Overnight, every document grew a strange extension and a payment demand appeared in every folder. The attackers say their decryptor is the only road back; the drives usually say otherwise. Encrypted PCs, servers and NAS boxes from Swansea are examined here for every lawful route back to the data — and paying the ransom is never one of them.
Free diagnostic on every ransomware job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every ransomware job starts by matching the symptoms to the fault — these fifteen cover almost everything that reaches the bench.
Every user folder locked in a single overnight run — the single-machine attack that fills the intake shelf.
Internet-exposed Synology and QNAP boxes are prime targets; the snapshots beneath often survive the sweep.
Hypervisor strains lock every VMDK in the datastore, downing an entire virtual estate in one pass.
Speed-tuned strains hit only the leading blocks of large databases and archives — the remainder is frequently usable.
vssadmin runs before the encryption does; the deleted restore points sometimes carve back from free space.
The attached USB 'backup' was reachable, so it was encrypted with everything else — earlier versions and remnants still count.
Data stolen before it was locked, publication threatened — we scope what left the network for insurers and the ICO.
A ransom screen where Windows should be — the drive comes out, images, and is examined beneath the lock.
SQL and Exchange stores finish part-cipher, part-plain — rescued page by page out of the image.
A NAS that re-encrypts everything you restore is still compromised — isolation first, recovery from images only.
Unfamiliar extensions and notes are fingerprinted against strain databases for the family and any published flaw.
Scareware sometimes plants notes over intact files, or the run crashed early — a quick bench check settles it.
The current heavyweights of the business attack — aggressive deletion passes that are still rarely complete.
Rides in with cracked software downloads; older offline-key variants have free decryptors we apply lawfully.
Strains that encrypt a duplicate and delete the source leave the original carvable in free space.
A ransomware run walks the disk encrypting file after file with standard, strong cryptography — AES on the contents, with those AES keys wrapped inside a second, asymmetric layer whose private half never leaves the attacker. The weird extension is the strain's badge; the note is stamped out when the run completes. Capable families also purge Volume Shadow Copies, hunt down attached backups and sweep every share the account could reach — which is why the note reads so confidently. What it omits is everything the run missed, and there is almost always something.
Nobody brute-forces properly implemented encryption — any lab claiming to is lying to you. Honest recovery mines the attack's failures instead: shadow copies and NAS snapshots the deletion pass skipped, backups beyond the malware's reach, originals deleted-not-encrypted where the strain worked on a copy, unencrypted temp files and fragments carved from free space, damaged RAID and NAS structures rebuilt to expose the untouched data beneath, and the minority of strains with published flaws where a free, lawful decryptor exists. The free diagnostic maps which of those escape routes exist in your particular case.
We never pay ransoms, never negotiate with attackers on your behalf, and won't steer you toward paying: it finances the next wave, guarantees nothing, and criminal decryptors are infamous for corrupting the very files they unlock. What we deliver instead is every technical route exhausted and a written account of exactly what came back and what didn't. If insurers and advisers ultimately take a business down the negotiation road, that call is theirs — ours is making sure the technical answer arrived first.
A ransomware case is treated as a forensic incident from minute one — isolated, imaged, documented:
Media from an attack never touches the lab network — it lives on an isolated bench where nothing can spread, call out, or pick up encrypting where it left off.
Incident drives are imaged behind write-blockers before any examination; all recovery happens on those copies while the originals stay exactly as delivered.
Unallocated space is swept for the shadow copies and NAS snapshots the malware's purge missed, and the survivors are rebuilt into usable restore points.
The note and a handful of samples identify the family; that identification is then run against the reputable public decryptor sources — No More Ransom, vendor releases — in case a lawful key exists.
Unencrypted originals, temp files and partial copies are carved from free space — the debris a fast encryption run always leaves behind.
Everything is logged as we go — strain, blast radius, and precisely what came back — producing the record that insurers, regulators and your own internal review will each ask to see.
Two positions, stated plainly and in writing: a strain with no published weakness cannot be brute-forced by us or anyone else, and no ransom is ever paid by us — nor any message carried between you and the attackers. Ransomware sits in the forensic class of work — free diagnostic first, one fixed quote, and payment upfront rather than no fix, no fee.
Before anything is posted: pull the network cables and leave the affected machines exactly as they are — no antivirus sweeps, no reinstalls, no formatting, because each pass destroys the remnants recovery feeds on. Set the ransom note aside with two or three encrypted samples for strain identification, then call 0800 689 0668 to agree what to send. All media is captured on the isolated bench, and only the copies are ever worked.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.