Lab accepting new cases ·  Mon–Fri, 9am–5:30pm Urgent? Call 01273 964902
BDR Brighton Data Recovery 01273 964902 Start a case
BDR / How it failed / Ransomware attack

How it failed · ransomware

We recover. We never negotiate.

Ransomware encrypts what it can reach and deletes what would save you — then asks to be paid for the privilege. Our position is fixed: we recover data from backups, shadows, free space and the strains' own shortcuts, and we never pay, negotiate with, or contact attackers on anyone's behalf.

No fix, no fee on most jobs Free diagnosis & written quote Post-in from anywhere in Sussex

Talk it through with an engineer
01273 964902

What you're seeing, decoded.

Something else? Run the triage →
What you seeWhat it meansFirst move
Files renamed with a new extension (.akira, or a random string per victim)Encryption has run — Qilin generates a different extension for every victimPhotograph, then isolate
akira_readme.txt in every folderAkira's ransom note (variants: powerranges.txt, fn.txt)Don't delete the notes
README-RECOVER-<extension>.txtQilin's note, named after your victim-specific extensionKeep every copy
RECOVER-<id>-FILES.txtBlackCat/ALPHV-lineage note formatEvidence, not litter
Desktop wallpaper replaced with instructionsLock-screen-style extortion pointing at a Tor addressScreenshot before any reboot
Shadow copies missing; vssadmin delete shadows in the logsThe attacker deleted Windows' own restore points to stop you recoveringTells us where to look instead
Getting it to us: post your device tracked and fully insured to our secure intake lab — free return postage — or start by phone and we'll walk you through packing it. Sending details are on the contact page.

The strains on UK screens, 2025–26.

QilinThe most active operation of 2025 — over a thousand listed victims, including the Synnovis attack that disrupted London NHS pathology in June 2024. No free decryptor exists.
AkiraA CISA/FBI advisory in November 2025 flagged it as an imminent threat. A free decryptor exists only for the 2023-era variant; current versions have none.
The LockBit aftermathThe NCA-led takedown in February 2024 broke LockBit's dominance and freed decryption keys for a subset of past victims — successors persist at smaller scale.
Free decryptors — the truthNo More Ransom hosts every legitimate free tool. For Qilin, Medusa, INC, RansomHub and current Akira there is none — and paid “universal decryptors” advertised online are neither.

How we recover it, stage by stage.

See recent recoveries →
01

Booked in, diagnosed free Free

Your device is logged with its own case reference the moment it arrives. An engineer assesses the fault, confirms what's actually recoverable, and you get a fixed price in writing — no diagnosis fee, no obligation, and no paid work until you say go.

Free diagnosisFixed written quoteNo obligation
02

Contain and preserve

Affected machines are isolated and imaged in full — including free space, where recoverable originals often survive. Notes, wallpapers and lock screens are preserved as the evidence they are.

Full forensic imagesFree space captured too
03

Hunt the survivors

Many strains copy, encrypt and delete — leaving originals recoverable from free space. We check surviving shadow copies, partially-encrypted large files, NAS snapshots, and whether a legitimate free decryptor exists for the exact strain.

Free-space originals carvedDecryptor checked per strain
04

Rebuild clean and report

Recovered data is restored to clean media — never back onto compromised systems — with documentation that supports your ICO notification and insurance claim.

Clean media onlyICO-ready documentation
05

Verified, returned, signed off

Before you pay the recovery fee you approve a full listing of what came back. Your data returns on new media with free return postage, and the case only closes once you've confirmed everything opens on your side.

File listing approvalNew media includedFree return postage

What the lab checks first

  • vssadmin delete shadows /all /quiet — the near-universal first move, wiping Windows' own restore points. Finding it in your logs confirms the playbook, and tells us to look elsewhere.
  • Copy-encrypt-delete leaves survivors — strains that encrypt a copy and delete the original leave that original in free space, where careful carving finds it.
  • Intermittent encryption cuts corners — speed-focused strains encrypt only parts of large files, sometimes leaving usable content in what remains.
  • The UK is moving — in July 2025 the Government confirmed it will ban ransom payments by public-sector bodies and critical infrastructure. The direction of travel is written.

The numbers behind 'don't pay': Sophos (June 2025) found 97% of organisations whose data was encrypted got data back — while only 49% paid, and payment rates in Coveware's incident caseload fell to a record 23% by Q3 2025. The British Library refused a ~£600,000 demand in 2023 and rebuilt. Payment is neither necessary nor reliable; it's just the loudest option on the screen.

Hit right now? The UK routes

  • Report Fraud (formerly Action Fraud) — 0300 123 2040, the national reporting route for cyber crime, at any hour for live attacks.
  • NCSC — report the incident and follow the National Cyber Security Centre's ransomware guidance.
  • ICO, within 72 hours — if personal data is likely at risk, UK GDPR requires notification without undue delay and no later than 72 hours.
  • No More Ransomnomoreransom.org is the only legitimate home of free decryptors, run with Europol. Check it before believing anyone else.

Our part: we handle the data — imaging, recovery, clean rebuilds and the documentation your ICO notification and insurer will ask for. We don't negotiate, and we'll never suggest you should.

From the casebook.

EX · BDR-2026-0638VERIFIED ✓

A Sussex builders' merchant, encrypted overnight

The strain copied files, encrypted the copies and deleted the originals — so the originals were still carvable from free space, alongside a NAS snapshot the attacker missed. Trading resumed inside a week. Nothing was paid, and nothing was said to the attackers.

Back in a weekNothing paid

Before it reaches us.

Do

  • Photograph every note and lock screen before touching anything
  • Isolate affected machines — unplug the network, leave the power
  • Preserve logs and don't wipe anything yet
  • Report it: Report Fraud, the NCSC, and the ICO within 72 hours if personal data is at risk

Don't

  • Pay, negotiate, or contact the attackers yourself
  • Restore backups over machines that are still compromised
  • Trust websites selling 'universal decryptors'
  • Reboot a locked NAS before photographing its screen

Asked on this bench, answered honestly.

Should I pay the ransom?

No. UK law enforcement and the ICO jointly discourage payment — it funds the next attack, doesn't guarantee your data back, and the ICO has said plainly it won't treat payment as reducing your regulatory risk. We never facilitate payment in any form.

Can encrypted files be recovered without paying?

Often, partially or fully — from backups, surviving shadow copies, originals left in free space by copy-encrypt-delete strains, NAS snapshots, or a free decryptor where one genuinely exists for the strain.

Is there a free decryptor for my strain?

Check No More Ransom, the legitimate repository run with Europol. For Qilin, Medusa, INC, RansomHub and current Akira and LockBit versions, there is none — anyone selling one is selling a recovery service, not a key.

Do I have to report it?

Businesses should report to Report Fraud (formerly Action Fraud, 0300 123 2040) and the NCSC — and if personal data is likely at risk, notify the ICO within 72 hours under UK GDPR.

Whatever's failed, don't power it on again.

Every restart of a damaged device costs data. Open a case first — the diagnosis is free either way.

01273 964902