Open, and work is coming in · weekdays, 9am–5:30pm Faster by phone: 0800 6890668
PDR Plymouth Data Recovery 0800 6890668 Get a price
PDR / Common faults / Ransomware got in

Everything has been encrypted

Plymouth ransomware recovery. Working fast, it misses things, and no ransom is paid.

Locking an entire network in one night is a rush, and a rush is careless. That carelessness is where your files come from: a snapshot left behind on the NAS, a shadow copy the run never got near, deleted originals still lying in free space, a large file encrypted only in patches. Work reaches this bench from Plymouth, west Devon and Cornwall. We deal with the data. Nobody here talks to whoever did this.

Nothing readable? Most jobs carry no bill Free diagnosis, then one written price Boxes come to the lab from Truro, Newquay and Tavistock

You will be talking to an engineer
0800 6890668

Ransomware: what each symptom points to.

Yours not here? Start at the triage →
What happensWhat that points toWhat to do
Every filename has picked up a suffix: .akira, or a character string issued to you aloneThe encryption completed. Qilin hands each victim a different extensionPhotograph it, then pull the network lead
akira_readme.txt in every single folderAkira's note. Others go with fn.txt or powerranges.txtDo not touch a single one
README-RECOVER-.txtQilin again; the note is named for your extensionKeep the lot
RECOVER--FILES.txtThat is how BlackCat/ALPHV names its notesEvidence. Do not delete it
A demand in place of the desktop wallpaperThe talking is supposed to happen on a Tor linkPhotograph the whole screen
Every shadow copy gone, and vssadmin delete shadows in the logRollback is finished — Windows has nothing left to restore fromOddly it helps us; it says where to begin
Getting it to us: wrap it so nothing can shift, cover it for what it is worth, and post it tracked to the intake lab in Bristol. We cover the postage back. If you want an engineer to check the packing before the box is taped, ring first. It is spelled out on the contact page.

Who is hitting UK networks in 2025–26.

QilinNamed in more attacks during 2025 than any other group, with a public victim list well past a thousand. Synnovis was among them, and NHS pathology in London halted in June 2024. There is no free key.
AkiraA joint CISA and FBI advisory in November 2025 described it as an active threat. The 2023 build gave way, and in 2025 a researcher showed a 2024 Linux variant could be cracked by brute force — but there is no general decryptor for the versions in circulation.
After LockBitAn NCA-led operation broke LockBit up in February 2024 and returned keys to some of its victims. What has filled the space since operates on a smaller scale.
Genuine free decryptorsWhere a free tool is real, No More Ransom will have it. Nothing exists for Akira right now, nor for Medusa, RansomHub, INC or Qilin. Anything advertised online as a “universal decryptor” is not a tool and not a key.

What happens to a drive while it is here.

Cases in the log →
01

A number on arrival, then the free diagnosis Free

Whatever arrives is booked in under a case number on the day it reaches the bench. An engineer then works out the actual fault, and that part is free. You get a plain answer on what can come off the drive and what cannot, followed by one price in writing. Nothing further happens until you have read it and agreed.

Diagnosis at no chargeA single written figureYou owe nothing yet
02

Isolated, then copied as found

Anything infected leaves the network before it is touched. Then each disk gets a full image, free space and all, since the untouched originals are usually still lying there. Nothing is tidied. Ransom notes, the altered wallpaper, the lock screen: all of it goes into the case file.

Each disk imaged forensicallyUnallocated space included
03

Recover what remains

Most strains do not encrypt in place. They read the file, write an encrypted copy next to it, then delete the source — and deleting removes the pointer and nothing more. Those bytes remain on the disk until some other file claims the room, so carving them out whole is routine. The remaining routes are worked just as hard: shadow copies missed by the run, snapshots on the NAS, big files locked only in patches, and a real decryptor where one has been published for that strain.

Deleted originals recoveredMatched against published keys
04

Fresh media, and a record

Nothing is returned onto equipment the attack reached. Your files come back on media bought in for the job, along with a written account of the work that will hold up for an insurer or the ICO.

Written to fresh mediaA report for the ICO
05

You give the word, and it ships back

Thinking it over costs you nothing. Everything the drive gave up is listed for you before any invoice exists, and the bill only follows your go-ahead. Files travel back on media bought in for your job, with return carriage paid at this end, and the case stays on the bench until you confirm they open on your own computer.

