Home / Blog / Business

Ransomware data recovery: can encrypted files come back?

First hour: contain, don't clean

Disconnect the affected machines from the network and the internet — pull cables, kill Wi-Fi — but don't wipe anything and don't switch off the NAS or server until you've thought it through. The instinct to reinstall Windows and move on destroys exactly the artefacts that make recovery possible. Photograph the ransom note, note the file extension the encrypted files now carry, and stop all backup jobs immediately so encrypted files don't overwrite your last good backup versions.

If the business falls under UK GDPR and personal data is involved, remember an attack may be a reportable breach — loop in whoever handles your compliance early.

The three realistic recovery routes

Route one: copies the ransomware missed. Offline and off-site backups, cloud version history (OneDrive, SharePoint, Google Drive and Dropbox can roll files back to pre-attack versions), NAS snapshots, and Windows shadow copies. Modern ransomware tries to delete shadow copies and NAS snapshots — but 'tries' is the operative word, and we regularly find them partly intact.

Route two: a free decryptor. Some ransomware families have been broken and have free decryption tools published by researchers and the No More Ransom project. Identifying the exact strain (from the note and file extension) tells you if you're lucky. Never buy a 'decryption service' from an unknown website — most simply pay the criminals or take your money.

Route three: lab recovery of what encryption didn't reach. Encryption takes time, and attacks get interrupted. On real jobs we find untouched files on secondary drives, older file versions in unallocated space, whole virtual machine snapshots, database backups the malware didn't parse, and partially encrypted files where only the first blocks are damaged. This is standard data recovery craft applied to an unusual crime scene — imaged drives, forensic tools, and a file-by-file audit of what survived.

Should you pay?

Payment is a last resort, and not just ethically: industry studies year after year find a meaningful share of payers get nothing usable back, and payment marks you as a payer for the next crew. UK authorities advise against paying, and for some sanctioned groups paying can itself create legal exposure. Exhaust the three routes above first — most businesses that come to us assuming they'll 'have to pay' turn out to have more surviving data than they thought.

Report the attack via Action Fraud and preserve the evidence — it costs nothing and occasionally the strain you're hit with is one that gets broken months later, at which point preserved encrypted drives become recoverable.

How we handle ransomware jobs

Send or courier the affected drives, the NAS or the server (labelled by bay), and we image everything before any analysis — originals are never worked on. You get a report of what's recoverable across all three routes and one fixed quote; no fix, no fee applies to ransomware like everything else. Business-critical cases are prioritised on arrival — call 0800 689 0668 and say it's an active incident.

Related reading: NAS recovery, RAID recovery and SAN & virtual machine recovery — the three places business data usually lives when ransomware hits.

Stop backup jobs immediately after an attack. A scheduled backup that runs post-encryption can overwrite your last clean copies with encrypted ones — turning a bad day into a disaster.

// questions on this topic

Common questions

Sometimes — if the ransomware family has a published free decryptor, or if the attack was interrupted. More often, recovery comes from copies the malware missed: shadow copies, snapshots, cloud version history and unencrypted remnants on the disks.
Not always. 'Deleted' snapshots and shadow copies live on disk until overwritten, and attacks rarely run to absolute completion. Imaging the drives and hunting the remnants is a routine part of our ransomware work.
Contain first, recover second, rebuild third. Reinstalling on the affected disks overwrites recoverable data. Image or set aside the original drives, rebuild on fresh hardware or storage, and let the originals be worked for what they still hold.
Yes — NDAs on request, GDPR-compliant handling throughout, and we're used to working alongside IT providers, insurers and incident-response requirements. Recovered data is returned encrypted.

Need it recovered rather than explained?

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.