Every folder suddenly holds a payment demand, every document wears an extension you've never seen, and the attackers insist their decryptor is the only way back. It usually isn't the whole story. We examine encrypted PCs, servers and NAS units for Sheffield homes and businesses and pursue every honest route to your data — and we never pay ransoms.
Free diagnostic on every ransomware job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every ransomware job starts by matching the symptoms to the fault — these ten cover almost everything that reaches the bench.
Every document, photo and desktop file renamed and locked in one overnight run — the classic single-machine attack we see most.
Internet-exposed NAS boxes are a favourite target — but snapshots and remnants beneath the encrypted shares often survive the sweep.
Hypervisor attacks sweep the VMFS datastore and lock every VMDK inside it, dropping an entire virtual estate in one pass.
Speed-tuned strains encrypt only the opening blocks of big databases and archives — the untouched remainder is frequently usable.
Most strains run vssadmin to destroy restore points before encrypting; carving can sometimes pull the deleted copies back from free space.
The attached USB backup drive or backup share was reachable, so it got hit too — earlier versions and remnants are still worth chasing.
Data was stolen before it was locked, with publication threatened — we document what left the network for insurers and ICO reporting.
The PC starts to a ransom screen instead of Windows — the drive comes out, gets imaged, and the file system is examined beneath the lock.
SQL and Exchange stores caught during writes end up part-encrypted, part-corrupt — salvaged page by page from the image where they survive.
A live infection that re-locks whatever you restore — isolation first, then recovery from images, never on the compromised box.
An extension and note no search engine recognises — samples are fingerprinted to identify the family and any published weakness.
Some scareware plants the note without real encryption, or the run failed partway — a quick lab check can turn panic into relief.
Ransomware works through your storage file by file, encrypting each one with strong, industry-standard cryptography — typically AES on the files themselves, with those keys then sealed under an RSA or elliptic-curve key that only the attacker holds. The renamed extensions (.lockbit, .akira, .medusa and hundreds more) are the strain's signature, and the note planted in every folder is generated once the run finishes. Capable strains also delete Volume Shadow Copies, seek out backup drives and encrypt anything the infected account could reach across the network — it's why the note sounds so confident. What it never mentions is everything the attack missed.
When a strain's encryption is built properly and its keys are out of reach, no lab on earth can brute-force the files — anyone claiming otherwise is selling false hope. Genuine recovery comes from what the attack failed to finish: shadow copies and NAS snapshots that survived the deletion pass, backups the malware never reached, deleted originals left behind where a strain encrypted a duplicate and deleted the source file, unencrypted remnants and temporary files carved out of free space, damaged NAS and RAID volumes rebuilt so the intact data beneath them is readable again, and — for the minority of strains with a published flaw — a free public decryptor applied lawfully. The diagnostic establishes which of those routes exist in your case before you commit to anything.
We never pay ransoms, and we won't nudge you towards paying: it bankrolls the next attack, guarantees nothing, and the decryptors criminals hand over are notoriously slow, buggy and incomplete. Our job is to exhaust every technical route first and set out, in writing, exactly what is and isn't coming back — we make no promises against a strain with no known weakness, because nobody honestly can. If a business with insurers and regulators involved ultimately chooses to negotiate, that decision sits with them and their advisers; what you'll have from us is a recovered copy of everything recoverable and a straight account of the rest.
Ransomware jobs are treated as forensic cases from the first minute — isolated, imaged and documented:
Encrypted media is handled on an isolated bench with no route to the lab network — nothing can spread, phone home or start encrypting again while we work.
Each drive from the incident is imaged read-only before analysis begins; recovery runs entirely on the copies, and your originals leave exactly as they arrived.
Deleted Volume Shadow Copies and NAS snapshots are hunted through unallocated space and reconstructed wherever the malware's deletion pass left them intact.
Ransom notes and sample files are fingerprinted against strain databases, then checked against reputable public decryptors (No More Ransom, vendor releases) for a lawful way in.
Unencrypted originals, temporary files and partial copies are carved out of free space — the debris a fast-moving encryption run leaves behind.
The strain, the scope of the damage and exactly what was recovered are documented throughout — the paperwork insurers, the ICO and your own post-incident review will ask for.
Two things stated plainly up front: against a strain with no published weakness we make no promises, because correctly implemented encryption without the key cannot be broken; and we never pay ransoms or act as a go-between with attackers. Ransomware is classed as forensic work: it's quoted after the free diagnostic, and the price is payable upfront rather than on a no fix, no fee basis.
Before anything is posted: unplug the infected machines from the network and let them sit exactly as they are — no reinstalling, no antivirus 'cleanup', no formatting, because each of those destroys the remnants we recover from. Keep the ransom note and set aside two or three sample encrypted files, then call 0800 689 0668 and we'll agree exactly what to send. Everything is imaged on an isolated bench and worked on as copies only.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Leeds Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.