Open, and looking at it costs nothing · 9am–5:30pm, Mon to Fri Ring instead, it is quicker: 0115 8220606
NDR Nottingham Data Recovery 0115 8220606 Get my quote
NDR / By what it is doing / Files encrypted by ransomware

The job · files encrypted across a network

Ransomware recovery, Nottingham. It was in a hurry, and your files come back from what it missed. No ransom.

Encrypting a whole network overnight means working at speed, and speed is careless. That carelessness is our raw material: a snapshot the NAS still holds, a shadow copy nothing ever got to, deleted originals lying in unallocated space, one large file encrypted only in patches. Pull the network lead, leave the machines powered, photograph what is on the screens, then ring. Jobs reach this bench from Nottingham, from Derby, from Loughborough and from Leicester. A single machine is £300 + VAT; servers, RAID sets and NAS boxes start at £500 + VAT; the figure goes in writing first. Data is our half of it, and nobody here talks to the people behind it.

No files back, no bill — on most jobs Free diagnosis first, then a single price, in writing Parcels come in from Derby, Lincoln and Loughborough

Ask an engineer, and the first look is free
0115 8220606

What the symptom points to.

Not yours? Open the fault finder →
What it looks likeWhat usually causes itWhat that means for you
Every filename carries a new suffix — .akira, or a string of characters issued only to youEncryption finished. Qilin issues a different extension to each business it hitsPhotograph the screen, then unplug the network
akira_readme.txt left in each folderThe note Akira leaves. Others go by fn.txt, or powerranges.txtTouch none of them
README-RECOVER-.txtQilin again — the note is named after whichever extension has been appliedKeep all of them exactly as found
RECOVER--FILES.txtThe naming BlackCat/ALPHV usesIt is evidence. Nothing gets deleted
A demand sitting where the desktop wallpaper wasAny talking is supposed to happen down a Tor linkGet a photograph of the full screen
Not a shadow copy left, and vssadmin delete shadows recorded in the logRollback is over: Windows has been left nothing to restore fromWhich oddly helps — it tells us where to start
How to pack and post it: movement is what finishes a damaged drive, so pack it rigid, cover the parcel for what the files are worth rather than what the disk cost, and put a tracked label on it for the intake lab. We cover the journey back. If you would rather someone checked your packing first, ring before the box is sealed. The whole method is on the packing and postage guide.

The ransomware groups working UK networks in 2025–26.

QilinThrough 2025 it was named in more incidents than anybody else, and the public list of organisations it says it encrypted runs well past a thousand. There is no free key for it.
AkiraCISA and the FBI described it jointly as an active threat in November 2025. Two builds have been broken: the 2023 one, by Avast, and the Linux/ESXi variant in use from late 2023 through 2024, by a researcher's GPU decryptor published in March 2025 — Akira changed its encryption afterwards, and the current builds have held.
What came after LockBitLockBit was dismantled in February 2024 by an operation the NCA led, and keys were returned to a number of the firms whose files it had encrypted. Smaller outfits work that ground now.
The free decryptors that existOne catalogue lists genuine free tools, and only one: No More Ransom. Akira is on it — Avast's decryptor, worth trying, though it opens only what the 2023 build encrypted and nothing since. Qilin, INC, RansomHub and Medusa do not appear at all. Anything sold online under the name “universal decryptor” is a sales page and nothing else.

From the parcel arriving to the files going home.

Jobs already finished →
01

Booked in the day it arrives, and the first look is on us Free

Your device picks up a case number the day it arrives, and an engineer then establishes what has genuinely gone wrong — at no cost, and ahead of everything else. Two things come back to you together: a plain account of what can be lifted and what cannot, and one fixed figure in writing. Agree to that figure, or turn it down and pay nothing.

The first look is freeOne fixed figure, in writingNo charge at this point
02

Off the network, then copied as found

Before a finger is laid on anything infected, it comes off the network. A full image of each disk follows, unallocated space and all, since the originals it deleted are usually still sitting down there. Nor is anything tidied up: the ransom notes, the altered wallpaper, the demand screen — every bit of that goes into the case file.

A full image taken of each diskUnallocated space taken too
03

Take back what it left behind

Encryption in place is rare. What most strains do is read the file, write an encrypted copy alongside it and delete the source, which takes away the pointer and leaves everything else where it was. Until some other file claims that room, the bytes stay put, so carving them out whole is ordinary work here. Every remaining route gets pushed equally hard: shadow copies the run missed, snapshots held on the NAS, big files encrypted only partly, and a published decryptor if one covers the strain we are looking at.

The deleted originals carved outPublished keys checked as well
04

New media, and the job written up

Equipment the incident touched gets nothing back. Media bought in for the job is what carries your files home, and with them goes a written account of the work in a form an insurer or the ICO will accept.

New media, bought in for your jobWritten up for the ICO or an insurer
05

The file list comes before the bill

The file list reaches you before any invoice does. Say yes and it is billed; say no and it is not — and on most jobs, if nothing comes back there is nothing to pay. Whatever comes off goes home on media bought in for your case, carriage at our end. Nothing here is closed until you have opened those files on your own machine.

