Taking work now — the first look is freeSpinning disks in a machine Quicker still, give us a ring:0203 0868633
ADR Advanced Data Recovery 0203 0868633 Price my job
ADR / Sorted by symptom / Ransomware has encrypted the files

The job · an encryption run across the network

Ransomware data recovery, London. Speed makes mistakes, and we work from the mistakes. No ransom is paid.

Encrypting a whole network in one night has to be done fast, and fast work is sloppy work. The sloppiness is what we build on: a snapshot the NAS is still holding, a shadow copy that the run never reached, deleted originals sitting in free space, one large file encrypted in stripes only. Unplug the network lead, leave the machines running, photograph every screen, and then ring us. Jobs reach this bench from London, Bromley, Richmond and Croydon. A single machine is £300 + VAT; £500 + VAT is where anything holding a second disk starts — server, RAID set or NAS box — and that figure is in writing first. Data is the part we do, and nobody here speaks to whoever did this.

On most jobs: no data, no bill A free look first, then one figure in writing Media posted in from Croydon, Ealing and Camden

Put it to an engineer — the first look costs nothing
0203 0868633

Ransomware: what the symptom usually means.

Different fault? Try the finder →
How it shows itselfThe usual reason for itWhere that leaves you
Every filename now ends in something new — .akira, or a string issued to you aloneThe run has finished. Qilin gives each business it encrypts its own extensionPhotograph the screen, then pull the network lead
akira_readme.txt, folder after folderAkira leaves that one. Elsewhere: fn.txt, or powerranges.txtOpen none, delete none
The README-RECOVER-.txt noteQilin once more — its note carries whichever extension was appliedLeave every one of them where it is
A RECOVER--FILES.txt noteHow BlackCat/ALPHV names itThat is evidence. It stays on the disk
A demand standing in for the desktop wallpaperAny conversation is meant to happen through a Tor addressPhotograph the whole screen, edge to edge
No shadow copies at all, and vssadmin delete shadows in the logRolling Windows back is out: it has nothing to roll back toUseful, oddly — it shows us where to begin
Packing it and posting it:a damaged drive is finished off by movement, so use a rigid box and pad it out. Declare the parcel at what the files are worth to you, not at what the disk cost, then send it tracked to our intake lab. We meet the cost of the trip home. Rather have the packing checked over before you tape the box up? Ring first. It is all set down on theguide to packing and posting.

Who is encrypting UK networks in 2025–26.

Qilin ransomwareThrough 2025 no other group was named in as many incidents, and the public list of organisations it claims to have encrypted now runs into four figures. There is no free key for it.
Akira ransomwareIn November 2025 the FBI and CISA jointly labelled it an active threat. Two builds have been broken publicly — the original 2023 Windows build, by Avast's decryptor, and the 2024 Linux/ESXi variant, by a GPU brute-force method published in March 2025 — and nothing issued since has given way.
Whoever followed LockBitFebruary 2024 saw LockBit dismantled by an NCA-led operation, with decryption keys handed to some of the firms it had encrypted. The ground it worked is covered by smaller outfits today.
The free decryptors that do existFree tools that genuinely work are catalogued in exactly one place: No More Ransom. Look for Akira there and you will find a single tool, Avast's, which covers the early Windows builds only. Qilin, INC, RansomHub and Medusa are not listed at all. Whatever is sold online under the words “universal decryptor” is a sales page.

From the box arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on it the day the parcel lands, and an engineer settles what has truly failed before anything else happens — free of charge, and first in the order of work. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNothing owed at this stage
02

Off the network first, then copied as found

Nothing infected gets touched until it is off the network. Then every disk is imaged in full, free space included, since whatever it deleted on the way through is usually still lying there. Nor is anything tidied away — the notes, the altered wallpaper, the screen carrying the demand: every one of those is kept with the case.

Each disk imaged in fullFree space copied as well
03

Recovering what it did not reach

Encryption in place is unusual. What most strains do is read a file, write an encrypted version beside it and unlink the source, which removes the pointer while leaving the contents untouched. Until another file claims that room the bytes are still there, so carving them out whole is routine work here. Every other route is worked equally hard: snapshots the NAS kept, shadow copies the run failed to reach, large files encrypted in part only, and a published decryptor where one covers the strain in front of us.

Deleted originals carved out againPublished keys checked too
04

Clean media, and the work documented

Nothing goes back onto hardware the incident reached. Your files travel home on media bought in for this job, and a written account of the work goes with them, in a form that will satisfy an insurer or the ICO.

