Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · They Encrypt Backups First

A Backup on Reachable Storage Is Inside the Blast Radius

This enquiry came on behalf of a business after a ransomware incident, and the detail that matters is which drive they need. "They require an encrypted drive recovered, as it contains a system image backup of their server." The backup being encrypted alongside everything else is not misfortune — it is the point of the attack. A business with an intact backup does not pay, so backups are found and encrypted deliberately, usually before anything visible happens.

MediaBusiness hard drive holding a server system image backup — encrypted during a ransomware incident affecting the wider environment
Reported situationBusiness affected by a ransomware incident · server system image backup held on an attached drive · backup encrypted along with production data · recovery of the backup sought · sample encrypted files available
Fault classDeliberate encryption of backup media as part of the incident — no device fault; recovery dependent on incomplete encryption, prior snapshots or offline copies
Equipment usedDevice preserved unaltered including ransom artefacts · variant identified from artefacts and file structure · encryption completeness assessed per file · volume shadow and snapshot survival assessed · offline and rotated media identified · position stated honestly before any charge

The decode: why the backup went first, and what is actually worth trying

Why attackers target backups deliberately: the entire economic model depends on the victim having no alternative. An organisation that can restore from backup declines and rebuilds. So modern ransomware spends time before it announces itself — enumerating attached storage, network shares and backup destinations, and encrypting those first, precisely so that the discovery and the loss of the remedy happen together.

What follows, and it is the doctrine: a backup on storage the compromised systems can reach is not a backup. It is a second copy inside the same blast radius. Protection requires the copy to be unreachable — offline media physically disconnected between runs, or a destination the production systems have no credentials to modify.

Being honest about the encryption itself: where files have been properly encrypted by a current variant, they are not recoverable by technical means. There is no laboratory technique, and anybody suggesting otherwise should be treated with suspicion. Saying so plainly is the useful thing.

What genuinely is worth assessing, and it is more than nothing. Whether encryption completed — many variants encrypt only the opening portion of large files for speed, which on a multi-gigabyte system image can leave the overwhelming majority intact and extractable. Whether the process was interrupted partway, leaving later files untouched. Whether volume shadow copies survived, since deleting them is a standard step that does not always succeed. And whether any older or rotated media exists, disconnected at the time.

Why the variant matters: some families have had flaws found in them and free decryptors published by security researchers. Identifying which one is involved is a genuine first step, and the artefacts left behind — the note, the file extension, the structure — are what identifies it. Which is why the device must be preserved rather than cleaned up.

What must not happen: nothing should be reformatted, restored over, or "cleaned" before the position is established. And nobody should pay anything without advice — payment funds the model, frequently produces no working key, and is a decision with legal and insurance dimensions beyond the technical one.

What to do about the wider incident: this is a security matter as much as a data one, and the compromise should be investigated properly. Restoring data into an environment still holding the access that caused it repeats the exercise.

On the bench

The device was preserved unaltered including ransom artefacts, those artefacts identifying the variant and some families having published decryptors. Encryption completeness was assessed per file — many variants encrypting only the opening portion of large files for speed, which on a multi-gigabyte system image can leave the majority extractable. Volume shadow and snapshot survival was assessed, deletion of those being a standard step that does not always succeed, and offline and rotated media identified. The position was stated honestly before any charge.

The outcome

The device preserved unaltered, the variant identified from artefacts, encryption completeness assessed per file and the position stated before any charge. Free assessment, and no charge where nothing is possible. The decode: your backup was not unlucky. Attackers enumerate attached and network storage and encrypt backup destinations first, because an organisation that can restore does not pay. A backup on storage the compromised systems can reach is a second copy in the same blast radius.

Ransomware that encrypted your backup too

Preserve everything exactly as it is — including the ransom note and the file extensions — because those identify the variant, and some families have had published decryptors released by researchers. Don't reformat, restore over, or clean anything before the position is established, and don't pay without advice. Properly encrypted files aren't recoverable by technical means, and anyone claiming otherwise should be treated with suspicion. What is genuinely worth checking: whether encryption completed, since many variants encrypt only the opening portion of large files for speed and a multi-gigabyte system image may be mostly intact; whether shadow copies survived; and whether any rotated media was disconnected at the time.

Backup encrypted along with everything else?
Preserve it as it is — call Guildford Data Recovery on 01483 901310; variant identified from artefacts, encryption completeness assessed per file, shadow copies and offline media assessed, honest position before any charge.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.