Every file locked, the boot record overwritten, the shadow copies gone, a ransom note waiting. This is the case file where we lay out exactly what we recovered — because the thing most firms promise in this situation can’t actually be delivered.
← All case files · £300 + VAT, flat
An HP Omen laptop, taken by LockBit. Every user file locked away or unreachable, a note demanding payment, and Windows dead on boot. The antivirus had changed nothing — and that’s no surprise, because antivirus is there to block an infection, not to unpick one that’s already run. No backup existed.
read off the ransom note and the file markers. Nothing on this page matters more, because the strain alone decides whether a released decryptor exists — and for LockBit, there isn’t one.
the reason the machine wouldn’t boot in the first place.
ransomware always attempts this — it doesn’t always pull it off in full.
LockBit seals each file behind AES-256 and then locks that key away again under RSA. With the private key in the attacker’s hands and nowhere else, those encrypted files are beyond anyone — us, any lab, any supercomputer. When a recovery firm says it can decrypt a current strain, it’s either leaning on a public tool for a strain that was already cracked, or it’s lying.
We didn’t try to get through the encryption. We went round the side of it.
Going round it means gathering up every copy of the data that the ransomware failed to seal. Working from a full forensic image rather than the drive, we pursued four seams at once. First, the deleted originals still lying in unallocated space — LockBit encrypts a copy and bins the source, and that source is recoverable right up until Windows reuses the space. Second, any scraps of the Volume Shadow Copies that had survived the purge. Third, unencrypted caches and temporary duplicates that applications had scattered elsewhere on the disk. And fourth, the still-readable interiors of the big files the malware had only half-finished encrypting. Not one byte of it came from decryption — and before any of it, we rebuilt the overwritten Master Boot Record so the image would present as a volume at all.
Data came back, and none of it was decrypted — it came from deleted originals, shadow-copy fragments, unencrypted caches and the intact middles of half-encrypted files. The ransom went unpaid.
The total varies enormously from case to case, and any figure quoted before the drive is imaged is invention. It depends on the strain, on whether it overwrote in place or wrote-then-deleted, and most of all on how quickly the machine was switched off — because those deleted originals are the richest seam of all, and they last only until Windows writes across them.
The one thing it can never include is a file that was cleanly encrypted and whose original was truly overwritten. That file is beyond recovery, full stop — by us or anyone.
When ransomware lands, the next few minutes are what decide how much survives.
unplug the network cable — it travels across shares.
several strains encrypt in passes, and a restart can let a half-finished job run to the end.
it names the strain, and the strain is what tells you whether a free decryptor is out there.
the deleted originals are the single richest source of recovery, and they last only until something writes over them — and a running computer is writing something every minute.
As for afterwards: the backup that let this business down let it down by never existing. The backup that more often fails is the one left permanently mapped — ransomware encrypts whatever it can reach, so an always-connected backup drive isn’t a backup at all, just a second copy of the disaster.
Drop the drive at our Guildford Business Park reception, or post it to us — it costs nothing to find out what happened. You get a written figure from the fixed bands before any work begins.