Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / ransomware
Specialist recovery · ransomware

Ransomware recovery in Manchester, without the decryption promises.

Modern ransomware cannot be decrypted by anyone but the attacker, so the useful question is what survived it. Shadow copies the run failed to clear, unencrypted originals still sitting in free space, files it never reached, and backups it could not touch. We establish exactly what is recoverable, free, before you decide anything about paying.

From £300 + VAT
Strain identified first
Discreet & confidential
~ ransomjob-001 — live RECOVERED
$ mdr triage /dev/sdb
 Device: Dell PowerEdge (RAID 5)
 Status: RANSOMWARE — files encrypted (.locked)
 Strain: identified · known variant

$ mdr engineer-working
 Read-only image: taken · source preserved
 Shadow copies: located + extracted
 Decryptor: applied · known flaw

$ mdr verify
 ✓ databases — restored
 ✓ documents — 142,800 files
 ✓ data recovered — attacker unpaid
!

Isolate it. Don’t reboot, don’t rebuild, don’t pay yet.

Pull the network cable but leave running machines powered — shadow copies and material held only in memory can be lost on restart. Keep the encrypted files; they cost nothing to retain and are occasionally needed later.

// the first day

What to do in the first few hours.

Ordered by how much difference each makes, and none of it costs anything.

01

Disconnect from the network, not from power

Isolation stops it spreading to shares and NAS units. Powering down loses volatile evidence and can discard shadow copies that survived the attack.

02

Stop anyone rebuilding a machine

The instinct to wipe and reinstall is strong and it destroys the artefacts that establish what left the network — which you may need for the ICO and almost certainly for your insurer.

03

Find out what the backup actually contains

Not whether it exists. When it last ran, whether it was reachable from the infected network, and whether anyone has restored from it recently. Backups that sat on a mapped drive are usually encrypted too.

04

Photograph the ransom note

The strain name and contact details identify the family, which determines whether a free decryptor exists and how the attack behaves.

05

Don’t engage before you know what survived

The negotiation clock is designed to pressure you. Knowing what is recoverable without paying is the only thing that changes your position.

// why nobody decrypts it

The uncomfortable technical truth.

Worth stating plainly, because a good deal of this industry is vague about it.

Current ransomware encrypts each file under its own random symmetric key, then seals those keys with the attacker’s public key. Breaking one file gains you nothing toward the next, and the master key exists only on the attacker’s side. That is not a gap a specialist closes — it is correctly implemented cryptography doing exactly what it was designed to do.

Where a free decryptor exists it is usually published through the No More Ransom project and applies to a specific family with a specific implementation flaw. We check that first because it costs nothing. Where none applies, any firm still offering decryption is either describing an old broken strain or quietly proposing to pay the ransom on your behalf with a fee attached.

// what does come back

Recovering around the encryption.

In practice most of what is retrieved after an attack was never successfully encrypted in the first place.

// the claim and the regulator

Two conversations running in parallel.

Both are happening while you deal with the technical side, and both are shaped by decisions made in the first day.

Your insurer. Cyber policies almost always require the affected systems preserved for assessment. Wiping and rebuilding before the insurer’s appointed responder has looked is a common way a valid claim gets argued over — not because anyone acted in bad faith, but because the evidence of what happened went with the reinstall. Check the policy wording before touching anything, and if there is an incident hotline on it, use that first.

The regulator. Where personal data may have been accessed, UK GDPR gives you 72 hours to assess and potentially notify. The question the ICO asks is not whether files were encrypted but whether data left the network — and that is answered by logs, connection records and artefacts that a rebuild removes. Imaging the systems read-only before anything else preserves the ability to answer it, and costs nothing extra.

// pricing

What this costs, against what the ransom costs.

Worth setting side by side, because that is the decision actually being made.

Recovery on servers, NAS units and RAID systems starts from £500 +VAT; a single workstation is from £300 +VAT. Both are fixed in writing after a free 48-hour assessment that tells you what survived before you commit to anything.

Ransom demands against UK SMEs typically run into the tens of thousands, and paying buys a decryptor — not the deletion of anything already copied out, and not a guarantee the decryptor works on every file. Recovery around the attack costs a fraction of that and carries no dependence on the attacker keeping their word. We take no percentage of anything and no part in negotiation, which means we have no reason to overstate what we can retrieve.

// getting it to us

Getting it to the bench.

Get the device to us with a short note on what happened. The diagnostic that follows costs nothing, and the figure that follows it is fixed in writing before any work begins.

1

Post it, or drop it in

Nothing can begin until the device is on the bench, which makes this the only step that needs anything from you. Pack it properly, put your details in with it, and send it over. What follows is a free diagnostic and a written figure, in that order.

Packing it properly
  • A small rigid box or a padded envelope — and an anti-static bag if one is to hand, though a food bag will do at a push.
  • Leave the caddy, cables and power supply at home. None of it is needed to read the drive, and it only adds weight.
  • Put your name, address, phone number and email inside the box — on paper, or on the shipping form below.
Post toManchester Data Recovery
Peter House, Oxford Street
Manchester M1 5AN
Shipping formPDF · print & include with your devicePDF ↓

Posting it? Use something tracked and insured — whatever is on the drive is worth considerably more than the postage. Bringing it in? Weekdays, 9am to 5:30pm, and it still wants packing as above for the journey.

2

Not ready to send it?

Tell us what the device is, what it is doing, and anything already tried — an engineer will come back with a realistic view of the odds and a price band, before you commit to posting anything.

Every enquiry is read by an engineer rather than a form-handler, and most get an answer inside the hour on a working day. Would rather speak to someone? 0161 871 0788.

Got it — that’s with an engineer.

We’ll be in touch shortly. If it’s urgent, call 0161 871 0788.

// questions

Ransomware recovery — your questions.

What people most often ask us after a ransomware attack.

No, and nor can anyone else for a current strain. Each file is encrypted under its own key, sealed with the attacker’s public key, and the master exists only on their side. Where an older family has a known flaw, a free decryptor may exist through No More Ransom and we check that first at no cost.

That is exactly what the free assessment answers, and it varies enormously — from almost everything to very little, depending on what shadow copies survived, whether originals remain in free space, and what the run never reached. You get a figure before you commit to anything.

Disconnect them from the network, but leave running machines powered. Isolation stops the spread; a restart can discard shadow copies and memory-resident material that would otherwise have been recoverable.

Very likely encrypted alongside everything else, because modern families follow mapped drives and network shares deliberately. What tends to survive is anything that was offline, immutable, or on a system the attack could not authenticate to.

If personal data may have been accessed or exfiltrated, you have 72 hours to assess and potentially notify. The question is whether data left the network, and answering it depends on artefacts that a rebuild destroys — which is why we image before anything else.

No. We do not handle negotiation or payment and take no percentage of anything recovered. That also means we have no incentive to overstate what can be retrieved — the assessment says what it says.

// hit by ransomware?

Before you pay anyone, let us tell you what’s actually recoverable.

We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.