Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / ransomware
Specialist recovery · ransomware

Struck by ransomware? We help you get back.

Ransomware seals up your files and demands payment — yet paying is seldom the only way out, and frequently the worst. We identify the strain, recover whatever can be recovered — decryptable variants, shadow copies, backups, data that was never encrypted — and keep the whole of it intact for your insurer and investigators. It opens with a free assessment of exactly what can be brought back, before paying so much as crosses your mind.

From £300 + VAT
Strain identified first
Discreet & confidential
~ ransomjob-001 — live RECOVERED
$ bdr triage /dev/sdb
 Device: Dell PowerEdge (RAID 5)
 Status: RANSOMWARE — files encrypted (.locked)
 Strain: identified · known variant

$ bdr engineer-working
 Read-only image: taken · source preserved
 Shadow copies: located + extracted
 Decryptor: applied · known flaw

$ bdr verify
 ✓ databases — restored
 ✓ documents — 142,800 files
 ✓ data recovered — attacker unpaid
!

Hold off on paying — and don’t wipe the machine.

As soon as ransomware shows itself, cut the affected machines off — off the network, away from any backups — so it can’t spread. Reformat nothing, rebuild nothing, delete nothing, and don’t hurry to pay: a payment buys no guarantee of a working decryptor, and it bankrolls more crime. Keep the ransom note and a few encrypted sample files, and come to us — the strain is identified first, and a few can be decrypted for nothing.

// how ransomware hits

What ransomware does to your data.

Today’s ransomware goes well beyond scrambling a handful of files — it moves across drives, seeks out your backups, and aims at the systems your business runs on. These are the cases we meet most.

// strains we recover from

Every major ransomware family.

Before anything else is touched, we fix the exact family and variant from the ransom note and a few encrypted samples. Some strains have a free or known decryptor; for the current big families the encryption simply can’t be broken — so recovery comes instead from shadow copies, backups and data that escaped encryption.

We have a solution for these strains — variant-dependent
STOP/DjvuPhobos8BaseDharmaCrySISGandCrabTeslaCryptBabukLockFileMalloxDoNexAvaddon
We have partial solutions for these strains — recovered another way
LockBitQilinAkiraPlayBlack BastaCl0pRansomHubMedusaBianLianRhysidaRoyal / BlackSuitConti

Identifying the strain always comes first — we check the No More Ransom project, run by Europol and police forces to publish free decryptors, alongside our own tooling. Whatever the family, you’re told honestly what’s recoverable before any work starts.

// systems we take on

Every system, every platform.

Ransomware-hit data comes back across every major operating system, server and NAS platform — Windows, macOS and Linux, and the virtual environments running on them. If ransomware reached it, chances are we can help.

Windows 11Windows 10Windows 8.1Windows 7Windows Server 2025Windows Server 2022Windows Server 2019macOS TahoemacOS SequoiamacOS SonomamacOS VenturamacOS MontereyUbuntu / LinuxVMware ESXiHyper-VProxmoxSynology DSMQNAP QTSTrueNASRAID & NAS

Desktops, laptops and workstations; physical and virtual servers; NAS and SAN systems; current and older Windows, macOS and Linux releases.

// how the recovery runs

How recovery works after ransomware.

One principle drives everything here: your files come back without a penny reaching the criminals. Before anyone touches a byte we name the family behind the attack, and we refuse to gamble on a blind payment. From there the job is deliberately methodical — originals are frozen as evidence, every operation happens on cloned copies, and we chase recovery down each avenue in turn: unencrypted leftovers, offline and versioned backups, Windows shadow copies, and any decryptor that genuinely exists.

01

Assessment and strain ID

Walk us through the incident. Using the ransom note plus a handful of scrambled sample files, our engineers pin down which family is responsible — then confirm whether a functioning decryptor is already in circulation for it.

02

Isolate and image read-only

Every affected disk is captured as a write-blocked forensic image. Your original media is sealed away untouched as evidence, while all the subsequent work happens only against the clones.

03

Map the recovery routes

We rank each avenue by how much it is likely to return, then work down the list: deleted originals carved straight from unallocated space; temporary and half-scrambled files; transaction logs sitting inside your databases; cloud and offline backup sets; shadow copies the malware never managed to wipe; and, last of all, any legitimate published decryptor.

04

Recover around it

Where a strain is old or flawed enough to have a working decryptor, we run it. Modern families are a different story. BlackCat, Akira, LockBit and their peers wrap each file in AES-256 sealed behind an RSA or ECC key — a lock that no one, this lab included, can pick, and we will not claim otherwise. So we go around the encryption rather than through it: originals the malware duplicated and then overlooked, shadow copies, and the plentiful partly-scrambled files that fast strains leave behind (many bother only with the opening few megabytes, or strike every Nth block), plus whatever else on the platter is still legible.

05

Recover your data

Files, databases and virtual machines are pulled out and reassembled — and we sequence the work so that whatever you most need running again is handled first.

06

Verify and report

A full inventory of what came back goes to you for review; once you have confirmed it, everything is written out to a clean external drive.

07

Secure return

The recovered set returns to you on new media — or, for lighter volumes, over an encrypted transfer — all set for you to rebuild your systems from.

// what we recover from

Encrypted. Then recovered.