You see the list and decideWritten to fresh mediaWe pay the postage home

The faults we see most

  • vssadmin delete shadows /all /quiet — this turns up in most attacks; it takes away the restore points Windows was keeping. Seen in a log, it usually tells us which script ran and which other machines deserve a look.
  • Read, encrypt, delete leaves a trail — the source is unlinked rather than wiped, and it stays put until the disk wants that space for something else. Carving usually returns it whole.
  • Hurry leaves holes — under time pressure a strain encrypts a big file only partly, and whatever it passed over opens as usual.
  • The rules are hardening — a Government proposal of July 2025 would stop public bodies paying, along with critical national infrastructure. Private firms may follow. Nobody doubts the direction.

Refusal is now the ordinary answer: Sophos, surveying in June 2025, put recovery of data at 97% of organisations, with 49% having paid for it. Coveware recorded a payment rate of 23% in Q3 2025, the lowest it has measured. The British Library was asked for close to £600,000 in 2023, declined, and rebuilt. Payment guarantees nothing, and it was never the only way out — only the one on offer from the people who locked you out.

Being attacked? Call these

  • Report Fraud (formerly Action Fraud) — cyber crime goes to 0300 123 2040; with an attack under way the line is staffed round the clock.
  • NCSC — the National Cyber Security Centre wants a report as well, and its ransomware guidance repays following in order rather than picking at.
  • ICO, within 72 hours — under UK GDPR the counting starts as soon as you realise personal data might have gone, and three days later it has run out. That is not a deadline to let slide.
  • No More Ransomnomoreransom.org, which Europol backs, is the single place a real free decryptor ever shows up. Check there before believing any other offer.

The data is our part: images off the disks, recovery of whatever can be recovered, everything returned to hardware known to be clean, and the job written up the way an insurer or the ICO expects to see it. We open no line to the attackers, and our advice is that you should not either.

A job out of the casebook.

PL · PLY-2026-0638LOGGED ✓

A Cornish builders' merchant, and ransomware in the night

The lock had been applied to copies, not to the files themselves: each original was read, a scrambled duplicate written, and the original then deleted — so what mattered was still lying in free space, waiting to be carved out. The remainder sat in a NAS snapshot nobody had thought to check. The firm was trading again within the week, having paid nothing and answered nothing.

Trading again inside the weekNothing paid to anyone

Before you seal the box.

Get these done

  • Photograph each ransom note and every locked screen
  • Take anything infected off the network, but leave it switched on
  • Keep every log. Delete nothing
  • Report Fraud first, the NCSC after that — and where personal data went too, the ICO must hear within 72 hours

What to avoid

  • Making contact with the attackers, negotiating, or paying
  • Restoring a backup onto a machine still infected
  • Believing anybody selling a 'universal decryptor'
  • Switching a locked NAS on again before photographing it

Questions that come up most weeks.

Would paying be simpler?

Our answer is no, and we will not act as an intermediary either. Both police guidance and the ICO advise against it. A payment underwrites the following attack on someone else; no criminal is under any obligation to supply a key that functions; and the ICO has stated that having paid will do you no good at all in the assessment of a breach.

Realistically, what proportion comes back?

Frequently most of it, whole or in part. There are five sources: a backup you already have; a shadow copy the script missed; a snapshot still held on the NAS; deleted originals lying about in free space; and now and then a genuine free decryptor published for that particular build.

Is there a free decryptor for this one?

No More Ransom is where to look. It is run with Europol behind it and its listings do not overpromise. Right now nothing is published for Medusa, RansomHub, INC or Qilin, and nothing for the Akira and LockBit builds in circulation. Charging for a key to any of those means selling recovery work under a different name.

Who has to be told?

Cyber crime is reported to Report Fraud on 0300 123 2040 — the same service, renamed from Action Fraud. A business should file with the NCSC too. Where personal data has been caught up in it, the UK GDPR notification deadline for the ICO is 72 hours.

A drive that stays switched off gets no worse.

The diagnosis is free, and it comes back as a list: which files read, which do not, and what getting them off would take. Until then, leave the drive unplugged.

0800 6890668