Fresh media, supplied with the jobDocumented for the ICO or an insurer
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge whatever. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have read those files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the jobThe post home is ours

What arrives most often

  • vssadmin delete shadows /all /quiet — it appears in most of these jobs, and it removes the restore points Windows had been holding. In a log, that single line usually identifies the script that did it and shows which other machines want examining.
  • Read, encrypt, unlink — and the original survives — unlinking is not erasing. The source file stays where it was until something else needs the room, and carving normally lifts it out whole.
  • Hurry leaves holes — pressed for time, a strain encrypts a large file only in stripes, and every stretch it skipped still opens the way it always did.
  • The law is only moving one way — under a proposal the Government published in July 2025, no public authority would be permitted to pay, and neither would any operator of an essential national service. Private firms are widely expected to arrive at the same place. Nobody sees the rules loosening.

Refusal is now the majority position. The payment rate Coveware measured for Q3 2025 was 23%, its lowest reading on record. Sophos put the question to organisations in June 2025: 97% had their data back, 49% having paid — so about half recovered without paying anybody. Asked for roughly £600,000 in 2023, the British Library declined, and rebuilt. Nothing about payment is certain. It is one route of several, and the only one in which the people who encrypted your files have an interest.

Incident still live? These are the numbers

  • Report Fraud (previously Action Fraud) — its cyber-crime line on 0300 123 2040 is answered outside office hours, which matters while an incident is still live.
  • NCSC — the National Cyber Security Centre takes reports as well, and its published ransomware guidance is worth working through from the top rather than dipping into.
  • ICO, and 72 hours to do it — under UK GDPR the clock starts as soon as you have reason to think personal records are caught up in it, not when the investigation ends. By day four the window has gone. Treat the deadline as fixed.
  • No More Ransomnomoreransom.org. Europol and the security industry keep it between them, and any real free tool for your strain is catalogued there if one exists. Look before you believe anybody offering to sell you a key.

Data is our half of it: every disk imaged, everything that can be recovered recovered, results handed over on clean hardware bought new for the purpose, and the whole job documented to the standard an insurer or the ICO looks for. Looking at it costs nothing; a fixed figure goes to you in writing ahead of any billable work; and on most jobs, unless the data returns, there is no fee. Nobody at this bench makes contact with whoever did this, and we would suggest you do not either.

One job, followed all the way through.

LDN · ADR-2026-3188JOB LOGGED ✓

A Richmond builders' merchant, and ransomware in the night

Nothing at all had been encrypted where it sat. The software worked file by file: read one, put an encrypted version beside it, then delete the original it had just read — which left the real accounts exactly where they had always been. Unallocated, and straightforward to pull back. What that did not catch was sitting in a NAS snapshot that nobody had checked. Nothing was paid, nothing was answered, and the merchant had invoices going out again the same week.

Invoicingagain within that same weekNot one pennypaid, and no demand met

What helps, and what harms.

Do this much first

  • Photograph each note, and any screen showing a demand
  • Pull the network lead, not the power lead — leave infected machines running
  • Keep every log. Delete nothing at all
  • Report Fraud first, the NCSC next; personal records among them means the ICO hears within 72 hours

What sets us back

  • Making contact with them, negotiating, or paying up
  • Putting a copy back onto a machine that is still infected
  • Trusting anybody who sells a 'universal decryptor'
  • Powering an encrypted NAS up again before it has been photographed

Questions answered before you commit.

Would paying be faster?

No, and nobody here handles a payment on your behalf. Three reasons, in order of weight. Nothing obliges the other side to send a key that works, so what comes back can be partial or useless. Your money funds whoever gets encrypted next. And the ICO's published position is plain: having paid counts for nothing when the case comes to be assessed. Police guidance reads the same.

How much of it usually comes back?

Often a great deal — some files whole, others in part. There are five ways in, and most jobs draw on more than one. Shadow copies the run failed to reach. Snapshots still held by the NAS. Originals unlinked rather than overwritten, sitting untouched in free space. A published free tool, where one genuinely covers the strain. And plainest of the lot, a copy you already hold yourself.

Has a free decryptor been published for this strain?

No More Ransom is the catalogue to look at first. Europol runs it with the security industry, and a tool only gets listed if it works. Neither Qilin nor Medusa has anything listed against it; nor do INC or RansomHub; nor does any LockBit or Akira build in current use. A “universal key” sold for one of those strains is recovery labour, priced under a different name.

Who has to be told about it?

Three at the most, and which of them will depend on the case. Cyber crime is a matter for Report Fraud — Action Fraud renamed — on 0300 123 2040. If you are a business, the NCSC should have a report too. Then, where personal records sat among what was encrypted, UK GDPR allows you 72 hours to tell the ICO, timed from the moment of realising.

Nothing gets worse while the power is off.

Looking at it is free. Back comes a list of what opened and what did not, together with a single price to finish, set down in writing while you are still free to say no. On most jobs an invoice only follows the data. Until that list reaches you, leave the drive switched off.

0203 0868633