From workstations up through virtual machines, RAID arrays, NAS boxes and servers, we bring encrypted data back — naming the family first, safeguarding the evidence throughout, and pursuing every open recovery route to the end.

All systems
servers, NAS, RAID, PCs
Read-only
source preserved
Strain ID
decryptor checked
Written quote
before any work
Evidence
kept for insurers
25 yrs
Recovering data
// get a custom quote

Request a written quote

Tell us what happened and we’ll get back to you, usually within a working day.

Prefer to call? 01483 901310 · Mon–Fri 9am–5:30pm

// pricing

Clear, fixed pricing.

A written quote lands before any work starts — no buried fees, no pressure.

Ransomware recovery
From £300 + VAT
For a single-disk machine it’s a flat per-drive fee starting at £300 + VAT; multi-disk and larger setups are priced individually, case by case.
  • Evidence kept intact for your claim
  • Family pinned down and priced up front
  • You approve a written quote before we start
// jobs off the bench

Ransomware attacks, recovered.

A few recent ransomware recoveries across servers, NAS and workstations. Identifying details stripped, specifics kept deliberately vague.

// CASE 2026-040recovered
Dell PowerEdgeRAID 5 serverEncrypted

Overnight, a server and its mapped backups were both locked.

This particular family had a documented flaw. Working from read-only images of every disk, we deployed a decryptor and brought the databases and file shares back whole.

// CASE 2026-033recovered
Synology NASRAID 6 NASShadow copies

A NAS was hit through a mapped drive, but its snapshots held.

What the malware never reached was the NAS’s internal snapshots. Those protected versions, together with everything left unencrypted, came back in full.

// CASE 2026-026recovered
Windows PCWorkstationStrong encryption

A workstation caught a strain that had no decryptor at all.

With direct decryption off the table, recovery came instead from shadow copies, a dated offline backup, and the unencrypted fragments left on the disk.

// getting it to us

Two easy steps.

Send the device in for its free diagnostic and tell us briefly what happened; an engineer reviews it and confirms your exact quote in writing before anything starts.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toGuildford Data Recovery
Building 2, Ground Floor, Guildford Business Park
Guildford GU2 8XH
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01483 901310.

Thanks — your message is in.

We’ll be in touch shortly. If it’s urgent, call 01483 901310.

// questions

Ransomware recovery — your questions.

What people most often ask us after a ransomware attack.

More often than people expect, though the strain sets the ceiling. A few can be decrypted outright; for the rest we lean on other routes — leftover unencrypted data on the drive, offline and cloud backup sets, and Windows shadow copies. Where exactly you land is what the assessment establishes.

Have it assessed before you decide, every time. Handing over money buys no guarantee the decryptor even works, marks you out as an easy repeat target, and bankrolls the next victim’s attack. In a good many jobs we return the data without a single payment changing hands.

On occasion, yes. Older strains sometimes carry published keys or known weaknesses, and the No More Ransom project — a free initiative run by Europol alongside police forces — can crack a number of them. But for today’s major families the cipher is intact and unbreakable by anyone at all; rather than pretend, we simply route around it and recover your data another way.

Usually more than you would think. Off-site and offline copies, NAS snapshots, and shadow copies the malware attempted but failed to purge tend to slip past it; add database transaction logs and half-encrypted files and there is a real amount to rebuild from. We line all of those up against whatever you need restored first.

It is not really about a list. We start by working out the family from the note and a couple of encrypted samples, then check whether a decryptor is available — including the free No More Ransom tools. Whichever strain it turns out to be, we weigh every recovery avenue, not decryption on its own.

That is a core part of what we do. Servers, RAID sets, NAS units and virtual machines that have been locked are all familiar ground: we image each disk, reconstruct the array if it needs it, and pull back file shares, mailboxes and databases.

Completely. We handle these cases quietly and are glad to sign an NDA. Both your data and the fact you were breached at all go no further than us.

For a one-disk machine it is typically a flat per-drive charge from £300 + VAT. Anything bigger is priced case by case, because the strain, how much data is involved and which systems are affected all move the figure. Either way a written quote reaches you before work starts — no surprises.

You can either bring them to our Guildford premises, open 9am to 5:30pm Monday to Friday, or post them under full insurance. From servers and NAS units, pull the drives first and mark each one with its bay or order number. Pop your contact details in so we can log the job, and we will assess it before any work starts.

The defences are dull but effective — versioned or offline backups the malware cannot touch, systems kept patched, and caution around attachments. Already been hit? Take the machine off the network, resist wiping and reinstalling over your only copies, and do not be rushed into paying. Send the drives to us: shadow copies, unencrypted remnants and a dig through old backups frequently turn up more than the ransom note admits, and the free diagnostic gives you an honest read before you commit to anything.

Routinely, yes. Our engineers slot in beside your insurer and whatever incident-response or breach specialists they appoint, rather than cutting across them. Since everything runs on read-only forensic images and copies alone, none of our work disturbs the evidence investigators or insurers rely on — and for your claim we can set down the strain, which systems were affected, and precisely what was retrieved. Do flag any cyber cover early: certain policies insist on an approved provider or particular procedures, and we will work within them.

// hit by ransomware?

Before you pay anyone, let us tell you what’s actually recoverable.

We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.