The bench is open for new cases · Mon–Fri, 9am–5:30pm Need it fast? Ring 0800 6890668
EDR Exeter Data Recovery 0800 6890668 Start my case
EDR / What goes wrong / Ransomware attack

How it was lost · ransomware

Ransomware recovery for Exeter. Your files back, and not a penny to them.

A ransomware attack locks every file it can reach, then goes after the safety nets — backups, restore points — before asking you to buy back your own work. We take the other road: shadow copies that survived, originals stranded in free space, snapshots, the corners these strains cut. Paying, haggling or contacting the gang — we do none of it, for anyone, Exeter included.

No result, no bill — most jobs Free diagnosis and a written quote Post it in from anywhere in Devon

Talk it over with an engineer
0800 6890668

What the symptoms are telling you.

Not there? Head for the triage →
The errorWhat it usually meansStep one
Every file now ends in .akira — or in a random string minted for your network aloneEncryption has already finished; Qilin hands a different extension to every victimPhotograph it, then pull the plug
An akira_readme.txt sitting in each folderAkira's ransom note; variants drop powerranges.txt or fn.txt insteadLeave every note where it is
README-RECOVER-.txtQilin's note — it takes its name from your assigned extensionKeep the lot
RECOVER--FILES.txtThe BlackCat/ALPHV family's naming patternTreat it as evidence
Desktop wallpaper replaced by a ransom demandA lock-screen shakedown pointing to a Tor addressPhotograph the screen first, restart after
Shadow copies gone — vssadmin delete shadows in the logsWindows' restore points were wiped by the attacker to block any rollbackTells us where to look instead
Posting it to us: send the device by a tracked, insured service to our intake lab — the return leg is on us — or ring first and an engineer talks you through the packing. Full posting instructions live on the contact page.

What's attacking UK networks, 2025–26.

QilinThe most active gang of 2025, with over a thousand named victims — Synnovis among them, the June 2024 breach that brought London's NHS pathology to a standstill. No free tool decrypts it.
AkiraNamed an imminent threat in a November 2025 advisory from CISA and the FBI. A free decryptor covers the 2023 build alone — everything released since is uncracked.
Life after LockBitThe NCA-led takedown of February 2024 broke LockBit and freed keys for a share of its past victims; the groups filling the gap operate at a smaller scale.
Free decryptors, honestlyIf a real free tool exists, No More Ransom hosts it. Qilin, Medusa, INC, RansomHub and current Akira have none — and the “universal decryptors” sold around the web are neither universal nor decryptors.

Ransomware recovery, one stage at a time.

Read the latest cases →
01

Booked in, assessed for nothing Free

Your device is logged under its own case number the day it arrives. An engineer finds the fault, tells you plainly what stands a real chance of coming back, and writes you one fixed quote. Nothing is charged for that look, nothing obliges you, and paid work starts only when you say so.

The look is freeA single quote, in writingNo obligation
02

Cut it off, preserve everything

First job: infected machines leave the network. Each drive is then imaged in full — free space too, because intact originals are often lying in it. Ransom notes, wallpapers and lock screens all stay put; that's your evidence.

Forensic image of the full diskFree space captured too
03

Hunt down the survivors

Plenty of variants work copy-first: encrypt the duplicate, bin the source. That binned source sits in free space, and patient carving brings it out. We also look for shadow copies the attacker missed, NAS snapshots, big files only partly scrambled — and check whether that strain truly has a free decryptor.

Deleted originals carved backDecryptor checked for your strain
04

Fresh media, full paper trail

Recovered data never goes back onto compromised machines — it comes to you on new media, with documentation written to stand behind an insurance claim or an ICO report.

Fresh media every timePaperwork ready for the ICO
05

Watched back, verified, returned

Before any fee falls due you see a full listing of everything recovered and approve it. Your files travel back on brand-new media, return postage on us, and the case stays open until you've confirmed everything opens on your own machine.

You approve the file listReturned on new mediaWe pay return postage

Opening checks at the bench

  • vssadmin delete shadows /all /quiet — the near-universal opening move, wiping the restore points Windows holds. Once the log shows it, the playbook is obvious and our search moves on.
  • Copy-encrypt-delete has a flaw — the deleted original doesn't vanish; it waits in free space, and careful carving can lift it out whole.
  • Speed-tuned strains don't encrypt everything — big files get scrambled in patches, and the untouched stretches often still read.
  • The law is moving too — in July 2025 the Government said it will ban public bodies and critical national infrastructure from paying ransoms. You can see where this ends.

Refusing to pay is normal now: in June 2025 Sophos reported that 97% of encrypted organisations recovered their data, yet only 49% had paid. Coveware's caseload shows payment rates at a record low — 23% by Q3 2025. In 2023 the British Library refused a demand of around £600,000 and rebuilt from scratch. A ransom is neither the reliable route nor the only one — it's simply the option shouting loudest.

Mid-incident? Report it here

  • Report Fraud (formerly Action Fraud) — the national cyber crime line on 0300 123 2040; during a live incident it's staffed round the clock.
  • NCSC — tell the National Cyber Security Centre what's happened, then follow its ransomware guidance step by step.
  • ICO, within 72 hours — where personal data looks likely to be caught up in it, UK GDPR requires a report without undue delay, and 72 hours is the outer limit.
  • No More Ransomnomoreransom.org, run jointly with Europol, is where every legitimate free decryptor lives. Check it before trusting any other offer.

Our part is the data: imaging drives, recovering files, rebuilding clean, and producing the records your insurer and the ICO will ask for. Negotiating with attackers isn't a service we offer — or one we'd ever recommend.

Fresh from the casebook.

EX · EDR-2026-2638VERIFIED ✓

A builders' merchant in Devon, encrypted while they slept

Rather than encrypting in place, this strain copied every file, locked the copy and deleted the original — so the originals still lay in free space where we could carve them, alongside a NAS snapshot the attacker had missed. Seven days later the firm was back trading. Nobody paid, nobody spoke to them.

Back within the weekNothing handed back

Before it leaves your hands.

Do

  • Photograph every ransom note and lock screen before touching anything
  • Pull the network cable on infected machines — but keep them powered
  • Keep every log; delete nothing yet
  • Report to Report Fraud and the NCSC — and, if personal data could be involved, to the ICO within 72 hours

Steer clear

  • Contacting, haggling with or paying the criminals
  • Restoring backups onto machines nobody has cleaned yet
  • Believing anyone selling a 'universal decryptor'
  • Turning a locked NAS back on before you've photographed what it shows

Straight answers from the bench.

Should we pay the ransom?

No. The ICO and UK policing agencies both say don't pay: money funds the next wave, nothing guarantees your files come home, and the ICO is on record that paying does not soften your regulatory position. Arranging payment is something we simply won't do.

Can files be recovered without paying the ransom?

Often, wholly or partly. The routes: backups, shadow copies the attack missed, originals still sitting in free space where a copy-encrypt-delete strain left them, NAS snapshots — or a genuine free decryptor where one exists for the variant.

Does a free decryptor exist for my strain?

Go to No More Ransom first, the legitimate archive run alongside Europol. No working decryptor exists for Medusa, Qilin, RansomHub, INC, or the current builds of LockBit and Akira — anyone claiming one is selling recovery work, not a key.

Do I have to report it?

Businesses should notify Report Fraud on 0300 123 2040 (it was formerly Action Fraud) and the NCSC; if personal data has likely been exposed, UK GDPR gives you 72 hours to inform the ICO.

Whatever the fault, leave the power off.

Each power-up of a failing device takes more data with it. Open a case first — the look-over is free whichever way it goes.

0800 6890668