You arrive to find every document wearing a strange extension and a demand note in every folder, insisting the criminals' decryptor is the only exit. The drives usually disagree. Encrypted PCs, servers and NAS units from Swindon and Royal Wootton Bassett are examined here for every lawful way back — and handing money to attackers is never on the list.
Free diagnostic on every ransomware job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every ransomware job starts by matching the symptoms to the fault — these twenty cover almost everything that reaches the bench.
Every user folder locked in one overnight run — the single-machine attack that stocks the intake shelf.
Internet-exposed Synology and QNAP boxes are favourite prey; the snapshots below the shares often ride it out.
Strains aimed at hypervisors cipher the datastore VMDK by VMDK, felling a whole virtual estate at once.
Speed-tuned families cipher only each big file's first stretch — databases and archives keep a usable balance.
The malware calls vssadmin ahead of encrypting; deleted restore points can sometimes be carved back out of free space.
The USB 'backup' was plugged in, so it was reachable, so it was encrypted — earlier versions and remnants still count.
Data stolen before the locking, publication threatened — what left the network is scoped for insurers and the ICO.
A demand screen where Windows belongs — the drive comes out, is imaged, and examined below the lock.
SQL and Exchange files caught mid-write end up half-ciphered — salvage proceeds page by page from the capture.
A NAS that re-encrypts every restore is still owned — isolation first, then recovery from images only.
An extension nobody has heard of gets fingerprinted against the strain databases, hunting the family and any published weakness.
Scareware plants demands over intact files, and some runs crash early — a bench check separates fright from loss.
The current heavyweights of the corporate attack — thorough deletion passes that still miss things.
Hitchhikes on cracked downloads; where an older offline-key variant is involved, a free decryptor exists and gets applied lawfully.
Some families cipher a duplicate then delete your original — leaving that original sitting in free space for carving.
Dharma and Phobos still walk in through exposed remote desktop — the encryption follows within hours of the login.
OneDrive and Drive dutifully synced the encrypted versions over the good ones — version history and remnants are checked both ends.
VHDX files encrypted on the host drop every guest at once — partial-encryption quirks often leave the guests rebuildable.
Nothing locked, everything copied, extortion by threat of leak — forensic scoping takes over from recovery.
The one disk connected on attack night was the one hit — the off-rotation sets and carved remnants close the gap.
The malware walked your storage encrypting file after file with entirely standard cryptography — AES over the contents, the AES keys sealed in turn under an asymmetric key whose private half stays with the attacker. The odd extension is the strain's signature; the note prints once the run completes. Serious families also hunt shadow copies, reachable backups and every share the compromised account could touch, which is why the demand reads so smugly. What it never admits is what the run missed — and something almost always was.
No lab anywhere brute-forces properly built encryption, and any firm implying it can is selling you a story. Honest work mines the attack's imperfections: snapshots and shadow copies the purge overlooked, backups out of the malware's reach, originals that were deleted rather than encrypted when the strain worked on a copy, temp files and fragments retrieved from slack and free space, broken NAS or RAID structures rebuilt until clean data shows through, and the handful of families whose published flaws allow a free decryptor to be applied lawfully. Your free assessment maps which of those exits exist in your specific case.
We never pay ransoms, never carry messages to attackers, and never nudge a client toward paying — it bankrolls the next campaign, guarantees nothing, and criminal decryptors have a habit of wrecking the files they claim to release. What you get from us: each technical route exhausted, plus a written record of what came home and what stayed lost. Should insurers and advisers later push a company toward negotiating, that call belongs to them — ours was making certain the technical answer came first.
A ransomware case is run as a forensic incident from the first minute — isolated, imaged, documented:
Media from an incident stays off the lab network entirely, worked on an isolated bench where nothing spreads, phones home, or resumes its encryption run.
Incident drives are captured behind write-blockers before any examination; recovery happens on the copies while originals stay sealed.
Free space gets combed for surviving shadow copies and for NAS snapshot data the purge ran past; what turns up is rebuilt into usable restore points.
The note and a few samples identify the family, which is then checked against reputable public decryptor sources — No More Ransom and vendor releases — for any lawful key.
Unencrypted originals, temp files and partial copies carved out of free space — the litter every fast encryption run leaves behind.
Strain, blast radius and results logged throughout — the paperwork insurers, regulators and your own post-mortem will each come asking for.
Two commitments in writing before any work: no lab on earth brute-forces a strain lacking a published weakness — ours included — and no ransom is ever paid or relayed through us. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.
Before anything gets posted: disconnect network leads and let the affected machines stand untouched — no antivirus sweeps, no reinstalling, no formatting, since each pass grinds away the remnants that recovery feeds on. Save the demand note plus a couple of encrypted sample files for identifying the strain, then phone 0800 689 0668 to agree what should travel. Capture happens on the isolated bench; recovery only ever touches the copies.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.