and RAID systems, and from £300 plus VAT for a single workstation or drive — quoted in writing after a free 48-hour assessment. We don’t handle ransom payment and don’t take a percentage.

// hit by ransomware?

Before you pay anyone, let us tell you what’s actually recoverable.

We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.