Nothing is charged until you agree the figureNew media, bought in for your jobWe pay to send it home

What comes in most often

  • vssadmin delete shadows /all /quiet — it turns up in most of these jobs, and what it takes away are the restore points Windows had been keeping. Sitting in a log, that one line usually identifies the script responsible and points to whichever other machines are worth examining.
  • Read, encrypt, delete — and the trail survives — unlinking is not erasing, and the original sits where it was left until something else needs that space. Carving normally brings it back whole.
  • Haste leaves gaps — under time pressure a strain encrypts a large file only partly, and everything it skipped opens exactly as it did before.
  • The law is travelling in one direction — under a Government proposal published in July 2025, no public body and no operator of an essential national service would be permitted to pay at all. Private companies are widely expected to follow them into the same position. Nobody is betting on the rules loosening.

Most organisations now refuse. By the end of 2025 Coveware had measured the payment rate at about 20%, the lowest it had recorded, and its 2026 reports put it lower still. Sophos, surveying early in 2025 and publishing that June, found 97% of the organisations it asked had recovered — 49% of them having paid (48% in its 2026 report), which leaves the other half getting data back without any payment at all. The British Library was asked for roughly £600,000 in 2023, said no, and rebuilt on its own. Payment guarantees you nothing. It is one of several routes, and the only one that whoever encrypted your files has any interest in you taking.

Incident still running? Ring these

  • Report Fraud, which used to be Action Fraud — its cyber-crime line, 0300 123 2040, is answered out of hours as well, while an incident is still live.
  • NCSC — a report can go to the National Cyber Security Centre too, and its published ransomware guidance repays being worked through in order rather than dipped into.
  • ICO, inside 72 hours — UK GDPR starts that clock the moment you become aware personal records may be involved, not when the investigation wraps up. Three days on, the time has gone. Treat the limit as immovable.
  • No More Ransomnomoreransom.org. Run by Europol with the security industry, it is the catalogue where a genuine free tool for your strain will appear if one exists. Check it before you believe anyone offering to sell you one.

Data is the part we handle: disks imaged, everything recoverable recovered, results returned on clean hardware bought for the purpose, and the job documented as an insurer or the ICO would expect to see it. The first look costs nothing, the fixed figure reaches you in writing before any chargeable work is started, and most jobs carry no fee where the data does not come back. No line gets opened to whoever did this, and our advice is that you open none either.

One of these, from start to finish.

NG · NTG-2026-1788ON THE LOG ✓

Ransomware overnight at a builders' merchant in Loughborough

Nothing had been encrypted where it lay. What the software did was open each file in turn, write a scrambled version beside it, and delete the one it had just read — so the real accounts had never gone anywhere. They were sitting unallocated and could be pulled straight back. Whatever that missed turned up in a NAS snapshot nobody had bothered to check. No ransom, no reply, and the merchant was invoicing again inside the week.

Working again inside the same weekNot a thing paid, and nothing handed over

What helps, and what does damage.

Worth doing first

  • Photograph every ransom note and every screen carrying a demand
  • Take out the network lead, not the power lead — infected machines stay on
  • Every log kept. Nothing deleted
  • Report Fraud first, the NCSC next; the ICO gets its 72 hours' notice where personal records are involved

What makes it harder

  • Getting in touch with the people behind it, negotiating, or paying
  • Restoring a copy onto a machine that is still infected
  • Believing anyone who is selling a 'universal decryptor'
  • Switching an encrypted NAS back on before anyone has photographed it

Answers before you spend anything.

Is paying the quicker way out?

No, and we broker payments for nobody either. Three reasons, most important first: nothing obliges the other side to hand over a working key, so what arrives may be partial or broken outright; your money funds the next set of encrypted files; and the ICO has been explicit that payment counts for nothing when it comes to assess what happened. Police guidance says the same.

What proportion of the files return?

A good deal of it, frequently — some files entire, others only in part. Five routes exist and most jobs use several of them. A published free tool, if one genuinely covers the strain. Originals that were deleted rather than erased, sitting where the file system left them. Snapshots the NAS held on to. Shadow copies the run never reached. And simplest of the lot, a copy already in your own possession.

Is a free decryptor published for this one?

The catalogue worth checking first is No More Ransom: Europol is behind it, and only tools that work get listed. As matters stand, nothing has been published for Qilin, for INC, for RansomHub or for Medusa, and nothing for the LockBit or Akira builds now in circulation. Anyone selling a “universal key” for those strains is charging you for recovery labour under another name.

Who do we have to notify?

Up to three bodies, depending on the case. Cyber crime goes to Report Fraud, which is Action Fraud renamed, on 0300 123 2040. Businesses should log it with the NCSC as well. Where personal records sat among the encrypted files, the ICO has to hear from you inside 72 hours under UK GDPR, timed from the moment of realising.

Switched off, a drive cannot get any worse.

The look costs nothing. What comes back to you is a file list — what opened, what did not — plus one figure to finish the job, in writing, before anything chargeable begins. Most jobs carry no fee at all unless the data comes back. Leave the drive switched off until you have that list.

0115 8220606