Data Recovery Case File · Ransomware · An Honest Limit
Six drives of hostage files: the decryption question, answered the way it deserves
The business had already done the hard part impressively: hit by a ransomware outbreak that encrypted the bulk of the files on their virtualisation host — every document renamed with the attackers' e-mail address and an ".adobe" extension — they rebuilt their domain on a fresh host and got trading again within days. Then they turned to the six 250GB SSDs from the old server, preserved intact, and asked the question every victim eventually asks someone: how much will it be to decrypt the files? The answer costs nothing and is worth this whole page: for this malware family, no one can sell you that — and anyone who does should be asked, precisely, how.
| Incident | Ransomware outbreak on a business virtualisation host; files encrypted and renamed with attacker contact details and ".adobe" extension (Dharma/CrySiS family behaviour) |
| Customer status | Business rebuilt and operating on a new host; the six original SSDs preserved unmodified and offered for recovery |
| Fault class | Strong per-victim encryption by a family with no known decryption weakness |
| Work performed | Array assembly and full imaging of the six drives · exhaustive search for unencrypted survivors, prior-version artefacts and recoverable remnants · written findings |
Why "decrypt it" wasn't for sale
Modern ransomware of this family does the cryptography properly: each victim's files are locked with strong encryption whose key exists only with the attackers. There is no clever workaround, no lab-grade brute force, no tool that undoes mathematics designed by competent adversaries — for a few older or botched families, researchers have published free decryptors, and checking whether yours is one of them is a legitimate first step we're glad to help with; this wasn't one of them. We put that in writing rather than in an invoice, alongside the counsel we give every victim about the other route: paying is a negotiation with criminals that guarantees nothing, funds the next outbreak, and sits outside anything we'd sell or manage. What a recovery lab can honestly offer after ransomware is narrower and still worth having: a rigorous audit of what the malware missed.
The audit — assembling first, searching second
Six SSDs from a virtualisation host aren't six independent stories; they'd worked as one array, so they were imaged individually and reassembled virtually into the volume the server had actually seen — the step DIY inspection of ransomware leftovers almost always skips, and without which even intact files are confetti. Across the assembled whole, the search ran every seam: files the outbreak never reached (encryptors prioritise documents and skip plenty), system-level prior-version snapshots (present but purged — this family kills them deliberately, and it had), and the free space where deleted originals sometimes linger — largely barren here, as expected on SSDs whose housekeeping erases the past by design. The findings: a modest but real population of untouched survivors — installers, some media, peripheral working files — extracted and delivered with an itemised map of exactly what existed in what state, so the business's rebuild proceeded on facts rather than hope.
Outcome
No decryption, because none was possible; no fee for the impossible part, because honesty is cheaper to give than false hope is to survive; and a business that lost data but not its footing — their swift rebuild being the real recovery in this story. The defences worth naming, since this page will be found by the recently attacked: offline, versioned backups are the only technology ransomware cannot negotiate with — a copy the network can't reach, tested by restoring it. Report the incident to the authorities. And keep the encrypted drives preserved, as this customer did: on rare occasions, keys for old families surface years later, and preserved is the only state that can ever benefit.
After a ransomware attack
Isolate first, preserve everything second — don't wipe the encrypted drives in the rebuild, and don't run cleanup tools over them. Check the free public decryptor databases for your family before believing anyone who offers paid decryption; if the family has no known weakness, no lab can change that, whatever the advert says. Then rebuild from offline backups if they exist — and if they don't, let that be the last time.
Start with an honest assessment of what's genuinely recoverable — call Bristol Data Recovery on 0117 332 1137.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.